Cold Calling for Cybersecurity Companies: The Vishing Test
For security vendors whose reps call security teams: who picks up by account size, why the buyer is trained to distrust the call, and what worked on recorded calls.

A security vendor's cold call reaches a listener trained by public CISA guidance to distrust unknown callers asking about internal systems. Security leaders may answer at 200 to 1,000 employees; at large enterprises the reachable contacts sit one or two levels below or behind a reseller. Calls that worked named an event already on the buyer's desk.
Key takeaways
- A buyer-side commenter in a 30 April 2025 r/sales thread, working at a roughly 80,000 employee organisation, says the CIO and CISO do not meet vendors and the people to reach sit 1 to 2 levels below.
- CISA tells staff to be suspicious of unsolicited phone calls asking about employees or internal information and to verify an unknown caller directly with the company, so a legitimate caller invites the call back.
- ISMG's Henry Kogan, after 300 weeks of listening to recorded security sales calls, singles out openers built on published guidance, a zero-day in the news and a peer's framework work, and warns against fear-based FUD.
- With no risk, role or regulation to name, Kogan's advice is not to call yet; the phone is also the wrong play where leaders meet only strategic vendors or the account buys through a partner.
Reviewed and updated September 18, 2026
Cold Calling for Cybersecurity Companies: The Vishing Test
A sales development rep at an endpoint security vendor dials a security operations manager at a regional bank. The manager has spent the morning running a phishing awareness session in which staff were told to be suspicious of unsolicited phone calls from people asking about internal systems. The rep's first question is which endpoint tool the bank runs today. The call lasts eleven seconds, and the manager did exactly what the training says.
This page is for the cybersecurity vendor whose own reps make the calls: a security software company, a managed security provider or a security consultancy calling security and IT teams. It covers what changes on a cold call in this one market, which is who answers, why the buyer is trained to distrust the call, what the calls that worked had in common, and when the phone is the wrong tool. The general method sits on other pages, starting with what cold calling is and which rules apply to a B2B call. Every outside source below was fetched on 18 September 2026.
Who answers, and it is rarely the CISO
The best buyer-side account in the search results for this topic is a thread on r/sales titled Cold Calling Cybersecurity, opened on 30 April 2025. A former security SDR describes booking meetings with CIOs and CISOs. A commenter who now works inside a global organisation of roughly 80,000 employees answers from the other side of the phone: "The CIO and CISO do not meet with vendors unless you are Microsoft or AWS. The people you want are 1-2 levels below the CIO or CISO." The former SDR agrees, and adds that the targets had been companies of 200 to 1,000 employees, where the security leader could still be reached.
So company size decides who picks up. The same commenter adds a second route that callers tend to forget, writing that with the volume of cold outreach it is "Far easier to engage a VAR or partner to seek out what is needed." In a large account the reseller may hold the relationship the caller is trying to open, which is the channel question that cybersecurity lead generation treats as a targeting constraint before anyone dials.
The people who did pick up in the recorded calls described by Henry Kogan of Information Security Media Group (ISMG) are a fair sample of the reachable layer. His piece is titled "What 1,500 Hours of Cybersecurity Cold Calls Taught Me" and reads as a field report: ISMG, 23 July 2025. The four were a cyber risk officer at a hospital network, a CISO new to the role at a mid-sized manufacturer, a privacy officer at a global SaaS provider, and a senior engineer at a regional bank. One of the four is a CISO, and that one had just started the job.
The buyer teaches the company to distrust this exact call
Every vertical has gatekeepers. This one has a buyer whose job includes training the whole company to refuse callers, and the training material is public.
The Cybersecurity and Infrastructure Security Agency's guidance on avoiding social engineering and phishing attacks defines vishing as the social engineering approach that leverages voice communication, and its first instruction to staff is blunt: "Be suspicious of unsolicited phone calls, visits, or email messages from individuals asking about employees or other internal information." The next sentence is the one a caller should plan around: "If an unknown individual claims to be from a legitimate organization, try to verify his or her identity directly with the company." The same page tells staff not to provide information about the organisation, including its structure or networks, unless they are certain of a person's authority to have it.
CISA's Recognize and Report Phishing page lists a phone call among the forms the bait takes and names urgent or emotionally appealing language as a common sign. The National Institute of Standards and Technology's small business phishing guidance tells employers to recognise that email is not the only way to get phished, and lists phone calls among the other routes.
Read those three pages as a description of a vendor's discovery call. An unknown individual, claiming to be from an organisation the listener cannot verify, asks which tools the company runs, how the team is structured and who owns the decision, with a time-limited offer attached. The Point Company, an agency that sells pipeline to security vendors, puts the conclusion in its own article on why a CISO will not take a cold call: "unsolicited contact from an unknown party asking for time and information is, by definition, the profile of a social engineering attempt." The agency is selling an alternative, and its framing still matches what the government guidance tells staff to do.
