How to Cold Email CISOs: What Actually Gets a Reply
CISOs get pitched dozens of times a week. What their inbox looks like, the angles that resonate, four copy-paste templates, and the best send windows.
To cold email a CISO, lead with budget displacement, analyst workload, or audit evidence rather than fear or breach statistics. Reference peer companies of the same size and regulatory regime, keep the first email under 120 words, ask for a document instead of a demo, and send plain text with clean SPF, DKIM, and DMARC records.
Key takeaways
- Average security budget growth slowed to 4% year over year in 2025, down from 8% in 2024, so most CISO purchases now require displacing an existing tool rather than adding one.
- Proofpoint's 2025 survey of 1,600 CISOs found 76% believe a material cyberattack is likely in the next 12 months while 58% say their organization is unprepared to respond.
- Reported average CISO tenure runs 18 months to three years versus roughly 5.2 years for the average S&P 500 C-suite executive, which pushes buyers toward wins visible inside 12 months.
- Fake vulnerability disclosure openers ('we scanned your perimeter and found exposures') are the fastest route to being blocked and shared on peer block lists.
- Offering a document (evidence pack, architecture diagram, peer benchmark) converts better than asking for a 30-minute demo on the first touch.
- Send plain text with no tracking pixels, no link shorteners, and no first-touch attachments, because security orgs run the most aggressive filtering in the enterprise and will inspect your headers.
Reviewed and updated July 31, 2026
How to Cold Email CISOs: What Actually Gets a Reply
A security leader at a 4,000-person company sits down Monday morning to 60 unread messages. Nine are vendor pitches. Three of those claim to have "identified critical exposures" in the company's external attack surface. One opens with "I noticed you're the CISO at [Company]." Two are follow-ups from sequences the CISO never replied to in the first place. All nine get archived in under 40 seconds, and at least three of the senders get added to a personal block list that the CISO shares with peers in a private Slack group.
This is the baseline condition of the role. CISOs are among the most aggressively prospected buyers in B2B, and they have developed fast pattern-matching for anything that smells like a template. The bar for standing out is low, because almost nobody bothers to understand what the job actually involves.
What the CISO Job Actually Is
The title suggests a technology role. In practice, most CISOs spend the majority of their week on things a network engineer would not recognize as security work: budget defense, audit and compliance evidence, board and audit-committee reporting, cyber insurance questionnaires, third-party risk reviews, and hiring into a team that is chronically under-resourced.
Three structural facts shape every buying decision they make.
They are personally exposed. Since the SEC's cybersecurity disclosure rules and the SolarWinds enforcement action, CISOs at public companies carry legal and reputational risk that other executives do not. This makes them conservative about anything that creates new evidence trails, new data-processing agreements, or new claims they would have to defend later.
Their budgets are tightening. Average security budget growth slowed to 4% year over year in 2025, down from 8% the prior year and the slowest rate in five years. Source: IANS Research and Artico Search. A CISO who wants your product usually has to displace something else in the stack to pay for it, which means your email is competing against renewals, not against nothing.
Their tenure is short. Reported average CISO tenure sits between 18 months and three years, against roughly 5.2 years for the average S&P 500 C-suite executive. Source: Computer Weekly. A short-tenured executive optimizes for visible wins inside a 12-month window, not for platform bets that pay off in year three.
Write to those three facts and your email will already read differently from the other nine in the inbox.
What They Are Judged On
Boards do not ask CISOs about their EDR agent count. The metrics that show up in a CISO's board deck and performance review are narrower than most vendors assume:
| What the board asks about | What it means operationally |
|---|---|
| Material incidents and near-misses | Did anything happen that requires disclosure |
| Mean time to detect and mean time to respond | How fast the SOC actually moves |
| Coverage and control gaps | Percentage of assets, identities, and endpoints under management |
| Audit and regulatory findings | Open findings from SOC 2, ISO 27001, PCI, HIPAA, DORA, NIS2 |
| Third-party and supply chain risk | Vendor inventory, concentration risk, unresolved questionnaires |
| Cost per unit of risk reduced | Whether the program is getting cheaper or more expensive to run |
Proofpoint's 2025 survey of 1,600 CISOs across 16 countries found 76% believe their organization is at material risk of a cyberattack in the next 12 months while 58% say they are unprepared to respond, and 66% reported a material data loss in the prior year with human causes at the top of the list. Source: Proofpoint. That gap between perceived risk and readiness is the single most reliable emotional hook in this persona, provided you do not turn it into fear-mongering.
