Cybersecurity · Warm Call
Warm Call Script for Cybersecurity: Cashing a Peer Referral into a SOC Meeting
A warm call into a security org is not a friendly call. The person picking up is a Director of Security Operations who has four analysts against 12,000 alerts a day out of the SIEM, two reqs unfilled for seven months, and a renewal quote priced per GB per day that just came in higher than last year. They took your call because a peer they respect told them to. That peer's name is the entire reason you are not already in voicemail, and it buys you about ninety seconds.
Security buyers are also, professionally, the hardest audience on earth for a vendor call. Their job is to distrust unverified inbound. They have sat through the AI-powered-XDR-zero-trust deck eleven times this year. They can smell a transplanted pain from the first sentence — and if you say "Marisol was drowning in tier-1 triage so I imagine you are too," the CISO on the other end knows you did zero research on their estate, their stack, or their mandate. Different headcount, different SIEM, different regulator.
So the job is narrow: name the referrer in the first breath, say the small checkable reason they thought of this person, admit out loud why it might not apply to them, and get to one question about their alert queue. Then close on a date with a named attendee — usually their detection engineering lead — not on "I'll send some info over." Everything below is written to be said out loud, ten minutes before you dial.
The warm call script
Say it in your own words. The structure is the part that matters.
- 1
Pre-call: write the provenance line before you dial
One sentence, out loud, before the phone rings. Small and checkable: "Marisol pulled down our triage benchmark last month and said you'd just taken the SOC over at Brightline after the Meridian acquisition." Not "Marisol thought you'd be interested." That is nothing and they will hear it as nothing. Also pre-decide three things: 1. **Exactly what the referrer said.** If Marisol said "you should call Ray," you say "Marisol suggested I call you." Never inflate it to "Marisol said you'd really want to see this." Security leaders are a small community and they compare notes at the same three conferences. 2. **Your relevance hypothesis about THEIR world.** Built from a trigger: new in role, an acquisition doubling the estate, a SOC analyst job ad that's been live four months, a SIEM vendor migration, a first SOC 2 Type II cycle, a PCI date. 3. **The 15-second re-brief.** Assume the intro email was skimmed on a phone during a bridge call and archived.
- 2
The open — name, referrer, provenance, permission (25 seconds)
"Ray — Dev Ranganathan, from Kestrel. Marisol Vega suggested I call. She picked up something we published on alert-to-incident ratios and said you'd inherited the Meridian estate on top of your own SOC in January — so two SIEM tenants and one rota. She may have been overselling my usefulness. Have you got four minutes for me to work out whether this is actually relevant to you, or should I come back?" If they say "yeah, Marisol said you'd call" — that is the whole warmth budget landing in your hand. Five words of acknowledgement, then move: "Good, she said she'd flag it. Then I'll be quick."
- 3
If they can't place the referrer
This happens constantly. Do not argue them into remembering. "No reason you would — it was a two-line intro on a Friday. Short version: we sit at the ingest point in front of the SIEM and collapse duplicate and known-benign alerts so tier-1 reads one thing instead of forty. Read-only API, no agent. That's it. Worth four minutes, or not really?"
- 4
The relevance bridge — referrer's world, the difference, then a question
This is where the call lives or dies. Make it inside the first minute. "What Marisol was dealing with was about 9,000 alerts a day out of a co-managed SIEM, three of her rules generating most of it, and a Friday afternoon bulk close to get the queue back to zero. That's her shop, not yours. You've got in-house detection engineering, she doesn't — she's paying an MDR for that. So I honestly don't know if this lands on you the same way. What's your alert-to-incident ratio at the moment? Roughly — alerts hitting the queue last week versus how many became real incidents." The two moves that buy you credibility here: naming a specific reason you might be irrelevant, and asking about a number they actually get measured on rather than describing your product.
- 5
Discovery — three questions, four at the absolute most
This is not a booked discovery call. Do not run MEDDIC down the phone at a SOC manager mid-shift. **1. Mechanical current state.** "Walk me through a shift. How many alerts per analyst, and who's actually touching tier-1 — your people or the MDR?" **2. Cost or friction, in their numbers.** "When you close out the queue on a Friday, what's the honest percentage that got read versus bulk-closed? And has that ever come back and bitten you on dwell time?" **3. Priority test — the one that saves you a wasted follow-up.** "Is that a this-quarter problem, or is it a live-with-it problem you've budgeted around?" **Optional fourth, high hit rate on warm calls:** "Besides you, who'd care about this? Does your Head of Detection Engineering own the content in the SIEM, or is that split with the platform team?" Listen for the correction. If they say "it's less the volume, it's that ingest cost means we're not onboarding half our SaaS logs" — write down their exact phrasing. That sentence is your second-meeting agenda.
