Cybersecurity · Upsell Call

Upsell Script for Cybersecurity Customers: Expanding Inside a SOC That's Already Underwater

Your customer is a VP of Security Operations with four tier-1 analysts, a SIEM licence priced per GB per day that renews in March, and two open reqs that have been unfilled for seven months. Fourteen months ago they bought your triage layer and their queue went from 11,800 alerts a day to something a human can actually read. They picked up this call expecting a check-in. You are about to ask them for another $3,400 a month.

This is the call where security buyers are hardest, and for reasons that are specific to their world. They are not just budget-defensive — they are change-defensive. Every new data path means a fresh third-party risk questionnaire, an updated data flow diagram, and six weeks in GRC's queue. Every new capability means new runbooks for analysts who are already burnt out on triage. And underneath all of it sits the fear that governs every decision a SOC leader makes: if we suppress, route, or tier something and an intrusion lives inside it, the dwell time clock is running and it's my name on the post-incident review.

So the entire call is won in the prep. If you open with their alert-to-incident ratio, the MTTD number they quoted in their own QBR, and the fact that 22 of their 38 suppression rules are still sitting in observe-only mode — you get a real conversation with a peer. If you open with "I wanted to walk you through our new ingest module," you get a polite ten minutes and a request to send a one-pager, and you have quietly demoted yourself from partner to vendor. Everything below assumes you did the usage audit first.

The upsell call script

Say it in your own words. The structure is the part that matters.

  1. 1

    0. Pre-call usage audit — do not dial without these seven lines

    Write these on one page. If any line is blank, you're not ready to dial. 1. **Alert volume, then vs now.** "Presented to tier-1: 11,800/day at go-live, 2,100/day last month." Sourced from their tenant, not your benchmark deck. 2. **Alert-to-incident ratio and MTTD.** "1,900:1 down to 340:1. Median MTTD 4 days 9 hours down to 19 hours." Know which of these numbers they quote to their CISO — that's the one they defend internally. 3. **Depth of adoption.** Which suppression rules are live vs observe-only. Which log sources are wired in. "38 rules built, 16 enforcing, 22 still observe-only since June." 4. **Sponsor engagement.** Last login for the CISO and for the SOC manager. If the exec sponsor hasn't opened the coverage dashboard in 94 days, that's a fact you use, not one you hide. 5. **Commercials.** ACV, renewal date, who signed, whether they still work there, discount level, and whether the add-on can co-term. 6. **Support history.** Any P1 in the last 90 days. Any missed detection they raised. Any ticket where an analyst said "your rule swallowed something." You must raise this before they do. 7. **Their SIEM position.** Licensed GB/day, current average, renewal date, and which log sources they have refused to onboard because of cost. This is where the expansion lives. **The test:** can you say one thing about their environment they'd be mildly surprised you knew? "You've been sitting at 812 gigs a day against an 850 cap since the Okta migration" passes. "How's everyone finding the platform?" fails, and it's the specific thing this buyer holds against you.

  2. 2

    1. Frame the call in the first thirty seconds

    "Thanks for the time. Two things, and I'll be straight about both. First — I pulled fourteen months of your tenant data and there's a pattern in your ingest numbers I want to check with you, because I think it's costing you more than we're saving you. Second — depending on what you say, there's a piece of our platform that may be relevant, and if it isn't I'll tell you that on this call rather than send you a deck. Fair?" Do not sandbag. A security leader who discovers halfway through that this was a sales call will never give you a straight answer again. Pre-committing to walking away lowers their guard faster than any rapport-building.

  3. 3

    2. Raise the escalation before they do

    If there was a P1, a missed detection, or an angry ticket in the last 90 days, it goes here — not at the end, not never. "Before anything else. Three weeks ago Dana raised a ticket that one of our correlation rules collapsed a Kerberoasting alert into a bucket she didn't open until the next morning. We reviewed it, it was our rule scoping, we fixed it on the 14th and pushed a regression test so it can't reoccur. Do you consider that closed, or is it still sitting with you?" If they say it's still open — **stop the upsell**. Say so out loud: "Then let's spend this call on that and I'll come back to the other thing in six weeks." Pushing an expansion over the top of an unresolved miss in a SOC is how a renewable account becomes a churn risk.

