Skills / Finding the buyer / First CISO conversations

How do I get my first 10 CISO conversations when nobody has heard of us?

One practitioner they already listen to is worth more than any sequence you could write.

first-ciso-meetings

SKILL.md · 1,904 words

Verified Sept 2026

Download the folder
What your agent reads.
name
first-ciso-meetings
description
First conversations with CISOs and security buyers for a cybersecurity company nobody has heard of. Covers cold outreach to security leaders, practitioner-first versus CISO-first entry, what to ask for in a first meeting instead of a demo, when to spend investor introductions, how many follow-ups to send, the sending-domain rules a cold domain runs under, and building a named-account list by hand before enriching it with tools such as Clay or Sales Navigator. Use when a founder has no network into security buyers, is drafting a first outbound sequence, is getting no replies or landing in spam, is asking how many follow-ups are too many, or is being offered CISO intros. Not for paid CISO dinners or matchmakers (ciso-dinners-and-matchmakers); not for choosing the lead-data vendor (lead-list-services); not for the discovery interview once the meeting exists (buyer-discovery); not for paid design partners (design-partners); not for advisor pay (ciso-advisor-equity).
title
First CISO conversations
question
How do I get my first 10 CISO conversations when nobody has heard of us?
subtitle
One practitioner they already listen to is worth more than any sequence you could write.
summary
You will not get ten conversations with security leaders by cold email, because they get dozens of vendor emails a week and ignore nearly all of them. The first ten come through practitioners who vouch for you and through your investors' introductions, which are the warmest meetings you will get, so spend those wisely and do not expect every one to fit.
group
buyer
verified
2026-09-09
order
31

976 / 1024 characters

This is the top of the SKILL.md file, exactly as it downloads. Your agent reads the description field to decide when to load this skill. The rest of this page is for you.

You are asking for time from people who get dozens of vendor emails a week and ignore nearly all of them. Nothing in the general advice about outbound email was written for that. The founders who get their first ten conversations do not arrive as strangers. Someone brings them in, they ask for something a security leader can give without trusting them, and they spend their investors' introductions wisely.

Your cold email is one of dozens.

You are an unknown vendor writing to someone who gets dozens of notes like yours every week, and nearly all of them get deleted on the first line. A cold note from a security startup starts as noise, not as a threat, and the buyer's team notices the tooling behind it more than most people would.

Remove everything that ordinary sales tooling adds. Send no tracking link, no link shortener, no attachment, and never from a second domain bought to protect the first one. Send from your company's own domain, correctly authenticated. A founder who will not send from their own domain has already answered the buyer's question about them. Make yourself checkable in one search, with a real name, a company page that resolves, and a street address in the signature.

The message was never the problem. The way in was.

Your ten may not be CISOs.

You may be naming the wrong ten people. Budget goes to named programs with an owner, a deadline, and an audit behind them, and the person measured on that program is the person you want to talk to. Often that person sits in engineering, IT, risk, or legal, and the CISO is in the room but signs nothing.

We have watched companies spend two or three quarters selling to an audience that loved them and could not buy. Before you write the list, write the obligation your product discharges in the buyer's words, and name the function that owns it. If that function is not the CISO, your ten are not CISOs.

Then write two names for each account: the practitioner who runs the control, and the executive who is measured on it.

Get a practitioner to bring you in.

You are being judged in rooms you cannot enter. A CISO forms an opinion of you among peers, in the regional group, the private Slack, the dinner with other security leaders. Most of those rooms do not admit vendors, and the ones that do charge for it. A few, such as the regional groups and the industry information-sharing sessions, will seat an engineer from a vendor who shows up to contribute rather than to sell.

The way in is to be brought in, almost always by a practitioner the CISO already listens to. That person does three things for you. They vouch for you. They give you the buyer's own words for the problem. And they become a second contact inside the account, which matters because the executive you meet this year is often not in the seat at renewal time.

Earn the practitioner first. Write the engineering document a skeptical engineer would accept, covering what the product touches, how it fails, and what it needs, before you write a single sales email.

Four ways in when you know nobody.

You will be told to get brought in and then left standing outside. There are four kinds of path, and none of them can be bought.

The first is a former colleague, yours or a customer's, who now works inside the account. The second is a customer's peer in the same city, whom your customer will introduce. The third is a practitioner community you take part in as an engineer. The two open communities that admit vendor engineers on their own rules are the OWASP Slack and, for endpoint work, the MacAdmins Slack, and you show up there to answer questions, not to post about yourself. The fourth is a substantive reply to something the person published, a talk, a post, or a tool, that shows you read it and have something to add.

Write the path next to every account before you write a note. No path, no message.

Ask for what costs them nothing.

You are not asking for a demo, not in the first ten conversations. A demo asks the buyer to spend attention on software from a company they have no reason to trust. The exception is a product that shows a buyer their own exposure in a minute, where the demo is the question. Otherwise, ask a question only they can answer: how do you handle this obligation today, who owns it, what did the last audit say, and is this real for you.

Add one question nobody asks. How long did your last vendor take to get through procurement and security review? Their yes will be the start of a review that runs for months, and the answer tells you what you are really selling into.