- 6
Reading the cool-off
Warmth withdraws politely. Signals in this world: answers shorten to "yeah, makes sense"; they jump straight to "send me your SOC 2 and a TPRM questionnaire"; they ask pricing before you've established a problem; or they invoke the referrer as an exit — "well, if Marisol rates you." Stop talking and name it: "I'm getting the sense this isn't the pressing thing this quarter — which is fine, Marisol was guessing. Is it not the problem, or not the moment?" A clean "not the problem — our ratio's fine, our pain is coverage mapping" is a good outcome. It protects the referral relationship and it tells you exactly which of your other angles is live.
- 7
The close — date, length, named reason, named attendee
Close on their words, not yours. "Then here's what I'd suggest. You said the thing that keeps you up is the Friday bulk-close, not the detection content itself. Give me thirty minutes and I'll show you a two-week replay against last month's alert metadata — what your analysts would have skipped and what we'd have surfaced first, scored against incidents you already know the outcome of. I'd want whoever owns your detection content on that call, because the first question they'll ask is which of your five noisiest rules we'd collapse and how. Thursday morning, or Monday afternoon?" If they genuinely can't commit a diary slot, take a smaller real commitment with a date on **your** side: "Fine. I'll send you two paragraphs and one screenshot of the replay output — not a deck. I'll call you Thursday at 9 and you tell me whether it's worth thirty minutes."
- 8
Close the loop with the referrer, same day
Two lines, non-negotiable, and routinely skipped: "Marisol — spoke to Ray, thanks for that. His issue's a bit different to yours; his ratio's actually okay but he's not onboarding cloud logs because of the GB/day cap. Doing thirty minutes with him and his detection lead Thursday. Appreciate the intro." This thanks them, tells you whether you can use their name again with the rest of their peer group, and is the only reliable way one referral turns into a second.
- 9
Language bank
**Works** - "Marisol suggested I call — she may have been overselling my usefulness." - "That's her environment, not yours, so I don't know if this lands." - "What's your alert-to-incident ratio, roughly?" - "Is that a this-quarter problem or a live-with-it problem?" - "There's no agent. Read-only API against the SIEM you already ingest into." - "Four minutes, or shall I come back?" **Kills the warmth** - "So how do you know Marisol?" as an opener — three minutes gone, nothing returned. - "Marisol said you'd be really interested in this." They will check. - "Just to give you a bit of background on us…" - "As per the email below." They didn't read it. - "Marisol was drowning in tier-1, so I imagine you are too." - Any sentence containing "AI-powered" and "zero trust" in the same breath.
How the call actually sounds
Prospect on the left, the rep on the right.
Rep
Ray — Dev Ranganathan, from Kestrel. Marisol Vega suggested I call. She picked up something we put out on alert-to-incident ratios and said you'd taken the Meridian SOC on top of your own in January. She may have been overselling my usefulness. Four minutes to check whether that's true, or should I come back?
Buyer
Marisol, yeah. She flagged it. I'll be straight with you — I get eight of these a week and every one of them is AI-powered detection that's going to transform my SOC. You've got about ten seconds to be different before I go back to a bridge call.
Rep
Fair. I'm not going to claim a category. One question instead: how many alerts hit your queue last week, and how many of those became actual incidents? If that ratio's worse than about a hundred to one, you've got a triage problem, not a detection problem, and triage is the only thing I do. If your ratio's fine, I'll hang up.
Buyer
It's bad. Everyone's is bad. We're pulling somewhere around eleven, twelve thousand a day across both tenants and I've got four analysts on days and an on-call rota covering nights. But I'll tell you what Marisol's got that I don't — she's got an MDR doing her tier-1. Mine's in-house. So whatever worked for her probably doesn't map.
Rep
That's exactly why I said she might have oversold it. Her situation is she's billed on volume by someone else. Yours is four humans and a rota. Different problem. So let me ask the version that's actually about you — when you close the queue out on a Friday, what percentage genuinely got read?