The Angles That Resonate
Displacement math. A CISO with 4% budget growth cares intensely about anything that lets them retire a tool. "Three of your peers replaced [Category Tool] with us and cut annual spend by roughly a third" is a legitimate business conversation. It gives the CISO something to bring to the CFO.
Reduction in headcount drag. Security teams are small and burned out. An email that leads with analyst hours reclaimed, alert volume reduced, or tickets closed without a human touching them is speaking the language of a leader who cannot hire.
Audit and evidence automation. If your product produces artifacts that satisfy an auditor, say so plainly. "Generates the access-review evidence your SOC 2 auditor asks for" is worth more than any capability claim.
Peer proof at their exact size and vertical. CISOs trust other CISOs far more than they trust vendors. Naming two companies of comparable size in the same regulatory regime is the fastest credibility shortcut available.
A specific, non-alarming observation. Referencing something real and publicly visible (a recent acquisition, a new cloud region, a job posting for an identity engineer, a compliance certification they just announced) shows you did work. Keep it factual.
The Angles That Get You Deleted
Fake vulnerability disclosure. "We scanned your perimeter and found exposures" is the single fastest way to get blocked. It reads as unauthorized scanning, it triggers legal concerns, and CISOs discuss these senders with each other.
Fear as the opening move. Leading with breach statistics, ransomware headlines, or "the average cost of a breach is X" marks you as someone who has never sat in a security leadership seat. CISOs live in that data all day and have built immunity.
Compliance deadline panic. Manufactured urgency around DORA, NIS2, or the SEC rules signals that you are selling to the calendar rather than to the problem.
The 30-minute demo ask on email one. Their calendar is the most contested resource they own. Asking for half an hour before establishing anything is a non-starter.
Vague AI positioning. "AI-powered threat detection" now carries close to zero information. If AI is central to your product, describe the specific decision it makes and what happens when it is wrong.
Four Emails That Get Replies
Template 1: The Displacement Email
Subject: replacing {{incumbent_tool}} at {{company_size}} orgs
{{first_name}},
Most security teams your size are carrying two or three tools that
overlap on {{capability_area}}. When budgets flattened this year, that
overlap became the easiest line to cut.
{{reference_company_1}} and {{reference_company_2}} (both around
{{employee_count}} employees, both {{compliance_regime}}) consolidated
{{incumbent_tool}} into us. The consolidation itself was the business
case, the detection improvement was secondary.
Worth a 15-minute look at the before-and-after stack diagrams from
those two? I can send them over without a call if that's easier.
{{sender_name}}
{{sender_title}}
Why this works: It opens on budget rather than threat, which matches the actual pressure the role is under. It names peer companies with matching size and regulatory context. The ask offers an asynchronous option, which respects a calendar the CISO guards carefully.
Template 2: The Analyst Hours Email
Subject: {{alert_type}} triage volume
Hi {{first_name}},
Quick question rather than a pitch. How many analyst hours a week is
your team spending triaging {{alert_type}}?
The reason I ask: teams running {{their_siem}} at your scale usually
tell us it's somewhere between 12 and 20 hours, and most of that ends
in "no action required." We take that work off the queue before it
reaches a human.
If your number is lower than that, genuinely ignore this. If it's
higher, I'll send you how {{reference_company}} measured the change.
{{sender_name}}
Why this works: It asks a question the CISO can actually answer, and gives them a permission-to-decline exit that makes replying feel low risk. It anchors on a workload metric rather than a fear metric, and it references their existing stack, which proves research.
