Seven solutions. And a buyer
already waiting for every one.

Prepared for
James Spencer · Secfolio
Selling
Secfolio, into security leadership at mid-market and enterprise
Prepared
August 2026 · Charm

On our call you said the thing most founders never get to: you know what you sell and why it is different. Architect resilience instead of detecting failures. Invest from the impact inward. That is a point of view, and most value-added resellers do not have one. It is also the part of an outbound build that normally takes six weeks and a fight.

So the work ahead is not strategy. It is aim. Each of your seven solutions has its own buyer, its own budget line, and its own moment it becomes urgent, and every one of those moments is already public. This document turns your seven into seven separate answers to why me and why now, and points each one at the people living that problem this month.

Charm builds and runs outbound for
Hello Hero Rightworks VirtualFork Ben's Bites Highline + others

01 / SituationWhat we can see from the outside.

Note on this section

Everything below comes from our first call and from public sources: secfolio.com, the seven solution pages, your three-step prevention framework, and your own background as you described it. Nothing here assumes your margin per deal, your deal registration terms with any vendor, your close rate, or your average cycle length. Where we would normally use your numbers we left the question open and put it in section 09. Correct anything that is wrong on Wednesday and we will rebuild around it.

Why you'll win

You already did the part that usually takes six weeks and an argument.

1

You have a point of view, which almost no reseller does

"Beyond detection, architect resilience" is a position, not a product list. So is "invest from the impact inward." Most engagements burn the first month deciding what the client actually stands for, because most clients sell whatever the vendor sheet says that quarter. Yours is written, published and consistent across seven pages. Every campaign in section 04 inherits it instead of inventing it.

2

Seven named solutions is seven campaigns, not one message

Cyber storage, post-auth data security, passwordless, identity microsegmentation, defensive automation, deepfake security, external exposure management. Each one has a different buyer, a different budget line and a different moment it becomes urgent. Most clients arrive with one product and one angle and we have to manufacture variety. You arrive with seven real ones, which is why the campaign count in section 08 is the number that matters most in this document.

3

Your buyer is enumerable and the moment they need you is public

Security leadership changes are announced. Acquisitions are announced and dated. Identity and security architect requisitions are posted. Breach notifications are filed with state attorneys general and, for public companies, with the SEC. Cyber insurance renews on a calendar. None of that is bought data. It is public, dated, refreshable weekly, and it answers the only two questions cold outbound survives on: why this company, and why this week.

4

Reseller economics let you lead with the problem instead of a product

You are not defending one vendor's roadmap, so you can open on the exposure and let the tool arrive later in the conversation. A security leader will read an email about a pathway. They will not read an email about a platform. Every vendor selling direct into your accounts is structurally unable to write the email you can write, and that is an advantage that lasts as long as you stay tool-agnostic in the first touch.

5

In a trust sale, the founder is the asset, and yours is unusually specific

Business plus security and risk analysis at Penn State, then sales and support at the largest Microsoft partner while the Fortune 500 moved to cloud, then a penetration testing company before Secfolio. You can explain the mechanism, not just the outcome, and you can do it to someone technical without a deck. A larger reseller can outspend you on everything except that. Section 04 is built to put you in front of people rather than a brand nobody knows yet.

What's in the way

Nobody has heard of Secfolio, and in security that is the entire first meeting.

1

You have no published proof, and this is a proof-gated category

Founded 2024, no customer stories on the site, no named references, no logos. Everyone selling security says the same three sentences you do, so the buyer's real filter is not the pitch, it is whether anyone they recognise has trusted you. This is the tightest constraint in the engagement, tighter than volume, tighter than deliverability, and it is why section 09 asks for one customer story before it asks for anything else.

2

Seven solutions on one homepage reads as a menu, and a menu reads as a reseller

The strength in section one is also the problem. Every visitor currently gets all seven, so a CISO with a ransomware recovery problem and a CFO with a deepfake wire-fraud problem land on the same page and both have to do the sorting themselves. They will not. The fix is not to cut anything. It is to give each pillar its own audience, its own trigger and its own landing point, which is exactly what a campaign is.

3

This is a reduce-risk sale, which carries far more scrutiny than a make-money sale

There are three parent offers in business: make me money, save me money, save me time. Yours reduces risk, which sits at the far end of that scale. More touchpoints, more people in the room, a longer cycle, and expertise has to be demonstrated before anyone books. That is not a problem to solve, it is a shape to plan for, and it changes the copy, the channel mix and what we count as progress in month one.

4

Email alone will underperform here, and we would rather say that now than discover it in month two

From the cybersecurity engagement we have run for about a year: email did fine. LinkedIn did considerably better. And the format that outperformed both was a small recurring session with no pitch in it. Security buyers open your profile before they answer your email, because the first thing they are assessing is whether you are a real person. So LinkedIn is not a secondary channel in this build. It is the lead channel, and it is live in week one because it needs no warming.

5

You are the only closer, and the same calendar has to deliver the work

Every meeting we book lands on one person, and that person is also the architect, the implementer and the vendor relationship. Volume is not your constraint. Your week is. Which means the goal is not the largest number of meetings, it is the highest-quality meeting per hour you can spare, metered to a ceiling you set. That gets its own section, straight after section 04.