  4. 4

    3. Make them say the result out loud, in their numbers

    "Fourteen months ago your tier-1 queue was 11,800 alerts a day across four analysts — roughly 2,900 per analyst per shift — and your team was bulk-closing on Friday afternoons to get back to zero. Last month you presented 2,100 a day. Your alert-to-incident ratio went from about 1,900:1 to 340:1, and median MTTD on confirmed incidents came down from four and a half days to under twenty hours. Does that match how it feels in the SOC, or am I reading my own dashboard optimistically?" Then shut up. Their correction is worth more than your number. If they say "MTTD is nice but the thing that actually changed is nobody bulk-closes on Friday anymore" — write that sentence down verbatim. That's the line their CISO will repeat to the audit committee, and it becomes the first paragraph of your recap email. **If they can't confirm a result, this is not an upsell call.** Pivot immediately: "Then let's not talk about anything new. You're paying us eighty-nine thousand a year and you can't point at a number — let's fix that first." That's the only version of this call that protects the renewal.

  5. 5

    4. Name the underuse before they weaponise it

    They are already thinking *we barely use what we've got.* Say it first and you're diagnosing; let them say it and you're defending. "Here's what I'd push back on if I were you. We've built 38 suppression rules in your tenant and 22 of them are still in observe-only — they've been running in shadow since June and nobody's promoted them. Your CISO hasn't opened the coverage dashboard in 94 days. If I were sitting where you are, I'd ask why I'd buy anything else before I'd turned on what I already own. So let me tell you what those 22 rules would have done last quarter if they'd been enforcing: another 640 alerts a day off the queue, and zero of your 47 confirmed incidents touched by them — I checked against your own incident IDs. That's not me asking for money, that's a 45-minute session with Dana to promote them. Want me to book that regardless of where the rest of this call goes?" Giving away the adoption fix for free, on the record, is what buys you the right to ask for the expansion ten minutes later.

  6. 6

    5. Find the seam — the questions that surface the cut scope

    Never lead with the module. Lead with where value leaks out. Highest-yield questions for a SOC leader: - "What did you deliberately leave out of scope when we scoped the original deal because it was too big a bite?" - "Which log sources are you currently choosing *not* to onboard, and what's the reason — cost, parser work, or nobody's asked?" - "What's the number your SIEM renewal is priced on, and where are you sitting against the cap this month?" - "When your GRC director needs evidence of log source coverage for the SOC 2 cycle, how does she get it today?" - "What percentage of known assets have working EDR telemetry as of this morning — and how long would it take you to prove that number to an insurer?" - "Which of your analysts would quit first if you added another runbook?" That first question is the one that pays. Most expansions were already scoped and cut during the original deal. You're not selling something new — you're reopening a decision they made once under a different budget.

  7. 7

    6. The gap, stated as their problem not your feature

    "So here's what I see and tell me where I've got it wrong. You're licensed at 850 gigs a day. You've averaged 812 since the Okta migration. You've got three AWS accounts, the Okta system log and two SaaS admin logs sitting un-onboarded — call it 180 gigs a day you *know* you need and are refusing because it puts you over the cap, and the next tier on your renewal quote is another two hundred and ten thousand a year. Meanwhile about 240 gigs a day of what you *are* paying full price to ingest is perimeter firewall accept-logs, proxy and DNS — data you need for retention and for hunting, and almost never for real-time detection. So you're paying premium per-GB rates to store chatter, and going blind on three cloud accounts to afford it. That's the gap. The thing I want to talk about routes the chatter to cheap immutable storage and keeps it queryable and replayable, so the SIEM ingest budget goes to the sources that actually fire detections. Nothing is dropped, nothing is deleted, retention is unchanged and the auditor still gets a log source inventory report."