Template 3: The Audit Evidence Email
Subject: {{framework}} evidence for {{control_area}}
{{first_name}},
Saw {{company}} announced {{recent_certification_or_expansion}} in
{{month}}. Congrats, that's a heavy lift.
The part that usually gets painful in year two is producing
{{control_area}} evidence on a recurring basis: access reviews,
change approvals, and the screenshots nobody wants to own.
We generate that continuously so the auditor pulls it themselves.
{{reference_company}} cut their {{framework}} evidence collection
from about three weeks of internal time to a couple of days.
Want the sample evidence pack? No call needed, I'll just send it.
{{sender_name}}
Why this works: It anchors on a public, verifiable event rather than a fake insight. It names a specific operational pain that only someone familiar with audit cycles would know about. The offer is a document, not a meeting, which converts far better at this level.
Template 4: The Deputy Path Email
Subject: right person for {{capability_area}} at {{company}}?
{{first_name}},
You're probably not the person who evaluates {{capability_area}}
day to day, so this may be a redirect.
We work with {{reference_company_1}} and {{reference_company_2}} on
{{specific_outcome}}. Their {{deputy_title}} owned the evaluation and
brought it to the CISO with the consolidation numbers attached.
If that's how it works at {{company}}, who should I be talking to?
Happy to go through them rather than around them.
{{sender_name}}
Why this works: Asking for a referral downward is a genuinely easy reply for a busy executive, and CISOs frequently do delegate evaluation to a Director of Security Engineering, Head of GRC, or Deputy CISO. The line about going through rather than around signals that you will not try to pressure their team from above, which is a real fear.
Send Timing
CISO calendars are dominated by standing meetings, incident reviews, and audit windows. A few timing patterns hold up in practice:
- Early morning, 6:30 to 8:00 in their local time zone. Many security leaders clear their inbox before the day's meetings begin. Emails landing at 10am get buried under whatever the day produced.
- Tuesday through Thursday. Monday is status meetings and weekend incident review. Friday afternoon is when incident response tends to get busy, since attackers know it too.
- Avoid the last two weeks of a quarter if the company is public, and avoid the weeks immediately following a disclosed breach anywhere in their industry, when every CISO is fielding board questions.
- Budget season matters more than day of week. For most calendar-year companies, security budget planning runs from roughly August through October. An email that arrives in September with displacement math attached is arriving at the exact moment the CISO is building a spreadsheet.
- Never send during a known incident. If their company is in the news for a security event, wait. Vendors who pitch during a breach are remembered permanently.
How to Reference Their Metrics Without Sounding Like a Vendor
The mistake most senders make is claiming an improvement to a metric they cannot possibly know. "We'll cut your MTTR by 40%" is unfalsifiable and reads as noise.
The alternative is to reference the metric as a shared frame and let the CISO supply their own number:
- Instead of "reduce your MTTD," write "teams tell us the detection gap is worst on {{specific_surface}}. Is that where yours sits?"
- Instead of "improve your security posture," write "what does your coverage number look like on unmanaged endpoints?"
- Instead of "save you money," write "if you consolidated {{tool_a}} and {{tool_b}}, what would that free up?"
Every one of those is answerable in a single line, which is the only kind of reply a CISO has time to write. A one-line reply is a conversation. That is the entire goal of the first email.
Deliverability Is a Bigger Problem Here Than Anywhere Else
Security organizations run the most aggressive email filtering in the enterprise, often the same products they sell or buy. Assume link rewriting, attachment stripping, sandbox detonation, and banner warnings on external senders. Practical consequences:
- Send plain text with no tracking pixels. Open-rate tracking gets you flagged and, in security orgs, actively resented.
- Avoid link shorteners entirely. Use full URLs on a domain that has been warmed and has clean DNS records.
- Do not attach anything on the first email. Offer to send the document after they reply.
- Get SPF, DKIM, and DMARC right before you send a single message. A CISO who checks your headers and finds a misconfigured DMARC policy has learned everything they need to know about your company's security hygiene.