02 / ApproachFounder first. Public triggers second. Never a bought list.

We don't buy you a list.
We build one out of public moments.

Buying a list of CISOs is the single most commoditised thing in outbound. Every reseller in the country has the same one, and a security leader can smell it from the first line. So we do not start there.

First, you. Your LinkedIn, your network and your existing conversations. Founder-led, no variables, no automation voice, and live in week one because nothing needs to warm.

Second, the trigger datasets. New security leadership in seat, closed acquisitions, open identity requisitions, breach notifications, insurance renewal cycles. Public, dated, refreshed weekly.

Third, the channel you already sit inside. You resell six tools. Those vendors have channel teams, deal registration and co-marketing budgets, and there are MSPs with no security architecture practice. That is a partner motion, not a cold one.

Fourth, the room. A small recurring closed-door session, which is the format that has beaten email outright in this category for us.

Then all of it gets metered to your calendar, not to our sending capacity.

Step 01 · Activate

Your profile, your network, your voice

Two LinkedIn seats run human-paced and proxied. Founder-led copy with no merge fields, because a security leader will spot one and it costs you the meeting.

→ Live in week one
Step 02 · Enumerate

Public moments, read as a target list

Leadership changes, closed acquisitions, identity and security requisitions, breach notifications, renewal cycles. Resolved to a named human, scored by how recent the trigger is.

→ A self-refreshing engine
Step 03 · Partner

Vendor channel and MSPs

The six vendors you already resell, their channel teams and their installed bases. Plus MSPs with no architecture practice. Partnership copy, not sales copy, and it compounds.

→ One relationship feeds years
Step 04 · Meter

Down to what one calendar can hold

You set the weekly ceiling at kickoff and grade every meeting. Campaigns producing meetings you would not take again get paused that week, not at the end of the month.

→ Quality is the throttle
The band we would start with, for you to argue with on Wednesday

You asked how we define mid-market plus, and you were right to, because everybody cuts it differently. Here is our opening cut for Secfolio. It is a starting band, not a finished ICP, and the whole point of the kickoff session is that you move these numbers.

Parameter
Opening cut
Why
Where it moves
SegmentMid-market and up
$20M+
Revenue primary
headcount secondary
Revenue reads spend better than headcount does. Very large companies can run very small teams, so headcount alone puts you in front of people with no budget authority.
HeadcountSecondary filter, not primary
100+
Filter, not target
used to exclude
Below roughly a hundred people there is usually no dedicated security function, so the buyer you want does not exist and the sale becomes an IT generalist conversation.
Titles Director and aboveCybersecurity lineage only
4 tiers
Senior manager excluded
director champions, VP+ buys
CISO, CIO, VP Security, Director of Identity and Access, Security Architect, Head of Infrastructure. A senior manager cannot approve this. A director can champion it and start it moving.
IndustriesThree theories to test, not a decision
3 first
Tested, not assumed
ranked by month two
Financial services, healthcare and manufacturing are our opening theories: two under heavy regulatory scrutiny with mature budgets, one with real exposure and historically thin security spend. You may have better instincts and we will run yours instead.
ExclusionsWritten before anything sends
Day 1
Suppression list
yours and your vendors'
Your live pipeline, anything registered with a vendor under deal registration, existing customers, and any account a partner has claimed. This is the one list we need before week one, not during it.

On the size of that universe. We are not printing a total addressable market number in this document, because an invented one is worse than none. We size it live at kickoff, in front of you, against these exact filters, and you approve the band before a single message is written. If you want that number before Wednesday, say so and Chris will pull it against whatever cut you prefer.

InterludeThe seven you already built, read as seven campaigns.

Same seven solutions, sorted by one column nobody has sorted them by yet: who signs for it, and what happens in the world the week before they start looking.

Solution
Buyer
The public moment
What it becomes
Cyber storage Lead playRansomware elimination through how backup works
Infra
Insurance renewal
peer incident in sector
Head of Infrastructure and VP IT, with the CISO in the room. The easiest of the seven to explain in one sentence, and the one with a hard external deadline attached to it once a renewal is in play.
Identity microsegmentationStopping lateral movement between accounts and systems
CISO
Closed acquisition
new security lead in seat
The pillar with the sharpest trigger in the whole set. Two directories being merged is a temporary trust that outlives the integration by years, and everybody in the seat knows it.
Post-auth data securityProtecting data after the credential has already worked
CISO
Audit cycle
data residency review
Your sharpest intellectual argument and your hardest cold open, because it requires the reader to accept a premise first. Better as a second touch and far better in a room than in an inbox.
PasswordlessRemoving the credential as an attack surface
IAM
MFA bypass coverage
insurance control requirements
Director of IAM and IT operations. Has a cost story attached as well as a risk story, which makes it the one pillar that can be sold on saving money rather than avoiding loss.
Defensive automationAI in the response path, not just the detection path
SecOps
SOC requisitions open
headcount freeze
Head of SecOps and SOC managers. An open analyst requisition that has sat unfilled for two months is a public statement that the team cannot hire its way out of alert volume.
Deepfake security Different buyerVoice and video impersonation against approval chains
Finance
Wire fraud coverage
not a security purchase
The outlier, and worth noticing. The person who feels this is the CFO or the controller, not the CISO, because it lands as a payment-approval problem. Different list, different words, and it will never work aimed at the security lineage.
External exposure managementWhat is reachable from outside, including what nobody documented
CISO
Acquisition or new entity
new subsidiary or region
The natural first-call offer for several of the other six, because it is diagnostic rather than a purchase. It gives a stranger a reason to spend thirty minutes with you that does not require trusting you with anything yet.
7named solutions, each with a different buyer, a different trigger, and a different sentence that makes it land. Today they share one message and one page.