  8. 8

    7. The arithmetic, with the price said out loud

    Say the price in the same breath as the value. Never make them ask. "The unit: your SIEM quote for the next tier is $210k a year. The volume: 240 gigs a day of routable perimeter data based on your last 90 days of ingest telemetry — that's from your own volume metrics, not my model. The capture rate: I'd assume we route half of it, not all of it, because you'll want some of that DNS data staying hot for hunting. So call it 120 gigs a day of headroom, which is enough to onboard the three AWS accounts and Okta and still sit under your existing cap. The router is $3,400 a month on top of what you're paying — $40,800 a year, and I'd co-term it to your March renewal so it's an amendment, not a second contract and a second procurement cycle. So: $40,800 against a $210,000 tier uplift you don't take, plus five log sources you've been going without. If you think my routing estimate is generous, tell me the number you believe and we'll rerun it right now on the call." Handing them the pencil on the assumptions is the difference between a business case and a pitch.

  9. 9

    8. Cost the implementation in hours and names

    Budget is the stated objection. Bandwidth is the real one — and in a SOC that just lost its detection engineer, it's usually true. "Implementation ask, honestly: one 90-minute config session with whoever owns detection content — that's Dana now that Marcus has gone — then about two hours a week from her for three weeks while we validate. We write the parsers and the field mappings, not you. We run the replay validation on our side against your last quarter's 47 incidents and hand you the results. No agent, no endpoint change, no golden image rebuild. It's a read-only API integration and a routing config in front of an ingest point you already operate. If it needs more than that from your team, I've mis-scoped it and I'll say so. And if your PCI evidence gathering is in February, we don't start in February. Tell me the crunch and I'll put the start date after it — but I want a date on the calendar, not a 'circle back in Q3.'"

  10. 10

    9. The ask: smallest reversible unit, their success criteria

    "Here's what I want, and it's smaller than you're expecting. One log source family — perimeter firewall, proxy, DNS. Sixty days. Two success criteria and you write them, not me. My suggestions: GB/day into the SIEM drops by at least 100, and we replay all 47 of last quarter's confirmed incidents against the routed path with zero detection content breakage and zero change in what your analysts would have seen. If we hit both, we co-term the router to the March renewal and you onboard the AWS accounts with the headroom. If we miss either, we unroute it in an afternoon — it's a config change, not a migration — and you owe nothing further. What would you add to those success criteria?"

  11. 11

    10. Buying committee check — ask, don't assume

    "Last time this went through Ravi in finance on your signature. Is that still the path for a forty-thousand-dollar add-on, or has the threshold moved since the new CFO landed? And second — does a routing change in front of the SIEM trigger a fresh third-party risk review with your GRC director, or does it fall under the existing agreement and data flow diagram? Because if it's a new TPRM cycle I'd rather start that paperwork this week in parallel than discover it in week six." If procurement now requires three bids over $25k, or a new CISO has landed since the original deal, you're running a fresh evaluation dressed as an expansion. You need to know that today.

  12. 12

    11. Recap email — write it for the forwarder, not your CRM

    Same day. Six elements, no marketing language, because this email gets forwarded to a CISO and possibly to a GRC director: 1. The result they confirmed, in their words: *"Nobody bulk-closes on Friday anymore"* — plus the ratio and MTTD numbers they didn't dispute. 2. The free adoption fix, with a booked date: promote the 22 observe-only rules, session with Dana on the 9th. 3. The gap in their language: 812 of 850 GB/day, five log sources un-onboarded, $210k tier uplift on the March quote. 4. The math with *their* assumptions marked as theirs. 5. The price, co-term terms, and the exit clause. 6. Pilot scope, both success criteria in their words, decision date, and named owner on each side. Attach the updated data flow diagram and subprocessor list unprompted. It saves their GRC director a chase email and it's the single cheapest credibility purchase available to you.

How the call actually sounds

Prospect on the left, the rep on the right.

  1. Rep

    Thanks for making time. Two things and I'll be upfront about both. First, I pulled your tenant data back to go-live and there's something in your ingest volumes I want to check with you. Second, depending on your answer, there's a piece of our platform that might be relevant — and if it isn't, I'll say so on this call instead of emailing you a deck. Fair?

  2. Buyer

    Fair. Though I'll tell you now, budget's gone. The SIEM renewal ate everything and I've got two reqs I still can't fill. So if this is the part where you upsell me, save us both the hour.

