The short answer
This playbook runs security vendor prospecting on three lines: role-and-vector sorted lists, blocks timed to security leaders, a five-attempt cadence whose artifacts are ungated and technical, stack-aware dispositions, and KPI targets expressed as ranges against production reference points from 3-line sessions over 90 days.
Step by step
- 1
Build lists by role, vector and stack signal
Rows pair the security owner with the vector the vendor addresses and a public stack signal: conference talks, job posts, tool mentions, cloud footprint. The signal is the opener's fact, and public means verifiable. Rows without a signal go to research, not the dialer.
- 2
Scrub the list the boring way
Internal do-not-call suppression before import, the stop-request log checked daily, bad numbers dead on second confirmation. The B2B exemption in 16 CFR 310.6(b)(7) is narrow and not a TCPA exemption; 47 CFR 64.1200 wireless rules still apply to personal cells on the list.
- 3
Run blocks on security-leader hours
7:30 to 9:00 catches leaders before the standups eat the day, 12:00 to 1:00 catches the after-incident lull, 4:30 to 6:00 catches the second window. Three lines per SDR, one connect at a time; security connects are scarce and get full presence.
- 4
Cap the cadence at five attempts
Days 1, 3, 6, 10 and 14, dayparts rotating, voicemails calm and rare because three a week reads like a pentest. After five, the lead exits to a dated nurture keyed to the budget quarter or the next public event.
- 5
Make the artifacts ungated and technical
Every call's follow-up is the session agenda, public documentation and the trust page, ungated, out within the hour. Security vendors who gate their own trust documents lose the audience before the meeting.
- 6
Keep the claims line bright
No citing alleged vulnerabilities, no breach speculation about the prospect, no scanning claims, advisory outreach on public facts only. The FTC's Impersonation Rule at 16 CFR 461.3 governs false affiliation claims, and the category's ethics is its marketing.
- 7
Disposition by stack and budget, not by vibes
Technical meeting booked, Gatekeeper referral, Stack mismatch, No budget this quarter, Existing tool covers it, Bad number, No answer, Left voicemail, Do not call. Stack-mismatch rows are honest exits, not nurture bait.
- 8
Review KPIs weekly as ranges
Dials per active hour, security-leader contacts, technical meetings booked per 100 contacts, show rate, artifact open rate. Compare against the production reference points, then fix list signal quality before coaching pace.
What this playbook covers
Security vendor prospecting is credibility arithmetic: scarce connects, professional skeptics, and a category where one dishonest call can poison a market. This playbook covers signal-based list building, block structure, cadence, artifact discipline, dispositions, the three-line workflow, and KPI ranges against production reference points.
List building and hygiene
Rows pair the owner with the vector and a public stack signal: a conference talk, a job post naming the tooling, a cloud footprint, an open-source contribution. The signal is the opener’s fact, and public means verifiable; the SDR who shades a signal into a claim about the prospect’s environment has crossed the line the whole playbook exists to hold. Hygiene rules:
- Internal do-not-call suppression before import; the stop-request log checked daily, because security leaders report pestering vendors to their communities.
- The B2B exemption in 16 CFR 310.6(b)(7) covers most calls to induce a business purchase but is narrow and not a TCPA exemption; 47 CFR 64.1200 wireless rules still apply.
- Hours inside 8 a.m. to 9 p.m. local at the called party’s location as standing policy; the dialer computes it per row.
- Bad numbers die on second confirmation; recycled failures on security desks read as reconnaissance and get reported.
Call block structure
Early block, 7:30 to 9:00. Security leaders before the day’s standups and incident reviews; the calmest 90 minutes of their calendar.
Midday block, 12:00 to 1:00. The after-morning-incident lull, and the window where SOC managers answer their own phones.
Late block, 4:30 to 6:00. The second window, plus artifact follow-ups and booked-session confirmations.
Between blocks: agendas and ungated docs go out, AI summaries get edited, and engineer prep notes land in the session calendar. The SDR who leaves stack facts unedited is booking the wrong depth of meeting.