This is the whole engagement in one table. Nothing above needs to be built, repositioned or renamed. It needs to be pointed at seven different people at seven different moments, which is a volume-of-permutations problem, and permutations are what a campaign count buys you.

It is also why the tier question in section 08 is not really about sending more email. Four campaigns every two weeks tests your two strongest pillars properly. Eight tests four of them properly. Whichever you pick, by month three you own a ranked answer to which of your seven actually sells, and to whom. That answer outlives this contract.

03 / How it runsPublic moment to booked call.

01
The founder layer

You go first, because you are the only proof that exists today.

Two LinkedIn seats, run human-paced and proxied, one of them yours. Everything sent from your profile is written with no merge fields at all. A security leader who spots a variable in the first line has learned everything they need to know about how much attention you paid, and in a trust sale that is the whole meeting gone.

Alongside it, a posting cadence that does one job: make your profile survive the click. Someone receives a message, opens your profile, and either finds a person who clearly knows this material or finds nothing. That page is doing more selling than any email in this document, and right now it is doing it unassisted.

→ 2 LinkedIn seats, human-paced, proxied, throttled, live week one → Founder-led copy, zero variables, written to be read aloud → No warming required, so this runs while cold email is still building
02
The signal layer

Security has more public timing data than almost any category we work in.

We build and maintain five feeds. Leadership changes, so we reach a new CISO or head of identity inside the window where they are still deciding what to keep. Closed acquisitions, which is the cleanest identity-sprawl trigger there is. Open requisitions for identity, security architecture and SOC roles, which is a build-versus-buy decision happening in public. Breach notifications filed with state attorneys general, sector regulators and, for public companies, the SEC, used to time outreach to peers rather than victims. And renewal and audit cycles, where a control requirement arrives with a date attached.

Each answers why this company and why this week. Everything is deduplicated and suppressed across plays, so nobody hears from Secfolio four different ways in the same fortnight.

→ Feeds refreshed weekly, resolved to a named human, never to an inbox → Recency-scored, so a trigger from March is not treated like one from last week → Your pipeline, your vendors' registered deals and partner-claimed accounts all suppressed
03
Two things we will not do

We will not scan someone and email them the findings, and we will not sell fear.

Both are the default in security outbound and both are why security leaders have stopped reading. "We ran a scan on your domain and here is what we found" arrives unrequested, reads as a threat even when it is not meant as one, and makes the recipient's first move a defence of their own program. Nobody buys from that position.

The fear version is worse. "Companies like yours are being hit" is the email every CISO deletes without finishing, because they have been receiving it weekly for a decade and they have long since stopped being frightened by strangers. It also insults the person's competence, which is the exact opposite of what a trust sale needs in touch one.

So the signal sets the targeting and the timing, and the copy opens on something neutral and observable: a start date, a closed deal, an open role, a question the board is already asking. The trigger is why we are in their inbox. It is never the reason we say we are there. Every sequence in the next section works that way and you can check them line by line.

→ Every email is a three-step sequence: fresh, threaded, then a fresh third angle → One consistent ask across all three touches. No fourth email, no breakup email → Separate sending domains, never the domain your customers reply to

04 / CampaignsFive plays. Written, not described.

Real copy, not placeholder. Every play is three touches: first fresh, second threaded, third a fresh angle. One ask, held word for word across all three. Values in {{braces}} populate from the signal that selected the company. Play five has none, on purpose.

The security leader in their first quarter

Recommended lead

The strongest trigger in this category and the one we would build first. A new CISO, VP of security or head of identity spends their first ninety days finding out what they inherited, and they arrive with permission to change things that the previous person could not. They are also, briefly, willing to talk to strangers, because they are actively assembling a bench. That window closes. The copy never mentions that they are new to security, only that they are new here, which is the difference between a congratulation and a condescension.