  3. Rep

    Noted, and I'll come back to that. First — three weeks ago Dana raised a ticket that one of our rules collapsed a Kerberoasting alert into a bucket she didn't open until the next morning. That was our rule scoping. We fixed it on the 14th and added a regression test. Do you consider that closed, or is it still live with you?

  4. Buyer

    It's closed. But honestly it rattled me. That's exactly the thing I said would happen when we signed. Nobody gets fired for reading too many alerts — they get fired for the one they didn't read.

  5. Rep

    They get fired for dwell time, and reading 11,800 alerts a day is how dwell time happens — but I'm not going to argue the philosophy with you after we caused a miss. What I'd rather do is check whether the trade actually paid. Fourteen months ago you had 11,800 a day across four tier-1 analysts, roughly 2,900 per analyst per shift, and a Friday bulk-close. Last month you presented 2,100 a day, alert-to-incident ratio went from about 1,900:1 to 340:1, and median MTTD on confirmed incidents is under twenty hours against four and a half days before. Does that match how it feels on the floor, or am I reading my own dashboard optimistically?

  6. Buyer

    The MTTD number is roughly right. The thing I'd actually point at is that nobody bulk-closes on Friday anymore. I stopped getting the Monday morning email asking why 4,000 alerts closed in eleven minutes. That's what changed. But before you go anywhere with that — we're not using half of what we bought. Marcus built a load of rules and then left for a vendor and they've been sitting there.

  7. Rep

    Twenty-two of thirty-eight, still in observe-only since June. I was going to raise it before you did. And your CISO hasn't opened the coverage dashboard in ninety-four days. If I were you I'd absolutely be asking why I'd buy anything else before turning on what I own.

  8. Buyer

    Right. So you already know the answer to your own call.

  9. Rep

    Partly. Here's what those 22 would have done last quarter if they'd been enforcing — another 640 alerts a day off the queue, and I checked them against all 47 of your confirmed incident IDs: zero touched. That's a 45-minute session with Dana, it's free, and I'll book it whatever else we do today. Can I do that?

  10. Buyer

    Yes. Book it. Now what's the actual pitch.

  11. Rep

    One question first. What's your SIEM renewal priced on, and where are you sitting against it this month?

  12. Buyer

    850 gigs a day. We're at 812 average, spiking over on patch Tuesdays. Which is why there are three AWS accounts, the Okta system log and two SaaS admin logs I'm not onboarding. I know they're gaps. I've written them down as accepted risk. It's in the risk register with my signature on it, which is not a document I enjoy.

  13. Rep

    About 240 gigs a day of what you are ingesting at full price is firewall accept-logs, proxy and DNS. You need it for retention and hunting; it almost never fires a detection. We route that to immutable object storage in front of the SIEM — still queryable, still replayable, retention unchanged, log source inventory still exports for your auditor. Say we only route half of it: 120 gigs of headroom, which covers the AWS accounts and Okta and keeps you under the existing cap. It's $3,400 a month, co-termed to March. Your next SIEM tier is what, on the quote?

  14. Buyer

    Two-ten a year. But hang on. You're describing a new data path in front of my SIEM. That's a fresh third-party risk questionnaire, an updated data flow diagram, and my GRC director will want to know why log data is landing somewhere that isn't in the current DPA. That's six weeks minimum, and my PCI evidence window is February. Also — my co-managed MDR already tells me they do ingest filtering, and they're on the same renewal.

  15. Rep

    Three separate things, let me take them in order. GRC: yes, it's a new data flow, I won't pretend otherwise. I'm sending the updated diagram, subprocessor list and SOC 2 Type II today so it's in your GRC queue this week rather than week six — and it's an amendment to the existing agreement, not a new master. MDR: ask them what they'd charge you next year if your volume dropped 15%. Their commercial model is priced on the volume they look at; mine isn't. February: we don't start in February, we start after your evidence window closes.

  16. Buyer

    And if routing breaks a detection? Half our content references firewall fields. I have one detection engineer and she is not spending March rewriting correlation rules because a vendor moved her data.