Buyer
You want me to say it out loud on a first call with a vendor? Enough of it gets bulk-closed that I don't love the question. Three rules generate most of the noise, we've tuned them twice, and every time we tune them somebody's use case breaks and we untune them. That's the loop.
Rep
Understood, and I'm not going to pretend I need the number. Different question: has that loop ever cost you on dwell time? Not a breach — I mean an incident where the first signal was sitting in the pile from three days earlier.
Buyer
Once. Credential stuffing, and it was in there, and nobody read it. That's the thing I actually care about. But here's where you lose me — you're going to want an agent on five thousand endpoints, and our risk review for anything touching the golden image takes a full quarter. I've got two EDR agents already fighting each other. I'm not adding a third thing.
Rep
I'd fail that review too and I'd deserve to. There's no agent. We read from the SIEM you already ingest into, over a read-only API. No kernel driver, no change window, no image rebuild. The security review is a data-handling review, not an endpoint deployment — different form, usually a much shorter one.
Buyer
Then send me your SOC 2 Type II, your latest pen test summary and our TPRM questionnaire back, and my GRC director will queue it. That's six weeks minimum, so realistically we're talking about a conversation in the autumn anyway. Budget's committed through Q2.
Rep
All three go out today, plus the data flow diagram and subprocessor list so your GRC director isn't chasing us for them. And I'm not asking for budget — I'd rather be the thing you already validated when the money frees up than start cold. While the review runs, can I do thirty minutes with whoever owns your detection content?
Buyer
That's Priya, she runs detection engineering. But she'll ask you the question I'm going to ask now, so save her the time. If we collapse alerts and we miss something, that's my job on the line. Nobody's ever been fired for reading too many alerts.
Rep
They get fired for dwell time, and reading twelve thousand alerts a day is how dwell time happens. Two things: nothing gets deleted — everything stays queryable and retained for your auditor, we only change what's presented first. And you write the suppression rules. We don't auto-close anything you haven't approved in writing.
Buyer
Fine. But I've seen a lot of demos that look brilliant on the vendor's own data. Anything I take to Priya has to run against ours or it's a waste of her afternoon.
Rep
That's the only proof I'd trust either. Give us a thirty-day export of alert metadata — no payloads, no PII — and we'll replay it: what your analysts would have skipped, what we'd have surfaced first, scored against incidents you already know the outcome of. Including that credential stuffing one. If we miss something you caught, that's a real answer and you've lost an afternoon.
Buyer
And if the replay shows nothing?
Rep
Then I tell you that, and I tell Marisol I called and it wasn't a fit. Thirty minutes with you and Priya to scope the export — Thursday morning or Monday afternoon?
Buyer
Thursday, but make it 8:30 before shift handover, and Priya may only give you twenty of it.
Rep
Thursday 8:30, twenty minutes is plenty for scoping. I'll send the SOC 2 pack and one paragraph on the export format today so Priya can shoot it down before we're on the call. Thanks, Ray.
Objections you will hear
What they say, and what you say back.
| Objection | How to answer it |
|---|---|
| “"Every vendor says AI-powered detection. You've got ten seconds to be different."” | "Fair. I'm not going to claim a category. One question: how many alerts hit your queue last week, and how many became incidents? If that ratio's worse than about a hundred to one you've got a triage problem, not a detection problem, and triage is the only thing I do. If your ratio's fine, I'll hang up." Do not defend the category. Trade the pitch for a number they already track. |
| “"Adding your agent to 5,000 endpoints? The risk review alone takes a quarter."” | "Agreed, and I'd fail that review too. There's no agent — we read from the SIEM you already ingest into, over a read-only API. No kernel driver, no change window, no golden image rebuild. So the security review is a data-handling review, not an endpoint deployment. That's usually a different, much shorter form." Say 'no agent' in the first six words or they stop listening. |
| “"We already have a SIEM, a SOAR and an MDR. Where does this even sit?"” | "In front of all three. Your SOAR runs playbooks on alerts after somebody's decided they matter. Your MDR bills you on the volume it has to look at. We sit at the ingest point and collapse duplicates and known-benign into one thing your analyst reads. Fastest way to find out if that's real is a two-week replay against last month's alerts — no production change, nothing in the path." |
