Cybersecurity lead generation works when a buyer has a dated reason to act and your message reaches the person who owns that reason. There are only a few such reasons: an incident, an audit or compliance deadline, a new security leader, a contract up for renewal, or fast growth.
The owner of the reason is rarely "an IT decision maker". It is the CISO, the head of security, the GRC (governance, risk and compliance) lead or, in a mid-size company with no CISO, the CTO, with the management board signing off.
In Europe, two laws now set many of those dates. NIS2 requires medium and large companies in critical sectors to manage the security of their suppliers, and it lists managed security service providers (MSSPs) as both in scope and a particular risk.
DORA, which has applied to EU financial firms since 17 January 2025, writes security terms into every contract they sign with an ICT (IT and telecom) supplier.
The rest is execution: a clean list, a sender a technical buyer can check in a minute, and enough follow-ups to still be there when the date arrives.
Smirnov Consulting Group is a Prague-based B2B outbound lead generation agency that runs cold email and LinkedIn campaigns for founder-led B2B companies and books qualified sales calls.
Over 12 years of this work I have written up several IT and software cases, none from a security company, so this piece carries no campaign numbers of mine. It carries the regulation, read at the source, and the targeting rules I bring to every new market.
Why do security buyers ignore most cold outreach?
Distrusting unexpected messages is part of their job. A security team trains the whole company to report lookalike domains, surprise attachments, shortened links and senders nobody can trace. Then your cold email arrives and gets the same inspection.
That changes the order of what matters. A security buyer checks the sender before reading the offer. If your sending domain looks like a cheap copy of your brand, or the person who signed the email has no real LinkedIn profile, the message is finished before the second line.
They also read, ask peers and check your website and people before any call. And a security purchase touches the security team, compliance, IT, finance and procurement, so the title section below matters more here than in most niches.
Which events open a security budget?
Five triggers come up again and again. What changes is how a product vendor and a services firm should use each one.
| Trigger | Where you can see it | Angle for a security product vendor | Angle for an MSSP or security services firm |
|---|---|---|---|
| An incident, theirs or a close peer's | Public disclosures, news, regulator notices | The control that would have caught it earlier | Monitoring and incident response that fit the NIS2 reporting clock |
| An audit or compliance deadline | Their sector and size, certifications listed on their site, compliance hires | Evidence and reports an auditor asks for | Gap assessment, audit preparation, managed controls |
| A new security leader | Job changes on LinkedIn, press releases | A tool the new leader can deploy and show results with in the first year | An outside assessment of what the new leader inherited |
| A contract up for renewal | Rarely public; ask in early calls, note announcement dates | A switch before the renewal date | Taking over from the current provider |
| Growth: funding, a new market, security hiring | Funding news, job posts for security roles | Tooling for a team being built | Cover while they hire, or instead of hiring |
In Europe, regulation drives two of these directly: the compliance deadline, and the incident, because NIS2 puts a legal clock on what follows one. In the US, audit dates under SOC 2, PCI DSS (card payments), HIPAA (health data) and CMMC (defense suppliers) play the same role as the deadline.
The other three are ordinary B2B signals, and I covered which free buying signals repay the time it takes to watch them separately.
What do NIS2 and DORA change for security sellers?
Across the eight competing pages on this query that I went through, NIS2 gets one passing mention in a list, and DORA does not appear at all. Here is what the two legal texts say, checked at the source in September 2026.
| NIS2 | DORA | |
|---|---|---|
| What it is | An EU directive; each country writes it into its own law | An EU regulation that applies directly |
| Key date | National laws were due by 17 October 2024 | Applies from 17 January 2025 |
| Who is covered | Medium and large organizations in listed sectors: energy, transport, health, finance, water, digital infrastructure, critical product manufacturing, waste, postal services, public administration and more | 20 types of financial entities, plus EU oversight of critical ICT providers |
| What touches a security seller | Supply chain security, incident reporting within 24 hours, 72 hours and one month, and management approval of security measures | Written ICT contracts with set clauses, a register of every ICT contract, exit strategies |
| Fines | Each country sets its maximum, which must be at least EUR 10 million or 2% of worldwide turnover (essential entities) | Outside the scope of this piece |
"Medium-sized" follows the EU SME definition: as a rule, NIS2 starts at 50 staff, or at more than EUR 10 million in both annual turnover and balance sheet.
Three details in the NIS2 text matter most for outreach.
Suppliers are now part of the buyer's homework. Article 21 makes supply chain security, including relationships with direct suppliers and service providers, one of the required measures.
The preamble goes further: it names MSSPs and software makers as supply chain risks and tells covered companies to use "increased diligence in selecting a managed security service provider." Expect to be assessed, and bring your evidence before they ask.
The incident clock is written down. After a significant incident, a covered company owes an early warning within 24 hours, a notification within 72 hours and a final report one month after that. Detection and response services now have a dated reason to be bought.
The board is on the hook. Article 20 makes the management body approve the security measures, oversee them and follow training, and it can be held liable. That is why a CEO or CFO can suddenly be in a security meeting.
