CISOs are the hardest buyer persona in B2B technology. They are trained to be skeptical, they receive more vendor outreach than almost any other title, and they view unsolicited emails as a potential social engineering vector. Defendify had a high ACV at $120K+ per deal but the lowest reply rates of any ICP the sales team had targeted. Previous outbound efforts had generated a 0.8% reply rate with nearly zero positive responses. The total addressable market of SMBs with a dedicated CISO was also relatively small, roughly 12,000 companies in the US, so burning contacts with bad outreach had a real cost.
We took a low-volume, high-research approach. Approximately 800 emails per month targeting CISOs at companies that had disclosed a vendor change, completed a compliance audit, or experienced a publicly reported security incident in the past 90 days. We used technical, peer-level copy with zero marketing language. Every email referenced the prospect's specific tech stack by name: if they were running CrowdStrike for endpoint but had no visible SIEM, we mentioned that gap specifically. Subject lines were kept under 4 words, lowercase, no punctuation, designed to look like an internal forward. We ran only 2 follow-ups per sequence because CISOs who do not reply to the first 2 emails will not reply to the 5th. LinkedIn was not effective for this ICP, so we dropped it after month 2 and reallocated those touches to a second email sequence with a different angle.
Key Insight: CISOs responded 3x more to emails that referenced their existing security tools by name. Tech-stack awareness in the first line was the difference between spam and a reply. It signaled that the sender had done real research, not just pulled a list. 38 meetings at $120K+ ACV created $1.9M in pipeline, more than 100 meetings with a $15K product would have. The lesson: for high-ACV deals, fewer hyper-targeted contacts will always outperform volume.
Let's talk about building a pipeline system for your team.
Book a Strategy Call →