Signal → target set Title changes into CISO, VP Security, Head of Information Security, Director of Identity and Access, or Security Architect, within the last 90 days → companies above $20M revenue and 100 employees, in the three test industries. Recency-scored so week two of a new role outranks week eleven. A second wave fires at the ninety-day mark, which is usually when the first budget request goes up.
E1 · the inherited mapDay 0
Subject: your first 90 at {{company}}
Hey {{first_name}}, Saw you picked up {{title}} at {{company}} in {{start_month}}. Congrats. The thing nobody hands over with the badge is the map. Which accounts can reach which systems, and what one compromised laptop can actually touch by Friday. I put that map together for people in your seat, usually before anyone asks them to sign off on a budget. Want the one page version of what we map, or is that already inventoried?
P.S. No deck attached. It genuinely is one page.
74 words · score 94
E2 · what the map showsDay 4 · threaded
Subject: none, threads to E1
Hey {{first_name}}, quick follow up. To be specific about what it shows: every path from a normal user account to something that would actually hurt, ranked by how few steps it takes to get there. Most teams find two or three they did not know existed. One of them is usually a service account nobody owns. Want the one page version of what we map, or is that already inventoried?
P.S. Takes us about a week, and you keep it either way.
70 words · score 92
E3 · fresh angle, the real inheritanceDay 9 · fresh
Subject: different question, {{first_name}}
Hey {{first_name}}, last one from me. Different angle. Most people in your seat inherit a stack that detects well and recovers badly. The tooling sees the intrusion fine. It just cannot stop it moving. If that is closer to your situation, the map is still where I would start, because it tells you which of those two you are actually buying next. Want the one page version of what we map, or is that already inventoried?
P.S. And if you inherited something genuinely clean, I would like to hear how.
76 words · score 93
Public trigger Ninety day window Second wave at day 90 No critique of the incumbent program

The two directories after an acquisition

Best fit to the product

The cleanest match between a public event and one of your seven pillars. A closed acquisition means two identity stacks that have to talk to each other before anyone has time to design how. The temporary trust that gets stood up to make the integration painless is exactly the lateral movement path identity microsegmentation exists to remove, and it reliably survives the integration by years because taking it down breaks something nobody can name. Note what the copy does not do: it does not tell them their integration is insecure. It names a window that everyone who has done one recognises.

Signal → target set Announced or closed acquisitions in the last 90 days where the acquirer is above $20M revenue → resolved to the CISO, VP of IT or Director of Identity at the acquirer, never at the acquired company, who are dealing with something else entirely that month. A second wave fires at six months, which is when temporary access becomes an audit finding.
E1 · the windowDay 0
Subject: {{target_company}} and the directory question
Hey {{first_name}}, Saw {{company}} closed {{target_company}} in {{deal_month}}. Congratulations, and I assume IT integration is currently the loudest thread in your inbox. The piece that usually slips is the window between the two directories being connected and being properly separated again. For a while, an account on one side reaches things on the other that nobody intended. Want me to send how we scope that window, or is the integration plan locked?
P.S. Not urgent. This one is a six month problem, not a six day one.
72 words · score 93
E2 · the specific mechanicDay 4 · threaded
Subject: none, threads to E1
Hey {{first_name}}, following up on this one. To be specific: the risk is not the migration. It is the trust that gets stood up to make the migration painless, and then never gets taken back down. It tends to outlive the integration by about two years, because removing it breaks something nobody can name. Want me to send how we scope that window, or is the integration plan locked?
P.S. If it is already scoped, I would genuinely like to see how. Most are not.
69 words · score 92
E3 · fresh angle, the cleanupDay 9 · fresh
Subject: the part after the integration
Hey {{first_name}}, one more and I will leave it alone. Different angle. If the integration itself is going fine, the thing worth a calendar note is the cleanup, roughly six months out, when the temporary access is still in place and nobody remembers granting it. That is when it stops being an IT project and starts being an audit finding. Want me to send how we scope that window, or is the integration plan locked?
P.S. Happy to just be the calendar note. I will follow up in six months either way.
75 words · score 92
Dated public eventMaps to microsegmentationSix month second waveAcquirer only

The question the board asks after a sector incident

Read the targeting rule before the copy, because it is the whole play. When a breach is disclosed publicly, every reseller in the country emails the company that got breached. We do the opposite. We contact peers of that company, matched on sector and size, and we never mention the incident, the company or the word breach. What we use is the second-order effect, which is completely reliable: after anything public in a sector, boards start asking a different question, and the people in your buyer's seat have to answer it with a document they do not have. That is a real, dated need and nobody is frightened into it.

Signal → target set Breach notifications filed with state attorneys general, sector regulators and the SEC → we take the sector and size profile of the disclosing organisation and target its peers, resolved to CISO, CIO or VP Security. The disclosing company is suppressed for 180 days. Fires within two weeks of the filing, which is roughly when the board question lands.
E1 · the board's questionDay 0
Subject: the {{industry}} question this quarter
Hey {{first_name}}, Something I keep noticing about {{industry}} boards this year. The question coming down is no longer "are we protected." It is "show me it could not happen here." Those are different questions. The second one needs a path map. A dashboard cannot answer it. Want the two pages we hand boards for that, or does your team already produce something like it?
P.S. Written for people who do not do this for a living, which is most of the room.
64 words · score 93
E2 · why the format mattersDay 4 · threaded
Subject: none, threads to E1
Hey {{first_name}}, quick follow up. To be specific about the difference: a dashboard shows what got caught. A path map shows what one compromised account could still reach if nothing caught it. Boards understand the second one immediately, and it is the version that survives the follow up question. Want the two pages we hand boards for that, or does your team already produce something like it?
P.S. Both pages fit on one screen. That is deliberate.
67 words · score 91
E3 · fresh angle, the internal versionDay 10 · fresh
Subject: the version for you, not the board
Hey {{first_name}}, last note from me. Different angle. Set the board aside entirely. The same map is more useful internally, because it ranks what to fix by how many steps it removes for an attacker. That list is usually short, and the top item is rarely the expensive one. Want the two pages we hand boards for that, or does your team already produce something like it?
P.S. If you already rank it that way, ignore me. Very few do.
67 words · score 92
Peers, never victimsIncident never mentioned180 day suppressionZero fear language