One correction while we are here. The fine figures above are floors for the national maximum, so summaries that say "fines up to EUR 10 million" get it backwards. A GRC lead will notice.
For financial clients, the DORA text is just as concrete. Article 30 lists what an ICT contract must include: where data is processed and stored, help during an incident at no extra cost or at a price agreed in advance, termination rights, and the terms of your participation in the client's security awareness training.
Contracts for critical or important functions add full service levels with measurable targets. The client also records you in its register of ICT contracts, which the supervisor can request.
So if you sell to a bank or an insurer in the EU, "we sign DORA-ready contracts", when it is true, is a stronger first line than any statistic about breach costs.
This is not legal advice. Check the national law in every country you sell into, because NIS2 details differ from one to the next.
Who actually signs a security purchase?
My rule for any niche: go after the real decision-maker titles in that niche, not a generic "manager" title. To find them, look at your past projects and check who actually made the decision.
In IT sales, that meant looking past "IT Manager" to titles like VP of IT Strategy or Director of IT. In security, the same discipline looks like this:
| Title | What they own in the purchase | Put them first when | What they need from you |
|---|---|---|---|
| CISO or CSO | The security budget and the risk story told to the board | The company is large enough to have one | Risk reduced, in terms the board understands |
| Head of security or security operations lead | The evaluation and day-to-day fit | You sell a product or a monitoring service | Technical proof and integration details |
| GRC or compliance lead | The audit, the regulation, supplier assessments | The trigger is NIS2, DORA, ISO 27001 or SOC 2 | Evidence mapped to the exact requirement |
| CTO, head of IT or IT director | Implementation, and in mid-size firms security itself | There is no CISO | Low effort to run and maintain |
| CEO, CFO or managing director | Final approval and, under NIS2, personal accountability | Smaller in-scope companies or large contracts | A short, plain account of which obligation you cover |
| Procurement or vendor risk | The contract and the supplier questionnaire | Later in the deal, after the first wave | Your security documents, ready to send |
Pick 2 or 3 of these per account, and give each one a different angle on the same trigger.
Two of my list rules apply here unchanged. Cut the generic titles, such as assistant, associate and manager. And verify every address before sending; I hold bounces under 0.5%.
A technical audience makes both rules stricter. A wrong name or a dead address in a CISO's inbox costs you twice: a bounce on your domain, and visible proof that you sprayed a list. With this audience, the list usually decides more than the copy does.
Does a security vendor sell differently from an MSSP?
Yes, and the articles that currently rank on this topic treat them as one seller. The buyer is asked to trust two very different things.
| Security product vendor | MSSP or security services firm | |
|---|---|---|
| What the buyer trusts | A tool inside their stack | People with access to their systems |
| Who evaluates first | Security operations and engineers | CISO or head of security, then GRC |
| Strongest triggers | New security leader, growth, renewal of a competing tool | Incident, audit deadline, a security team that cannot hire |
| Regulatory angle | NIS2 names software makers among supply chain risks | NIS2 lists MSSPs in scope and asks buyers for extra diligence |
| Proof that matters | Integration, peers who run it | Response times, process, certifications, where data sits |
A vendor's first message should earn a technical look: one specific problem the tool solves in an environment like theirs.
An MSSP's first message should earn trust with a named obligation. Here is a first touch for an MSSP writing to a GRC lead at a mid-size manufacturer:
Subject: supplier checks under NIS2
Hi [First name], NIS2 asks companies like [Company] to assess the security of their direct suppliers, and it asks for extra care when choosing a managed security provider. If supplier reviews are on your plan this year, I am happy to share the one-page summary we give our clients' auditors: where data sits, our incident process, our response times. Should I send it?
No fear, no fine figures, no attachment. One obligation and one useful document.
There is a twist for MSSPs. If yours has 50 or more staff and serves EU clients, NIS2 may cover you directly, because Annex I lists managed security service providers by name. Living under the same rules as your buyer is an argument, so use it.
An MSSP also sells a monthly contract, so its funnel math is closer to managed services than to software. I worked through the calls-per-contract numbers for that in the outbound guide for MSPs and IT consultancies.
What makes a security buyer reply?
Three things, in this order.
A sender that passes inspection. Send from a domain that clearly carries your brand and points to your real site, and authenticate it with SPF, DKIM and DMARC. The person in the signature should have a real, active LinkedIn profile. Plain text, no attachments, no shortened links.
A dated reason in the first line. Name the trigger you saw: a new CISO, a certification renewal, a financial client base under DORA. Generic "cyber threats are rising" openers read like every other vendor.
Restraint around incidents. If their breach is in the news, do not open with it. They will hear from plenty of vendors who read the same headline. Write later, about the work that follows an incident: the final report, the supplier review, the gaps an auditor will ask about.
Then follow up across email and LinkedIn. A trigger date rarely lines up with your first message, so plan several touches rather than one.
If you sell from the US or the UK into Europe, GDPR applies to your outreach too. I covered what GDPR means for cold outreach into Europe separately.
Which cybersecurity lead gen numbers can you trust?