A legitimate caller can only respond by behaving the way the guidance says a legitimate contact behaves. Give a full name and company early. Ask nothing about the stack, the structure or the people in the first minute. Invite verification instead of resisting it: the listener can hang up, look the vendor up on its own website and call back through the main number, and a caller who suggests that has just done the thing a visher cannot.
What staff are told
- Be suspicious of unsolicited phone calls asking about employees or internal information
- Verify an unknown caller's identity directly with the company
- Give out nothing about structure or networks
- Treat urgent or emotionally appealing language as a sign
What the caller therefore does
- Full name and company early
- No question about the stack, the structure or the people in the first minute
- Invites a call back through the vendor's main number
- No time-limited offer, no urgency
What the calls that worked had in common
Kogan's piece rests on an unusual body of evidence. "For 300 weeks," he writes, he spent an hour each day listening to recorded cybersecurity sales calls between SDRs and security leaders. The five calls he singles out share one property: the caller brought the reason, and the reason was already on the buyer's desk.
One rep opened on regulatory guidance published the month before and asked whether the listener was responsible for those updates internally; the privacy officer on the line said the document was sitting on the desk. Another called during the week a zero-day in a widely used remote access tool was in the news, said plainly that it was a cold call, and offered to help validate patch coverage; the senior engineer took a technical walkthrough the next day. A third referenced a peer hospital network's work on a named framework and the listener, a cyber risk officer at another hospital network, booked within five minutes. Kogan's summaries are short: "Specificity builds trust." and "Empathy beats hype."
This is also the honest answer to when this industry answers. None of the sources fetched for this page publishes a best hour or a best day for calling security teams, and this page will not invent one. What the recorded calls show is that the window is an event: a published obligation, a disclosed vulnerability, a leader who has just arrived. Kogan puts the preparation at five to ten focused minutes per call, spent on breach trends, job shifts, vendor consolidation or architecture gaps.
What the call must never say
Kogan's list of why calls fail is one sentence long: "Forced rapport, fear-based FUD, and recycled buzzwords destroy trust." He follows it with a rule that belongs above every security SDR's monitor: "If you can't name a risk, role, or regulation your prospect actually cares about, don't call yet."
Fear is the failure that is specific to this market, because the product category invites it. One of the calls Kogan praises did mention a ransomware attack on a meat processor, and the rep's next words were that the team was not there to scare anyone. The line between the two is whose incident it is. Calling a company because a peer was breached is market timing. Calling a company because it was breached is ambulance chasing, and the live lead generation page for this vertical says it should simply not be done.
The other failure is the caller who is visibly working a quota. Eyal Worthalter, who sells in the security industry, described on LinkedIn being cold-called by a security startup's outsourced SDR firm. His three complaints were a wrong target, since he is in sales and not a buyer, zero qualification, and relentless pushing for a meeting. When he raised technical concerns by email, the answer each time was a request to get on a call. A security buyer asks technical questions early. A caller who cannot answer them, and cannot say who will by when, confirms the listener's first suspicion.
The objections, in the vertical's own words
The r/sales thread is a catalogue of what callers hear. The most common is the incumbent: the listener already has a provider for the category, which in this market is nearly always true. One commenter suggests raising it first. Another replies that doing so hands the listener an exit, and adds the point that matters most here: a stranger on a cold call will not be told who the company works with and what they do for it, because the listener is likely under a non-disclosure agreement and has no reason to share it. The answer is to stop asking. A caller who names the event, says what the vendor does about it and asks for a time has not needed the information.
The second objection is size. The contacts one or two levels down can give a technical conversation and cannot give a procurement slot, so the ask has to be one they can grant. The general taxonomy of call objections is in cold call objections sort into three buckets.
The rules a security call inherits
Nothing in United States calling law is specific to security vendors. The federal position on business-to-business calls, and the separate statute on autodialers and mobile numbers, are quoted and linked in is cold calling against the law, and this page adds no legal reading of its own. What is specific to this vertical is that the listener's employer has trained staff, from the CISA material above, to treat the call as a possible attack. A caller is bound by one regime and judged by the other.
When the phone is the wrong play
Three cases. First, the large enterprise whose security leadership meets only its strategic vendors: the thread's buyer says so directly, and the dial budget is better spent on the layer below or on the partner. Second, the account that buys through a reseller or a managed security provider, where a direct call competes with the vendor's own channel. Third, the caller with no event. Kogan's rule covers it.
Three openers, each tied to a source
These are shapes for a first twenty seconds. They name no real recipient, make no claim about the caller's results, and every bracket is the caller's to fill with something true.
The first follows the regulatory call Kogan describes.