| “"Send me a SOC 2 Type II, a pen test report, and fill out our TPRM questionnaire. Then we'll talk."” | "All three today, plus the data flow diagram and subprocessor list so your GRC team isn't chasing us. While it's in the queue — can we do thirty minutes with whoever owns your detection content? The review takes six weeks either way; I'd rather it ran in parallel with the people who'd actually use this than sequentially." Never treat this as a brush-off; treat it as the price of entry and then ask for the technical session anyway. |
| “"We're not buying anything until Q3. Budget's committed."” | "Understood, I'm not asking for budget. What I want is to be the thing you already validated when Q3 arrives, rather than starting from a cold POC in July. One question while we're here — what's the GB-per-day number your SIEM renewal is priced on? If we change what has to be indexed and retained hot, that renewal conversation changes, and that's usually a different budget line to mine." |
| “"If we cut alerts and miss something, that's my job. Nobody gets fired for reading too many alerts."” | "They get fired for dwell time, and reading twelve thousand alerts a day is how dwell time happens. Nothing gets deleted — everything stays queryable and retained for the auditor, we only change what's presented first. And you set the suppression rules. We don't auto-close a single thing you haven't approved in writing." |
| “"Prove it in our environment. Everyone's demo looks great on their own data."” | "That's the only proof I'd trust either. Give us a thirty-day export of alert metadata — no payloads, no PII — and we'll show you what your analysts would have skipped and what we'd have surfaced first, scored against incidents you already know the outcome of. If we miss one you caught, that's a real answer and you've lost an afternoon." |
Questions reps ask about this call
- How is a warm call to a CISO different from a warm call anywhere else?
Security leaders are professionally trained to distrust unverified inbound, and they are pitched constantly. The referral gets you the pickup and roughly ninety seconds of suspended disbelief — it does not get you interest or credibility. What earns the next four minutes is a specific, checkable reason the referrer thought of them (new remit, an acquisition, a SIEM migration, a first SOC 2 cycle) and one question about a number they own, like alert-to-incident ratio or alerts per analyst per shift. Generic framing burns the goodwill faster here than in any other industry.
- What do I say if the Director of Security Operations can't remember who referred me?
Don't argue them into remembering — the intro was two lines on a Friday and they were on a bridge call. Say so: "No reason you would." Then give a fifteen-second re-brief in their language with no product name-dropping — "we sit at the ingest point in front of the SIEM and collapse duplicate and known-benign alerts, read-only API, no agent" — and re-ask for the four minutes. Half of warm calls into security run this way and they still convert if the re-brief is concrete.
- Should I use the referrer's pain to describe the prospect's problem?
No. Copy-pasting the referrer's environment onto the prospect is the fastest way to lose a security buyer, because their stack, headcount and mandate are visibly different and they know it. Use it as contrast instead: "What Marisol was dealing with was a co-managed SIEM with an MDR doing her tier-1. You've got in-house detection engineering, so I don't know if this lands the same way." Naming a reason you might be irrelevant is the single strongest credibility move available on a warm call.
- How much discovery should I attempt on a warm cybersecurity call?
Three questions, four at the outside. A SOC Manager or VP of Security Operations picking up mid-shift did not agree to a discovery meeting. Ask one mechanical question (alerts per analyst per shift, who touches tier-1), one cost question (what percentage gets bulk-closed, has it ever cost you on dwell time), and one priority test ("this-quarter problem or live-with-it problem?"). Running eleven qualification questions reads as an abuse of the referral and gets shut down with "just send me a deck."
- The prospect immediately asked for our SOC 2 Type II and a TPRM questionnaire. Is the call dead?
Not necessarily, but it's a fork. Sometimes it's a polite disqualification; often it's genuinely how security orgs buy. Send everything the same day — SOC 2 Type II, pen test summary, data flow diagram, subprocessor list — and in the same breath ask for a thirty-minute technical session with the Head of Detection Engineering while the review runs in parallel. If they refuse the technical session as well as accepting the paperwork, that's your signal it was a deflection.
- What counts as a real close on a warm call into a SOC?
A date, a length, a named reason built from their own words, and a named second attendee — usually whoever owns detection content in the SIEM. "Thirty minutes Thursday to scope a thirty-day alert metadata export, and I'd want Priya on it because she'll ask which of your noisiest rules we'd collapse" is a close. "I'll send some info over" is a pleasant call that goes nowhere. If they truly can't commit a slot, take a smaller real commitment — two paragraphs and one screenshot, and a callback time you diarise on your side.