Read what ranks for cybersecurity lead generation and you will find prices per meeting, "positive ROI within 60 days", engagement multipliers for prospects in an audit window, and the line that CISOs get dozens of pitches a day.
The meeting prices, ROI figures and multipliers come from agencies' own campaign data, published without a method or a sample. The pitch-volume line has no source at all on the pages that repeat it. Those numbers may be true for the agencies that published them. Nobody outside can check them.
What holds up is the legal text itself and your own numbers. When anyone quotes you a benchmark, ask three things. Out of what: emails sent, people contacted or replies? Over what period? For which buyer title?
A security buyer will ask the same about any number in your outreach.
What does cybersecurity lead generation cost?
I found no neutral price data for outbound aimed at security buyers. The per-meeting prices mentioned above are agencies quoting themselves, so I leave them out.
The one independent figure covers lead generation in general. Clutch's buyer guide for lead generation services, from a B2B review platform, gives a monthly range for hiring a lead generation agency: $1,000 at the low end, $25,000 at the top. The guide dates from March 2025 and gives no method for that range. Checked September 2026.
Treat that as a wide frame for any niche. Nothing in it is specific to security, and it is not our price.
For a security seller, what sits inside a quote matters more than the total. Ask each agency to price these on separate lines: research by trigger and title, sending domains and mailboxes, address verification, and follow-ups across email and LinkedIn.
Then divide the monthly total by held meetings with the titles in the table above. A cheap meeting with someone who cannot sign or evaluate still costs your team a call.
I compiled published agency price ranges, the costs outside the headline fee and what an in-house SDR costs separately, with a formula for putting two different quotes on one line.
How long until meetings, and until a signed deal?
For the reason given at the top, I will not give you a day count. Published numbers exist, and they disagree.
One agency's article on security lead generation warns of a 60 to 90 day wait after the first meeting while procurement and the security review run. An outreach software vendor's guide puts enterprise security deals at 6 to 18 months, many around 9 to 12, and credits only unnamed "industry analyses".
Neither shows a sample, and they measure different stretches: one starts at the first meeting, the other covers the whole deal.
The rules do tell you the shape.
First meetings depend on your list, your sender and your sequence, the same as in any B2B niche. Signed contracts wait for the buyer's supplier checks. Under NIS2, supplier security is a required measure. Under DORA, legal and procurement will read every Article 30 clause before signing.
So judge the first two months on held meetings with the right titles, and on how many of those meetings are tied to a dated trigger. Judge revenue later.
To shorten the tail, have your security pack ready before the first call: certifications, data locations, incident process, response times, and a contract that already carries the DORA clauses if you sell to financial firms.
How do you vet an outbound agency for a security company?
The usual agency checks still apply. These seven are specific to selling security, and each one can be tested on a single call.
- Ask what NIS2 or DORA changes for your buyer. A partner who says "fines up to EUR 10 million" has read a summary. One who talks about supplier checks, the incident clock or Article 30 contract clauses has read the text, and will write like it.
- Ask who they would contact at 3 of your target accounts. The answer should change with company size: the CISO at a large one, the GRC lead or CTO at a mid-size one. "IT decision makers" usually means a bought list.
- Ask to see the sending domain and the sender. A lookalike domain, or a sender with no real LinkedIn history, fails a security team's first check. Your brand carries that result.
- Ask how they verify addresses and what bounce rate they hold. My line is under 0.5%. If they cannot give a number, ask why.
- Ask for a sample first email for your offer. If it opens with a breach headline, a fear statistic or a fine figure, it will read like every other vendor in that inbox.
- Ask where their results numbers come from. A reply rate or meeting count for security buyers means little until you know out of what, over what period and for which title.
- Ask who owns the domains, mailboxes and prospect data, and how access is protected. An agency writing in your name becomes one of your suppliers. For a company that sells security, outreach accounts without multi-factor authentication are the wrong thing for a prospect to discover.
Short answers on reaching security buyers
Does cold email work for reaching CISOs?
It can, when the list is verified, the sender passes a technical check and the first line names a real trigger. Mass outreach to "IT decision makers" is where it goes wrong. In mid-size companies without a CISO, start with the GRC lead or the CTO.
Does NIS2 apply to security companies outside the EU?
It can. NIS2 covers in-scope entities that provide services or carry out activities within the EU, and managed security service providers are a listed type. A US or UK MSSP of medium size or larger serving EU clients should check with counsel. This is not legal advice.
How long does it take to book meetings with security buyers?
First meetings depend on list quality, sender setup and follow-ups, as in any B2B market. Contracts take longer, because the buyer must check you as a supplier. Published estimates range from a 60 to 90 day tail after the first meeting to 6 to 18 months per deal, none with a stated sample.
Which trigger should a security company act on first?
The one with a date attached. A compliance deadline, an audit or a new security leader gives you a window you can plan a sequence around. Funding and security hiring come next.
Should I contact a company right after its breach makes the news?
Not in the first days. They are dealing with the incident and hearing from other vendors. Wait, then offer help with what follows: the one-month final report, the supplier review or the audit questions. That reads as useful rather than opportunistic.