That last point is worth sitting with. When you email a security leader, your own infrastructure is part of the pitch. Teams that run outbound to security buyers, including agencies like RevenueFlow that manage the domain and inbox layer for clients, treat authentication and domain reputation as a credibility signal rather than a technical checkbox.
The Sequence Shape
Four to five touches over four to six weeks, each carrying new information. No "just bumping this to the top of your inbox."
- Email 1: The angle (displacement, workload, or audit evidence). Under 120 words.
- Email 2, five days later: A specific artifact. A one-page architecture diagram, a peer benchmark, a sample evidence pack.
- Email 3, eight days later: A different angle entirely. If email one was budget, make this one operational.
- Email 4, two weeks later: The deputy path. Ask for a redirect.
- Email 5, three weeks later: A clean close. "Assuming this isn't a priority right now. I'll check back after budget season unless you'd rather I didn't."
Reply rates at this level stay low in absolute terms. The compensating factor is deal size and the fact that a CISO who replies is usually the actual decision maker rather than a coordinator, so the meetings you do book convert at a far higher rate than mid-market outbound.
Getting This Right at Volume
Everything that makes CISO outreach work (peer references matched to company size and regulatory regime, awareness of budget cycles, clean sending infrastructure, restraint about the ask) resists automation. Most teams either send generic volume that gets blocked, or send genuinely good emails to 30 people a month and never build a pipeline.
If you would rather have this built and run for you, including the domain infrastructure, list research, and sequence copy calibrated to security buyers, book a strategy call and we will map out what a CISO-targeted campaign would look like for your offer.
Frequently asked questions.
Frequently asked questions- What is the best subject line for a cold email to a CISO?
- Short, lowercase, and specific to an operational reality rather than a benefit claim. Lines like 'replacing [incumbent tool] at 4,000-person orgs' or '[framework] evidence for access reviews' work because they name something concrete. Avoid anything containing 'partnership opportunity', 'quick question' with no context, or claims about vulnerabilities you supposedly found.
- Should I email the CISO directly or their team?
- Start with the CISO for the framing conversation, but expect the evaluation to sit with a Director of Security Engineering, Head of GRC, or Deputy CISO. A referral-request email asking who owns a capability area is one of the easiest replies for a busy executive to send, and going through their team beats going around it.
- When is the best time to cold email a CISO?
- Early morning, roughly 6:30 to 8:00 in their local time zone, Tuesday through Thursday. Budget season matters more than day of week: for calendar-year companies, security planning typically runs August through October, so consolidation and cost arguments land hardest in September. Never send during a disclosed incident at their company.
- Do fear-based cold emails work on security buyers?
- Rarely. CISOs read breach statistics and threat intelligence all day and have built immunity to them. Leading with ransomware headlines or average breach cost figures signals that the sender has never held a security leadership role. Budget displacement, reclaimed analyst hours, and audit evidence automation are far more likely to earn a reply.
- Why do my cold emails to CISOs never get delivered?
- Security organizations run the strictest filtering in the enterprise, including link rewriting, attachment sandboxing, and external-sender banners. Tracking pixels, link shorteners, first-touch attachments, and misconfigured SPF, DKIM, or DMARC records all increase the odds of being filtered. Plain text from a warmed domain with correct authentication is the baseline requirement.
About the author.

Ben Carden is CRO at RevenueFlow, which builds and operates outbound revenue engines for B2B companies. Previously at Gartner Enterprise. Studied at London School of Economics.
Ben Carden ยท CRO
Connect on LinkedIn โExplore more.
Ready to scale your outreach?
We build GTM engines that book real meetings. See the receipts.
Related articles.
How to Cold Email Plant Managers: What Actually Gets a Reply
Plant managers read email on a phone before shift start and delete anything generic. Here are the angles, send windows and templates that earn replies.
How to Cold Email Procurement Managers: What Actually Gets a Reply
Procurement managers sort vendor email by one question: does it help the savings number? Here are the angles, templates, and send windows that get replies.