  17. Rep

    Then that's the pilot's success criterion, and you write it, not me. Sixty days, one log source family — firewall, proxy, DNS. Two tests: GB/day into the SIEM drops by at least 100, and we replay all 47 of last quarter's confirmed incidents against the routed path with zero content breakage and no change in what your analysts would have seen. We run the replay, we write the parsers, Dana gives us 90 minutes up front and two hours a week for three weeks. Miss either test and we unroute it in an afternoon — it's a config change, not a migration. What would you add to those two criteria?

  18. Buyer

    A third. I want the un-onboarded sources actually live inside the sixty days, not 'available headroom.' Headroom I can't spend isn't a result. And I want to see the export the auditor would get, before we start, not after.

  19. Rep

    Both in. Sample audit export to you this week so your GRC director can red-pen it before anything moves. Last thing — the original order went through Ravi in finance on your signature. Is that still the path at forty thousand, or has the threshold moved since the new CFO?

  20. Buyer

    It's three bids over twenty-five now. Which for a co-termed amendment to an existing contract, I *think* I can argue as a variation rather than a new purchase. I'm not certain.

  21. Rep

    Then let's find out before we build a business case for something procurement won't let you sign. I'll draft it as an amendment to the March master with the pilot exit clause visible on the first page, and you take the question to procurement this week. If they call it a new purchase, I'd rather know now and start the three-bid clock than discover it in week six. Recap and the audit export to you by end of day, and I'll book Dana for the free rules session on the 9th regardless.

Objections you will hear

What they say, and what you say back.

ObjectionHow to answer it
Budget's gone. The SIEM renewal ate the whole line and I've got two reqs I can't fill.I'm not asking you to spend security budget. Your SIEM renewal is priced per GB per day and you're at 812 against an 850 cap, with a $210k tier uplift on next year's quote. This comes out of the same conversation, and if it works it makes that quote smaller. So the question isn't whether you have $40,800 — it's whether $40,800 stops $210,000. Ask me to be wrong about that and I'll rerun it at whatever routing number you believe.
You want to put a routing layer in front of my SIEM? My PCI auditor is going to have a problem with that.Nothing is dropped and nothing is deleted. The data lands in immutable storage, retention is unchanged or longer, and it stays queryable and replayable. What changes is where it's billed, not whether it exists. I'll send you the exact log-source inventory export your auditor would receive, this week, before we touch anything — let your GRC director red-pen it first. If she says it won't hold up in the SOC 2 cycle, we stop there.
My co-managed MDR says they already do ingest filtering, and they're on the same renewal.Ask them one question: what do they charge you next year if your ingest volume drops 15%? An MDR's commercial model is priced on the volume they have to look at, so nobody in that contract is incented to shrink it. I'd also ask them for the GB/day figure they've actually removed from your SIEM licence in the last twelve months. If they can produce it and it's bigger than what I'm proposing, I'll drop this.
We barely use what we've bought. Twenty-two rules are sitting in observe-only since Marcus left.You're right and I'm not going to argue it — I was going to raise it before you did. Here's what those 22 would have removed if they'd been enforcing: 640 alerts a day, and I checked them against all 47 of your confirmed incidents last quarter — none of them touched a real one. That's a 45-minute session with Dana and it's free, and I'll book it whether or not we ever talk about the router again. But it's an adoption gap, not a product gap, and it's a different problem from the fact that you're paying premium per-GB rates to store DNS chatter while three cloud accounts sit un-onboarded.
My team has no bandwidth. I have one detection engineer and PCI evidence gathering starts in February.Then we don't start in February. What I need is 90 minutes with Dana and two hours a week from her for three weeks — we write the parsers and the field mappings and we run the replay validation on our side and hand her the results. If it takes more than that from your team, I've mis-scoped it and I'll say so. Give me a start date after your evidence window closes and I'll hold it.
If we route something and an intrusion lives inside it, that's my name on the post-incident review.That's the right fear and it's why the pilot's success test is a replay, not a promise. We take all 47 of last quarter's confirmed incidents — ones where you already know the outcome — and run them against the routed path. If a single one would have surfaced differently to your analysts, that's a real answer and we unroute it in an afternoon. You set the routing rules, you approve every source in writing, and nothing moves that you haven't signed off on.
This is a new data path, so it's a fresh third-party risk questionnaire and six weeks in GRC.It is a new data flow and I won't pretend otherwise. What I can do is have the updated diagram, subprocessor list and SOC 2 Type II in your GRC director's inbox today rather than in week six, and structure it as an amendment to the existing master agreement instead of a new contract — same legal entity, same DPA, same read-only posture. The review runs six weeks either way. I'd rather it runs in parallel with the technical session than after it.
Send me something and I'll look at it after the audit.I'll send it, and I'll make it the recap rather than a brochure — your MTTD numbers, the ingest math with your assumptions marked as yours, the price and the exit clause. But 'after the audit' is a season, not a date. Your audit closes end of February. Can I put 90 minutes in the diary for the first week of March, and if you want to cancel it then, cancel it?