This is {{name}} at {{vendor}}. {{regulator}} published {{guidance}} last month and it changes how {{control}} gets documented. Are you the person who owns those updates? If you would rather check who we are first, our main number is on {{vendor_site}} and we will take the call back.
The source is a published obligation, and the last sentence is the CISA instruction turned into an offer.
The second follows the zero-day call.
This is {{name}} at {{vendor}}, and this is a cold call. {{cve}} was disclosed on {{date}} and teams running {{product}} are checking patch coverage this week. We validate that across remote endpoints. Is a twenty minute technical walkthrough with {{engineer}} on {{day}} any use?
It asks nothing about the listener's environment.
The third follows the thread's advice about level and channel.
This is {{name}} at {{vendor}}. We are not trying to reach your CISO. We work with {{partner_type}} partners on {{category}}. Does {{company}} buy this through a reseller? Knowing that means we talk to the right people and do not cut across them.
It is a question a level-down contact can answer without disclosing anything sensitive, and it settles the channel question first.
Where calling sits next to written outreach
RevenueFlow runs email and LinkedIn for clients and does not cold-call, so this page describes the phone as this vertical's reality and takes no revenue from recommending it. The two channels fail differently, which the comparison of email and cold calling sets out. In security, written outreach has one structural advantage: a message can be verified at the reader's own pace, from the sender's domain to the company behind it, which is the behaviour the buyer's own training rewards. Our written campaigns carry one message each, with no bumps and no thread replies, and a new approach to the same account waits for a new event. If the list and the first message are the part you would rather not build, see what a first campaign would target.
The short version
A security vendor's cold call lands on a listener trained, from public government guidance, to treat an unknown caller asking about internal systems as an attack. At 200 to 1,000 employees the security leader may pick up; at a large enterprise the reachable people sit one or two levels below, or behind a partner. The recorded calls that worked brought an event the buyer already had on the desk, asked for nothing sensitive and did not trade on fear.
Frequently asked questions.
Frequently asked questions- Who actually answers a cold call at a security team?
- It depends on company size. A former security SDR in a 2025 r/sales thread reached CIOs and CISOs at companies of 200 to 1,000 employees. A commenter inside a roughly 80,000 employee organisation says its CIO and CISO do not meet vendors, and the people to reach sit one or two levels below. In ISMG's recorded calls the pickups included a risk officer, a privacy officer and a senior engineer.
- Why do security buyers distrust cold calls more than other buyers?
- Because they train their own companies to. CISA's public guidance tells staff to be suspicious of unsolicited phone calls from individuals asking about employees or internal information, and to verify an unknown caller's identity directly with the company. A vendor's discovery questions about tools, structure and owners match that description closely, so the call is judged as a possible social engineering attempt before it is judged as a pitch.
- What should a cybersecurity cold call never say?
- Nothing that trades on fear or on the listener's own incident. ISMG's Henry Kogan writes that forced rapport, fear-based FUD and recycled buzzwords destroy trust. Referencing a peer's public incident as market timing is one thing; calling a company because it was breached is ambulance chasing. A caller should also avoid asking about the stack or the team's structure in the first minute.
- When is cold calling the wrong play for a security vendor?
- In three cases drawn from the sources here. At a large enterprise whose security leadership meets only strategic vendors, the dials belong one level down. Where the account buys through a reseller or a managed security provider, a direct call cuts across the vendor's own channel. And with no risk, role or regulation to name, ISMG's advice is simply not to call yet.
About the author.
B2B cold email experts helping companies generate qualified leads through done-for-you outreach campaigns.
RevenueFlow Team
Explore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
Cold Calling for SaaS Companies: What Changes on the Call
The two calls a software company makes, who picks up in crowded and uncrowded categories, how the first thirty seconds go, and why a SaaS list is a mobile-number list.
Cold Calling Scripts for SEO Agencies: After Google's Warning
Six call scripts for SEO agencies calling local businesses, written around what Google and the FTC tell owners about this call: no Google tie, no ranking guarantee.
Merchant Services Cold Calling Scripts: The Honest Version
Six call scripts for merchant services agents and ISO reps, built around what the FTC alleged about this exact call: no affiliation claim, no rate before a statement.
Appointment Setting for 3PL Companies: Fit Before the Calendar
For 3PLs, warehousing operators and brokers wanting shipper meetings: the five fit gates, the bid calendar, contract terms, the trade's rules and three openers.
Sales Outsourcing for SaaS Companies: What to Hand Over
For SaaS companies weighing an outside sales team: what the industry's own survey found, what a third party cannot hold in a software sale, and what can go out.
Cold Call Openers: Eleven Lines by Situation, and the Data
Eleven cold call openers sorted by what is true about the call, the four beats every opener has, and what Gong's 2018 opener study actually counted.