The best phone system for cybersecurity vendors and resellers
A narrow, heavily solicited target: get more attempts in without degrading the conversation.
Hundreds of companies use to make every call pay off
The situation
What holds you back today
CISOs are over-solicited and rarely reachable
Long decision cycles with several stakeholders
A technical pitch that is hard to standardise
The answer
What Skipcall changes
Specific to your industry
The three reflexes of a CISO on the phone, and what to do with them
A security lead is trained to distrust a call they did not ask for: that is the job. The objections you hear are therefore not ordinary sales objections, and treating them as such costs you the call.
“How did you get my number?”
The question is not rhetorical. An unknown caller asking questions about the information estate looks like reconnaissance, and NCSC guidance tells staff to verify unexpected callers rather than answer them. Say precisely where the data came from, straight away, offer to be called back on the number published on your own website and to send a message from your own domain. On a first call, ask nothing about architecture, versions, headcount or suppliers: those are exactly an attacker's questions.
“We already have a supplier”
Usually true, and attacking the incumbent closes the door. Move the conversation to what is not covered: a recently acquired site, operational technology on the industrial side, a cloud environment that arrived after the contract was signed. Above all ask when the current contract comes up for renewal and write the date down, because that is what drives the next useful call.
“Send me some information”
Nine times out of ten this is a polite exit. Ask what question the document is supposed to settle, send only enough to answer it, and fix the date of the follow-up call before you hang up. Material sent without a dated next step produces nothing and leaves you with no legitimate reason to come back.
“It is not my decision”
Often accurate: the CISO specifies, but the budget may sit with the IT director, with finance or with risk and compliance. Do not read it as a brush-off. Ask who signed off the last security spend, then who would carry it this time. You will get a name, which is worth more than an agreement in principle.
“Call me after the audit”
This is the one objection worth a firm appointment. A Cyber Essentials renewal, an ISO 27001 surveillance audit, a PCI DSS assessment or a penetration test all fix a date, a scope and a list of findings to close, and therefore a budget. Ask when the report is due, set the follow-up for that exact moment, and come back with the question the report will have raised.
On a target this narrow, the record of each attempt matters as much as the attempt: calling the same person twice in one week is enough to burn the account.
The script
The script for a first call to a CISO
You are calling a security lead or an IT director on their direct line, unannounced. The replies below answer the five reflexes described above one by one. The aim of a first call is not to qualify the estate, it is to get a date.
The opening
“Hello [name], [first name last name] from [company]. Your number came from [precise source]. I am not going to ask you anything about your estate, your tools or your suppliers. I just want to know whether [precise subject, coverage of your operational technology for instance] is an open subject for you this year, or not at all.”
Announcing that you will ask no technical questions defuses the suspicion before it fires, and leaves a question that can be answered yes or no.
If they ask where the number came from
“From [exact source]. If you would rather check, hang up and call me back on the number published on [domain], I am on extension [x]. I will also send you a message from my address at [domain] while we are talking.”
Offering the verification yourself is what separates your call from a social engineering attempt, and it costs one sentence.
If they already have a supplier
“Good, and I am not going to tell you they do a bad job. My question is elsewhere: does the scope of that contract cover [the industrial site, the acquired subsidiary, the cloud environment that arrived since]? And when does the contract come up for renewal?”
The renewal date is the only piece of information that drives the next useful call: write it down the moment it is said.
If they ask for documentation
“I will send you something, but a brochure will be no use to you. Tell me the question it needs to answer and I will send only that. And I will call you Thursday at nine to find out whether the answer holds, does that work?”
If they say it is not their decision
“I assumed so, the spend rarely comes out of your line. Last time you bought something in security, who signed it off? And this time, would it be the same person?”
You are after a name, not an agreement in principle: a name can be called, an agreement in principle cannot.
If they point at the end of an audit
“Happy to. When is the report due? I will put [date] down and I will not call you before then. And when I do, it will be about the findings the report raised, not about my product.”
At Skipcall, every call is recorded, transcribed and summarised, so the script gets corrected against what your reps actually say rather than what we imagine they say.
Avoid this
Three mistakes this industry makes on the phone
The mistake
Qualifying technically on the first call: which EDR, how many endpoints, who runs the SOC, which provider manages the network.
Do this instead
Those are word for word the questions of a reconnaissance phase, and a security lead is trained not to answer them on the phone. Keep them for an established conversation, once your identity has been verified. On a first call, ask only whether the subject is open and when it gets decided.
The mistake
Calling with the number withheld, or from a different number on every attempt.
Do this instead
A security lead who cannot call the displayed number back files the call as suspicious, and sometimes reports it internally. Ofcom's rules require outbound calls to present a valid, dialable number that identifies the caller, so use a business number tied to your company, ideally the one on your website. A number that stays the same from one attempt to the next builds the only thing that counts here, recognition of the caller.
The mistake
Opening on the breach of the moment, along the lines of “did you see what happened to that company?”.
Do this instead
They read the report before you did, and the opener puts them in the position of justifying their own defences to a stranger: the conversation is lost by the second sentence. Open on a verifiable date instead, a contract ending, an audit under way, a certification renewal, a regulatory deadline, and let them describe what follows from it.
Frequently asked questions, Cybersecurity
Other industries that prospect by phone
See all 25 industries →Web, SEO & marketing agencies
Selling time in an agency is whatever is left over: make it ten times more productive.
Media & ad sales
Selling space is won on the phone against hard deadlines: call more people, faster.
Events & trade shows
A show fills in a matter of weeks: point all your calling power at that window.
See what it does on your own lists
A demo runs on your own contacts, not on a sample data set.
Personalized demonstration