The first ten conversations are research, not selling. Run them that way and the buyer will tell you things a prospect never would. When a reply comes, answer it yourself within minutes, because a security leader's reply is rare and the moment you are still on their mind is the cheapest advantage you will get. Leave every conversation with a second name in a different reporting line: who else lives with this problem, and who would object to your solution.

Write the list by hand.

You will be told to buy a data tool and turn on outbound. Do the arithmetic first. Twenty names at a reply rate of two or three in a hundred is less than one reply. Cold email is not the tool that produces ten conversations with security leaders at this size. The practitioner path is. Send cold email only to the accounts where you cannot find a path, and only with a first line specific enough that it could not have gone to anyone else.

No list vendor can target a buyer for a category that has no name yet. The only list that works is one a person wrote, account by account. Then let the tools enrich it, in this order. Start with the org chart, to learn who runs detection, identity, and application security under the security leader. Then the technology they run, to learn what sits next to you. Then the email address, last, and verify a sample by hand before you send.

Before you buy a single name, look at the inbound you already have. If nobody is following up on it, that is your first finding. If there is none, that is a bigger one.

Send two follow-ups, then stop.

Every sales tool gives a different number of touches, and none of those numbers was measured on people who are paid to be suspicious.

Send an opening note and two follow-ups, a week apart. A security leader who has ignored two good notes has decided, and a fourth note only confirms the decision. After the second follow-up, the schedule ends. What restarts a dead thread is an event the buyer already feels: an audit finding, a mandate with a date, a new owner of the obligation. Follow up on those, and only those.

Spend introductions wisely.

Ask your investors for introductions to security leaders. They are the warmest meetings you will get, and we make them for every company we back. What an introduction buys is the meeting. It does not buy the budget, and it does not make the buyer's problem match your product, so do not expect every one to fit.

Know what an investor hears when the network is the plan. A founder who pitches a fund's introductions as their route to market has told that fund they do not have one. Ask for introductions when you are already winning without them. Your investors expect you to produce a customer with no help; the introductions make a working motion faster, and they never substitute for one.

Spend them wisely, because an introduction is a loan of someone's credibility, and each one can be spent once. Ask for the accounts where the product is ready for a senior buyer's first look, since a buyer who sees an unfinished product does not look again until their next renewal. And use them on deals that are already moving as well as on new ones. One of the best questions you can ask an introduced security leader is why a deal that has stalled is not moving.

Tell your investor what you learned from each introduction. That is how the next one gets better.

Write one good note. Measure at six weeks.

You need one note that works, not a sequence. Here is its shape. Two lines on who you are and where you and the reader have both worked. One line naming the obligation in their words. One question only they can answer. No link and no attachment. Your name and your address. The note to a practitioner is shorter still: I read what you wrote on this, here is what we found, would you look at the design and tell me where it is wrong.

Then measure. Of twenty names with a path, you should be talking to four within six weeks. If you are talking to none, the sequence is not the problem. The obligation sentence is wrong, or the ten are the wrong ten.

Working the question.

  1. Write the obligation your product discharges in the buyer's words, and name the function that owns it. If it is not the CISO, your ten are not CISOs.
  2. Write ten accounts by hand, then two names for each: the practitioner who runs the control and the executive measured on it.
  3. Write the path to each account, whether a former colleague, a customer's peer, a community you take part in, or a reply to something they published. No path, no message.
  4. Check the inbound you already have before you enrich anything. Then enrich the org chart, the technology, and the address, and verify a sample by hand.
  5. Ask a question only they can answer about a program they are measured on, and ask how long the last vendor took to get through. Do not ask for a demo unless the demo shows them their own exposure.
  6. Send one note and two follow-ups a week apart, from an authenticated domain with nothing attached. Answer replies yourself within minutes. After that, only an event restarts the thread.
  7. Use your investors' introductions on accounts where the product is ready for a senior look, tell them what you learned, and do not expect every one to fit. Never present them as your route to market.
  8. At six weeks, count the conversations. Four of twenty means it is working. None means the sentence is wrong, not the sequence.

Working with an agent.

Give your agent your ten target accounts and your last ten call notes. Ask it to name the path into each one: a former colleague who works there, a customer who will introduce you to a peer, a practitioner community you already take part in, or a reply to something that person published. Any account it cannot name a path for is not ready to be written to. Drop it and find another.

Install the skill.

You are reading the skill itself — this page and the download are the same files. Unzip it into ~/.claude/skills/ (or a project’s .claude/skills/) and Claude Code loads it when the question comes up; so does any agent that reads Agent Skills.

mkdir -p ~/.claude/skills && cd ~/.claude/skills && curl -sLO https://techoperators.com/skills/first-ciso-meetings.zip && unzip -oq first-ciso-meetings.zip && rm first-ciso-meetings.zip

first-ciso-meetings/SKILL.md

No terminal? Download first-ciso-meetings.zip and drop into your assistant’s project files.

Kevin Skapinetz

Tell us what you see.

Whether you’re thinking about starting a company, building one in stealth, or raising a round: send Kevin or Dan what you see on LinkedIn, in your words.