Attempt cadence
Five attempts over two weeks, dayparts rotating, voicemails calm and rare:
- Day 1. The role-and-vector opener, two stack questions, the engineer-led close.
- Day 3, different daypart. The catch window.
- Day 6. Voicemail at most once per sequence, 18 seconds, no urgency.
- Day 10. Live attempt; the agenda and docs go out the same hour regardless.
- Day 14, final. The honest exit: “Agenda is yours; I will stop here unless the roadmap moves.”
After five, the lead exits to dated nurture keyed to the budget quarter or the next public event. Attempt caps in the dialer enforce the stop; in this category the stop is a feature the buyer notices.
Artifact discipline
Every call’s follow-up is the session agenda, public documentation and the trust page, ungated, delivered within the hour. Nothing gated, nothing that smells like lead-scoring masquerading as content. The artifact is the proof of the call’s honesty claim: a vendor who said the session is technical and then sends a brochure has contradicted itself in writing, and security leaders forward those contradictions.
Dispositions and what they mean
- Technical meeting booked: slot, engineer prepped, agenda attached, stack facts in the invite.
- Gatekeeper referral: the named owner becomes a new row with the signal attached.
- Stack mismatch: honest exit; the product does not fit the environment and pretending otherwise burns the engineer’s hour.
- No budget this quarter: dated nurture keyed to planning season, one public-fact touch per quarter at most.
- Existing tool covers it: the benchmark session can still convert these; the disposition records which ones were offered it.
- Bad number / No answer / Left voicemail / Do not call: the mechanical set, stop requests honored the same day.
The three-line workflow and AI summaries
Three lines fit security prospecting because connects are scarce and valuable: one connect at a time, the honesty sentence spoken on every cold open, two stack questions maximum, and the AI summary edited before the next connect with ownership, stack facts including what stays, roadmap timing, the skip-this note and the session slot. The engineer reads the summary before the session because the meeting’s depth is the vendor’s product. Recording disclosure on in all-party consent states.
KPI targets
Ranges against production reference points. In production use across 3-line sessions over 90 days, the median operator ran about 85 dials per active hour and roughly 600 dials per operator day, with a person-connect rate of 17.8 percent measured separately over the last 30 days. Planning ranges for security vendor work:
- Dials per active hour: measured median about 85 per active hour, p90 about 134.
- Security-leader contacts: track it weekly and set the target from your own first two weeks of data.; count it on well-signal-ed rows.
- Technical meetings booked: track it weekly and set the target from your own first two weeks of data.; count it on signal-rich lists.
- Show rate: track it weekly and set the target from your own first two weeks of data.; the lever is ungated agendas and engineer prep.
- Stop-request rate: tracked weekly; a spike is an opener problem, not a market problem.
Only the dial-volume and person-connect figures above are measured (production use, three-line sessions, one operator; 90-day window for dial volume, its final 30 days for the connect rate). Every other range in this section is an uncited planning input, not a measured result or a promise.
Compliance guardrails
The B2B exemption in 16 CFR 310.6(b)(7) narrows the FTC Telemarketing Sales Rule but does not waive TCPA wireless rules at 47 CFR 64.1200 or the Impersonation Rule at 16 CFR 461.3, and all-party recording consent states require the disclosure. The vendor-specific lines stay bright: no alleged vulnerability claims, no breach speculation, advisory outreach on public facts only. Honor and log every stop request. DialBreeze applies your internal DNC list, quiet hours and attempt caps; list provenance and claims discipline are yours. This guide describes rules, not legal advice.
FAQ
What dial and contact numbers should a security SDR expect?
How many technical meetings book per hundred contacts?
How often should we touch a security lead?
What if the prospect mentions an active incident?
What compliance habits matter most here?
Sources
- ecfr.gov /current/title-16/chapter-I/subchapter-C/part-310/section-310.6
- ecfr.gov /current/title-16/chapter-I/subchapter-C/part-461/section-461.3
- ecfr.gov /current/title-47/chapter-I/subchapter-B/part-64/subpart-L/section-64.1200
- ftc.gov /business-guidance/resources/complying-telemarketing-sales-rule
Operational guidance, not legal advice. Rules vary by state and by campaign.