The identity requisition nobody can fill

An open identity or security architecture role tells you three things at once: the function is funded, whoever owns it now is not owning it well enough, and a build-versus-buy decision is live this month. The obvious play, "do not hire, use us instead," insults the person who wrote the requisition and gets deleted. The play that works is the opposite. Assume the hire happens, and be the thing that makes their first quarter productive. Your reseller position is genuinely built for that, which most people pitching against a requisition cannot say.

Signal → target set Open requisitions for Identity and Access Management Engineer, IAM Director, Security Architect, Zero Trust or segmentation roles, and SOC analyst roles for the defensive automation angle → posted within 30 days, companies above 100 employees. Addressed to the security or infrastructure leader above the vacancy, never to talent acquisition. A second wave fires when the requisition passes 60 days unfilled, and a third when the hire appears in seat.
E1 · assume the hire happensDay 0
Subject: the {{role_title}} req
Hey {{first_name}}, You have a {{role_title}} open at {{company}}, which usually means identity work is finally funded and somebody now has to own it. Whoever takes it will spend their first quarter finding out what they inherited before they can change any of it. We shorten that part, so the hire starts on the redesign instead of the archaeology. Want what we hand a new identity owner on day one, or is that scoped already?
P.S. Not a staffing pitch. Hire the person. This is the thing they open first.
75 words · score 93
E2 · naming the archaeologyDay 3 · threaded
Subject: none, threads to E1
Hey {{first_name}}, quick follow up. To be specific about the archaeology: service accounts with no owner, nested groups that grant more than their name suggests, and standing admin that was meant to be temporary in 2021. None of it is written down anywhere. All of it takes one person roughly a quarter to find by hand. Want what we hand a new identity owner on day one, or is that scoped already?
P.S. The 2021 one is a joke that has never once failed to land.
72 words · score 92
E3 · fresh angle, if the req sitsDay 8 · fresh
Subject: if that role stays open
Hey {{first_name}}, last one. Different angle. If that role stays open a while, and identity roles usually do, the work does not pause. It just lands on whoever is already there. That is the case where having the map done first matters most, because it turns an open ended backlog into a finite one. Want what we hand a new identity owner on day one, or is that scoped already?
P.S. If you filled it last week, say so and I will send it to them instead.
70 words · score 91
Never anti-hireThree wavesAbove the vacancy, not HRCovers two pillars

The room with no pitch in it

Runs on LinkedIn, from you

The format that beat email outright in the cybersecurity engagement we already run, and the direct answer to the proof problem in section 01. A recurring closed-door session for security leaders, one topic, forty five minutes, nobody presenting. It works because it inverts the trust problem: instead of asking a stranger to believe you are credible, you put yourself in a room where credibility is demonstrated in real time, and you leave with a relationship rather than a meeting. This one runs from your profile, in your voice, with zero variables anywhere in it. Everything below is written to be read aloud without sounding like a tool sent it.

Channel → cadence LinkedIn only, from your own profile, human-paced. Connection request, then two messages spaced across a fortnight, then the person either comes or does not. Targeted at the same director-and-above cybersecurity lineage as the email plays, deduplicated against them so nobody gets both in the same fortnight. The session itself is the offer. There is nothing to buy in it and there is not supposed to be.
Connection requestDay 0 · 300 char limit
Sent from: James Spencer, Secfolio
James here, I run Secfolio. Every other Friday I host a closed door session for security leaders. One topic, forty five minutes, nobody presents, including me. Happy to send you the next date if that is a room you would want to be in.
Craft note: No variables. Nothing that reads as merged. Sent at human pace from a warmed profile.
44 words · score 93
DM 1 · what the room actually isDay 2 after accept
Sent from: James Spencer, Secfolio
Quick context on the session, since "closed door roundtable" is a phrase that has been ruined by people selling things. Six or seven security leaders. Forty five minutes. One topic. The last one was standing admin access and why nobody ever removes it. I run it because I put these architectures together for a living, and I would rather hear what is actually breaking than guess at it. Want the next date, or is your calendar already full of these?
Craft note: No "thanks for connecting". No sentiment he does not mean. The reason he is writing is the actual reason.
80 words · score 94
DM 2 · smaller door, same askDay 9
Sent from: James Spencer, Secfolio
No pressure either way on this one. If it is easier, I can send you the write up from the last session instead. It is the ten minute version, and you can decide from that whether the room is worth forty five. Want the next date, or is your calendar already full of these?
Craft note: lower commitment step, identical ask. The write up is a real asset we build with you in week two.
54 words · score 92
DM 3 · fresh angle, then stopDay 16
Sent from: James Spencer, Secfolio
Last one from me on this. Different thought. If the room is not your thing, the part people actually use afterwards is the list of what everyone in it said they were fixing next quarter. I write that up regardless, so I can just send it. Want the next date, or is your calendar already full of these?
Craft note: ends clean. No breakup message, no guilt, no "should I close your file".
58 words · score 92
Zero variablesSolves the proof gapBeat email in this categoryBuilds an asset while it runs

InterludeYou are the only closer, and the proof is not published yet.

