I have at least a decade and a half of supporting sales teams as a security manager, CISO representative, proposal writer, or CTO. And every sales team has some kind of inside sales or sales development representative role. One of the quickest “wins” I’ve seen came from a few conversations to simplify their pitch and understand their buyer. I also taught them what security titles really mean (protip: “IT Security Manager” can be very senior or very junior, depending on the scope).
A couple of weeks ago, I watched a video about tips for cold calling for sales. And it made me wonder if cold calling or even warm calling actually works with CISOs and other security managers. In this blog post, we define cold calling as calling people from a list, usually purchased through a service, who haven’t shown any prior interest in your product. And we’ll define warm calling as calling people who have expressed some sort of interest through something like a web signup form.
I think it works to a point if you’re trying to sell security services to non-security people. One security vendor was infamous for being very aggressive on cold calling and repeated calling even though you were not a buyer. But for their market, that made sense to a point because they were targeting non-security buyers.
I’m on a hunt for anybody who works for a cybersecurity vendor who is having success with cold calling to CISOs. Partly because I’m not sure if it’s effective. Partly because if somebody is having success, that’s interesting to me.
Why Do Security People Hate Cold Calls?
Security people are intensely down on cold calling. I think it stems from several reasons:
- Incoming cold calls flood our phone lines. Even if you love your vendors, you could spend all day answering the phone without getting anything else done.
- Most companies do not talk about their security problems, especially if you’re an outsider.
- Most of us understand privacy regulation enough to know that our phone number was probably acquired illegally or at lease unethically.
- We live every day trying to detect and evade social engineering attacks and sales is by its very nature social engineering. Maybe non-malicious social engineering, but it’s still social engineering.
- I know of one CSO who doesn’t even answer their office phone unless they are feeling like they need to crush some poor Sales Development Representative’s soul. He’s nice about it, but he grades their technique, gives them feedback on what to do better, and sends them packing.
- Most of the advice and formulas that I’ve seen for cold calling is around highly polished introductory sentences. Which works for other people, but if you’re nice to a security manager, the don’t know how to react and they get defensive. The only time people call us and are nice is when things are broken and they need us to fix it.
- CISOs are all about trust and they usually work with a small group of vendors that they know. They very rarely bring on new vendors.
- Some of us spend our day fighting criminals so we’re very conscious of not sharing our contact information so that we do not get harassed from people who hate us.
- Even for me: my cellular phone is set up to not ring. This is because 99% of the people that call my phone are scammers.
What Works?
Since InfoSec people don’t like cold calls, what works then?
What works is opt-in, permissioned selling, and an email-first approach. Something like a “Yes, contact me about what products you have” button. I think that a lot of companies have whitepapers behind a registration form and that’s part of the first steps. But a “warm call” email campaign that points to on-demand resources that explain at depth goes a long way towards getting customers.
What works is being able to prune your contacts list. Focus on the people who are interested in buying instead of spending your time trying to sell to people who are not. You’ll see this in tech in general, but I think in InfoSec it’s even more important.
What works is current and relevant information that is not an overt product pitch. InfoSec managers live in a world full of chaos. They spin the random number generator and sometimes a cute kitten pops out, while other times it’s a tiger that tries to eat you. That tiger is usually a new vulnerability or a successful attack campaign by one of the adversaries. And the way that we manage that chaos is through getting up-to-date information on attackers and what they are doing. This is the role of the CERT/CSIRT/Security Research Teams and good Pre-Sales Engineers and Product Marketing Managers that understand the ecosystem and something beyond just the product features.
What works is CISOs asking their peers for what vendors they use and which ones are good to work with–Ie, referrals. Unfortunately, that’s not a predictable way for sales teams to get new sales. However, understand that it happens all the time and that if you treat one customer badly, it will get back around to you.
What works is giving people free access to tools so their staff can learn them before they buy. You don’t buy security tools that you don’t have experience in using. This is part of the success of Elastic, Splunk, Cloudflare, and others.
Published on April 14, 2021.
Last Updated on 6 months ago.