Questions reps ask about this call

What should I have in front of me before running an upsell script with a cybersecurity customer?

Seven things, all from your own systems: alert volume then vs now, alert-to-incident ratio and MTTD from their tenant, which suppression rules or detections are actually enforcing vs sitting in observe-only, last login for the CISO and the SOC manager, contract value and renewal date and whether the original signer still works there, any P1 or missed-detection ticket in the last 90 days, and their SIEM position — licensed GB/day, current average, and which log sources they've refused to onboard on cost. That last item is where most cybersecurity expansions actually live. The test is whether you can say one thing about their environment that mildly surprises them.

How do I open an upsell call with a VP of Security Operations who thinks it's a check-in?

Name the agenda in thirty seconds and pre-commit to walking away: 'Two things — I pulled fourteen months of your tenant data and there's a pattern in your ingest volumes I want to check, and depending on your answer there's a piece of our platform that may be relevant, and if it isn't I'll say so on this call rather than send you a deck.' Then, if there's been an escalation or a missed detection in the last quarter, raise it yourself before anything else. Security leaders do not forgive an expansion pitch that skips past a miss they're still carrying.

How do I handle 'budget's committed' when their SIEM renewal took the whole line?

Don't discount and don't accept it as final — it's usually a timing and authority objection in costume. Move the money out of your budget line and into theirs: their SIEM licence is priced per GB per day, and if your expansion reduces ingest volume or avoids a tier uplift, the business case belongs to the renewal conversation, not the security tools line. Also ask whether it can start at renewal with a signed order form now, and whether it can be co-termed as an amendment rather than processed as a new purchase — co-terming removes an entire procurement cycle and is the most underused unlock on this call.

When should I not run the upsell at all?

Park it if there's an open P1, an unresolved missed detection, a champion who just changed roles, a renewal inside 60 days with unanswered value questions, a flat or declining usage curve you can't explain, or a hiring freeze or cost review announced in the last quarter. In a SOC, add one more: if your product has been implicated in an alert that got surfaced late, do not sell anything until that post-incident review is genuinely closed in the buyer's mind. Pushing through any of these converts a renewable account into a churn risk to book incremental ARR.

What's the right size of ask on the first expansion call?

The smallest reversible unit that proves the case: one log source family, one detection domain, or one team, for sixty days, with success criteria the buyer writes down on the call. For cybersecurity specifically, the strongest success test is a replay against incidents they already know the outcome of — 'we run last quarter's 47 confirmed incidents through the new path and if a single one surfaces differently, we roll it back.' Pair that with a visible exit clause and co-term the add-on to the existing renewal date so it reads as an amendment, not a second contract.

The customer says they barely use what they already bought. Do I argue?

No. There are only two honest answers and neither of them is an argument. Either you can show the unused capacity is doing work somewhere else — rules built but not promoted, a dashboard nobody's opened, analysts doing the same triage in a spreadsheet outside the platform — or you concede the point and go fix adoption first. Offer the adoption fix free, with a booked date, regardless of what happens with the expansion. Giving that away on the record is what earns you the right to ask for money ten minutes later, and if the account genuinely can't point at a result, you're on a value-realization call and the upsell needs to wait a quarter.