Two constraints that shape everything above. Neither is a reason not to run this. Both are reasons to run it differently from how a twelve-person sales team would.

1

You set the weekly ceiling, and we hold it

How many real conversations a week do you want, not how many could you theoretically survive. Every meeting lands on the same calendar that has to do the delivery. Too high and we cost you the implementation work you are already paid for. Too low and we are wasting your money. It is the most important number in the engagement and it is yours, not ours.

2

A written definition of a qualified meeting, in your words

Title, company size, industry, whether they had a trigger, whether they showed up. Fifteen minutes in week one. It prevents roughly ninety percent of the arguments people have with outbound vendors in month two, because when we disagree about a meeting there is a document rather than two opinions.

3

One customer story, even fully anonymised

The single highest-leverage asset in this entire document, and it costs an afternoon. "A regional bank with eleven hundred staff, two directories after an acquisition, here is what we found and what we removed." No name required. It converts a stranger's polite interest into a second call, and right now you do not have one published anywhere.

4

Your profile is doing half the selling

Everyone we message opens it before they reply. If it looks like a company page with a person attached, the message underperforms no matter how good it is. Posting cadence is part of the build, not an upsell, and it is one of the few things here that keeps compounding after the contract ends.

5

Suppression, including your vendors' registered deals

Reseller-specific and easy to get wrong. We need your live pipeline, your existing customers, anything registered with a vendor under deal registration, and any account a channel partner has claimed. Emailing into a registered deal is not a lost lead, it is a damaged vendor relationship, so this list is a precondition for week one rather than a nice-to-have.

6

One consistent ask, so the call starts warm

Notice that every sequence in section 04 holds the same question word for word across all three touches. That is deliberate. When somebody finally replies, they are replying to a specific thing you offered, which means your first call opens on that thing rather than on "so, tell me about your business."

05 / Tool stackThe stack costs more than the fee.

You resell software, so you already know the licence is the cheap part and the person who knows how to run it is the expensive part. Both are included here.

Data & enrichment
Clay
Data orchestration
$800/mo
DiscoLike
Lookalike discovery
$199/mo
LeadMagic
Email verification
$249/mo
Ocean.io
B2B lookalikes
$600/mo
Infrastructure & sequencing
Hypertide
Inbox infrastructure
$1,850/mo
Charm Sequencer
Private IP pool
$500/mo
HeyReach
LinkedIn, human-paced
$197/mo
PhantomBuster
Social automation
$49/mo
Signals & glue
Apify
Filings, breach portals, job boards
$100/mo
RB2B
Site deanonymisation
$149/mo
n8n
Workflow glue
$100/mo
Leadership, M&A and req monitors
Built and maintained by us
Included
Licensed by yourself
$4,793/mo

Plus the person who runs them. Which, in a two-person company where one of those people is also the architect and the implementer, is the hire you cannot make yet.

VS
Included with Charm
$0

Every tool above sits on our licences and is run by our team. At the Engine tier you pay $3,500 a month and the stack behind it lists at more than that on its own, before anybody's time.

06 / TimelineYou are messaging people in week one.

01

Parameters set, LinkedIn live

Working session with you: the revenue band, the headcount floor, the title list, the three industry theories, and the ceiling on your calendar. Written definition of a qualified meeting. Suppression and deal-registration lists loaded. Both LinkedIn seats connected and the first founder-led messages go out. Cold domains ordered and warming starts in parallel.

02

Signal feeds built, session designed

Leadership-change, acquisition, requisition and breach-notification monitors wired and recency-scored. First target lists back to you for review before anything sends. The closed-door session gets a topic, a date and a format, and the write-up template that play five hands out gets built.

03

Copy written, scored, soft launch

All sequences written against your two or four lead pillars and scored line by line. External exposure management positioned as the first-call offer for the cold plays. Low-volume soft launch on the new domains to prove deliverability before anything scales. Your meeting feedback sheet live and in use.

04

All tracks live, throttle set

Cold plays running at metered volume against the week-one ceiling. First session held. Replies routing to you. First grading round complete, first campaigns paused or doubled. Weekly strategy call starts and keeps running for the length of the engagement.

One honest note on this timeline

Week one sends only because LinkedIn needs no warming. Cold email domains have a warming floor of two to three weeks and we will not shorten it. Anyone who tells you otherwise is planning to burn a domain and hand you the reputation damage afterwards, and given you are selling security, arriving in a prospect's spam folder is a worse first impression for you than for most of our clients. If you already have warmed sending infrastructure anywhere, tell us at kickoff and we will inherit it rather than start again.

07 / ProofFour builds with the same mechanics.

We also run outbound for a cybersecurity platform selling into enterprise IT leadership, which is where the channel findings in this document come from. Chris can talk through that one live. These four are here for a different reason: each is a problem your engagement is made of, already solved.

Hello Hero

Youth mental health platform · Same shape: public records → entity → named human
Challenge

Needed direct contact with decision-makers across thousands of US school districts, a universe that exists only inside public records, with the actual humans buried behind institutional entities.

Solution

Mapped every administrator in every US public school district from public data, resolved them to verified direct contacts, and ran parallel campaigns off that dataset. That is the identical build to turning breach notification filings, acquisition announcements and requisition boards into a ranked list and then into the named security leader at each company. It is the single most transferable thing in this list.

$35M
Pipeline generated
300+
Institutional leads
15+
Specialists recruited
6 mo
Timeline

Rightworks

Cloud accounting & practice management · Same shape: hiring signals as the trigger
Challenge

A saturated mid-market category, a sales team stretched thin, and a need for targeting that cut through noise rather than more volume. Security is the most saturated inbox in B2B, so this is the closest structural match to what you are walking into.

Solution

Intent-based outbound triggered on firms hiring specific roles and engaging with specific content, multi-touch across email and LinkedIn. Play four in section 04 is that exact mechanic pointed at identity and SOC requisitions instead.

$4.2M
Pipeline generated
180+
Demo requests
28%
Reply rate
5 mo
Timeline

Ben's Bites

AI education SaaS · Same shape: which angle actually sells?
Challenge

Real credibility in the space but no systematic outbound, and no clarity on which of many possible angles would produce pipeline. That is your question, almost word for word.

Solution

40+ campaign types A/B tested weekly across email, LinkedIn and inbound-led targeting, doubling down only on what converted. This is the direct answer to the thing you cannot decide internally: of your seven solutions, which one should Secfolio lead with, and into which industry? You do not have to pick that in advance. Outbound at a high enough campaign velocity is how you find out with data instead of an opinion, which is exactly what the tier question in section 08 is buying.

$2.5M
Pipeline generated
156x
ROI in 120 days
40+
Campaigns tested
4 mo
Timeline

VirtualFork

Restaurant technology platform · Same shape: long, relationship-led, closes in person
Challenge

Owner-operators who do not answer generic email, in a category that traditionally closed on a handshake, with long relationship-driven cycles and a buyer who was never sitting in front of a screen when the email arrived.

Solution

Signal data identified operators at the moment of expansion, with sends timed to the hours those buyers were actually reachable. The transferable finding is about timing and trust rather than the vertical: in categories that close on relationship, when a message arrives moves reply rates more than what the subject line says. Security is the same shape with higher stakes.

$1.8M
Pipeline generated
200+
Operator leads
35%
Reply rate
3 mo
Timeline

Highline

Internet service provider · Same shape: email opens it, a call closes it
Why this one is here

A local provider competing against incumbents, where email and LinkedIn alone were not going to move the buyer. Charm built and staffed the dialling teams, then layered email and LinkedIn around the call cadence against the same prospect. It is in this document for one reason: if one of your seven pillars turns out to need a phone layer in front of it rather than more email, we have built one before rather than outsourced it.

Note: the metrics on this engagement are still being verified, so we have left them out rather than print numbers we have not checked.

08 / InvestmentTwo tiers. Then you choose.

Three months, which is what we discussed on the call. Long enough to find out which of your seven sells and to whom. Short enough that you are not signing away a year to find out.

First, what a "campaign" actually is

Because the number is the whole difference between the two tiers and most vendors will not define it. A campaign is one permutation: an industry × a segment × a title × an angle. Worked example from your own solution list: financial services × $50M to $500M revenue × Director of Identity and above × identity microsegmentation after an acquisition. That is one campaign. Change the industry, the size band, the title or the pillar and it is a different one, with its own list, its own copy and its own score. Each campaign is a separate answer to "what should Secfolio say, and to whom." Seven solutions times three industries times two title tiers is forty two possible answers before you have tried a single new angle. That is why the count matters more here than it does for most companies, and it is the honest argument for the second tier.

Engine

$3,500/mo

Four campaigns every two weeks. Eight a month. Two pillars tested properly.

  • 4 campaign deployments every two weeks, 8 per month
  • Full cold infrastructure: domains, DKIM, SPF, MX, warming, private IP pool
  • 2 LinkedIn seats managed end to end, including yours
  • Founder-led LinkedIn copy, written with zero variables
  • Leadership-change, acquisition and requisition monitors, refreshed weekly
  • Breach notification monitoring, targeted at peers with victim suppression
  • ICP parameter session, TAM sized live and approved by you
  • All copy written, scored and iterated against your meeting grades
  • Weekly strategy call · dedicated account manager
  • 3-month commitment
Start here
Recommended

Engine ×2

$6,000/mo

Eight campaigns every two weeks. Sixteen a month. Four pillars, three industries, in parallel.

  • Everything in Engine
  • 8 campaign deployments every two weeks, 16 per month
  • Four solution pillars run in parallel rather than sequenced
  • All three industry theories tested at once, ranked by month two instead of month four
  • The closed-door session run as its own track, with the write-up asset built for you
  • Vendor channel and MSP partner motion run as a separate track
  • The deepfake pillar tested against finance titles, which is a different list entirely
  • Visitor deanonymisation on secfolio.com, so we see which solution pages get read
  • 3-month commitment
Get started
The arithmetic, including the numbers we do not have

We are not going to invent your deal size to make a slide look good. Here is the full spend and the two inputs that turn it into a real return figure, both of which are yours.

Total spend, 90 days
$10,500

Engine tier, three-month commitment. $18,000 at Engine ×2. No setup fee, no tool costs, no per-seat charges on top.

What it takes to break even
Your margin
× 1 deal

In a reseller model the number that matters is margin, not deal value. Bring your average margin per implementation and we will run this live on Wednesday.

Qualified meetings, 90 days
Target set
at kickoff

Against your written definition and your calendar ceiling, not against ours. Reported weekly, graded by you.

Two numbers we need from you: average margin per closed implementation, and average cycle length in weeks from first call to signed. Those two turn everything above from a fee into a payback period. One thing worth saying plainly: with a cycle that is likely to run months rather than weeks in this category, the honest measure of the first ninety days is qualified conversations and a ranked answer on messaging, not closed revenue. Anyone promising you closed revenue inside a quarter in enterprise security is selling you the last eighteen months of somebody else's disappointment.

Why three months, and what happens at the end of it

The first ninety days are for finding out which pillar, which industry and which title converts, and that testing only happens if it is funded. Performance pricing on day one pays a vendor to run the safest, highest-volume campaign that produces a meeting, which is the opposite of what you need while the question is still open. At month three you choose: stay on retainer, move to performance now that we both know the real numbers, or take the answers and run it in-house. All three are fine. The campaign matrix, the copy and the signal feeds are yours either way, which is the part most agencies keep.

09 / What we need from youSix answers, then we build.

The questions this proposal could not answer from the outside. None are hard. They are just yours, and we would rather ask than assume. Answers on Wednesday and we can start the week after.

1

Rank the seven by what actually pays, not by what is most interesting

Cyber storage, post-auth data security, passwordless, identity microsegmentation, defensive automation, deepfake security, external exposure management. Which two carry the best margin, which two close fastest, and which one would you quietly rather stop selling? We will lead with the top two, or the top four at Engine ×2, and let the data argue with you from month two.

2

Average margin per implementation, and average cycle length

The two numbers that turn section 08 from a fee into a payback period. In a reseller model the deal value is the wrong figure and your margin is the right one, so that is the one we want. If you only have a range, give us the range.

3

Your vendor constraints, in writing

Which of the six have deal registration rules that limit who you can approach, which have territory or named-account restrictions, and which have co-marketing or MDF budget you are not currently using. That last one is a funding source for this engagement that most resellers forget they have. It also changes what we are allowed to say in copy, so we need it before week one rather than after a mistake.

4

One customer story you can describe end to end, even anonymised

Industry, size, what you found, what you removed, what changed. No name needed. This is the highest-leverage thing on this list and the one we would chase first, because it is what converts a polite reply into a second call and you currently have none published.

5

Your industry instincts, so we can test yours before ours

We proposed financial services, healthcare and manufacturing in section 02. You have sat in rooms we have not. If your gut says defence contractors, or legal, or regional banks specifically rather than financial services broadly, say so on Wednesday and we run yours first. Being wrong quickly is the point, but starting from your instinct is faster than starting from ours.

6

How much of your own voice are you willing to put out

Play five and the LinkedIn layer depend on you being visible: messaging from your own profile, a posting cadence, and hosting a session every other week. It is the highest-return part of this build for a company at your stage and it is also the part that requires your time rather than ours. If the answer is "not much," tell us and we will reweight toward email, but you should know that trade before we make it rather than after.

10 / What happens nextWhen Secfolio signs.

01

The parameter session

The one we described on the call. We size the universe live against your filters, you approve the band, we rank your seven, write the meeting definition and set the ceiling on your calendar. It ends with a target list on screen, not with a follow-up email.

02

You are messaging people inside week one

LinkedIn goes out from your profile in the first few days, in your voice, with nothing merged into it. In parallel, domains warm, signal feeds get built and suppression lists load. You review every target list before a single message sends.

03

All tracks live, grading begins

Cold plays live around week four at metered volume. First session held. You grade every meeting weekly and campaigns get paused or doubled on your scores rather than on our opinion. Weekly strategy call from day one. At month three, you choose what happens next.

Seven solutions.
Let's go find every buyer.

Pick a kickoff date. Week one is the parameter session, the ranked pillars, the approved band, and your own profile talking to security leaders who have a reason to answer. None of that waits on infrastructure to warm.

Pick your kickoff date →