On our call you said the thing most founders never get to: you know what you sell and why it is different. Architect resilience instead of detecting failures. Invest from the impact inward. That is a point of view, and most value-added resellers do not have one. It is also the part of an outbound build that normally takes six weeks and a fight.
So the work ahead is not strategy. It is aim. Each of your seven solutions has its own buyer, its own budget line, and its own moment it becomes urgent, and every one of those moments is already public. This document turns your seven into seven separate answers to why me and why now, and points each one at the people living that problem this month.
+ others
Everything below comes from our first call and from public sources: secfolio.com, the seven solution pages, your three-step prevention framework, and your own background as you described it. Nothing here assumes your margin per deal, your deal registration terms with any vendor, your close rate, or your average cycle length. Where we would normally use your numbers we left the question open and put it in section 09. Correct anything that is wrong on Wednesday and we will rebuild around it.
"Beyond detection, architect resilience" is a position, not a product list. So is "invest from the impact inward." Most engagements burn the first month deciding what the client actually stands for, because most clients sell whatever the vendor sheet says that quarter. Yours is written, published and consistent across seven pages. Every campaign in section 04 inherits it instead of inventing it.
Cyber storage, post-auth data security, passwordless, identity microsegmentation, defensive automation, deepfake security, external exposure management. Each one has a different buyer, a different budget line and a different moment it becomes urgent. Most clients arrive with one product and one angle and we have to manufacture variety. You arrive with seven real ones, which is why the campaign count in section 08 is the number that matters most in this document.
Security leadership changes are announced. Acquisitions are announced and dated. Identity and security architect requisitions are posted. Breach notifications are filed with state attorneys general and, for public companies, with the SEC. Cyber insurance renews on a calendar. None of that is bought data. It is public, it is dated, we can pull it whenever we build a campaign, and it answers the only two questions cold outbound survives on: why this company, and why this week.
You are not defending one vendor's roadmap, so you can open on the exposure and let the tool arrive later in the conversation. A security leader will read an email about a pathway. They will not read an email about a platform. Every vendor selling direct into your accounts is structurally unable to write the email you can write, and that is an advantage that lasts as long as you stay tool-agnostic in the first touch.
Business plus security and risk analysis at Penn State, then sales and support at the largest Microsoft partner while the Fortune 500 moved to cloud, then a penetration testing company before Secfolio. You can explain the mechanism, not just the outcome, and you can do it to someone technical without a deck. A larger reseller can outspend you on everything except that. Section 04 is built to put you in front of people rather than a brand nobody knows yet.
Founded 2024, no customer stories on the site, no named references, no logos. Everyone selling security says the same three sentences you do, so the buyer's real filter is not the pitch, it is whether anyone they recognise has trusted you. This is the tightest constraint in the engagement, tighter than volume, tighter than deliverability, and it is why section 09 asks for one customer story before it asks for anything else.
The strength in section one is also the problem. Every visitor currently gets all seven, so a CISO with a ransomware recovery problem and a CFO with a deepfake wire-fraud problem land on the same page and both have to do the sorting themselves. They will not. The fix is not to cut anything. It is to give each pillar its own audience, its own trigger and its own landing point, which is exactly what a campaign is.
There are three parent offers in business: make me money, save me money, save me time. Yours reduces risk, which sits at the far end of that scale. More touchpoints, more people in the room, a longer cycle, and expertise has to be demonstrated before anyone books. That is not a problem to solve, it is a shape to plan for, and it changes the copy, the channel mix and what we count as progress in month one.
From the cybersecurity engagement we have run for about a year: email did fine. LinkedIn did considerably better. And the format that outperformed both was a small recurring session with no pitch in it. Security buyers open your profile before they answer your email, because the first thing they are assessing is whether you are a real person. So LinkedIn is not a secondary channel in this build. It is the lead channel, and it is live in week one because it needs no warming.
Every meeting we book lands on one person, and that person is also the architect, the implementer and the vendor relationship. Volume is not your constraint. Your week is. Which means the goal is not the largest number of meetings, it is the highest-quality meeting per hour you can spare, metered to a ceiling you set. That gets its own section, straight after section 04.
Buying a list of CISOs is the single most commoditised thing in outbound. Every reseller in the country has the same one, and a security leader can smell it from the first line. So we do not start there.
First, you. Your LinkedIn, your network and your existing conversations. Founder-led, no variables, no automation voice, and live in week one because nothing needs to warm.
Second, the trigger data. New security leadership in seat, closed acquisitions, open identity requisitions, breach notifications, renewal cycles. All public, all dated. Each campaign pulls it fresh when we build that campaign.
Third, the channel you already sit inside. You resell six tools. Those vendors have channel teams, deal registration and co-marketing budgets, and there are MSPs with no security architecture practice. That is a partner motion, not a cold one.
Fourth, the room. A small recurring closed-door session, which is the format that has beaten email outright in this category for us.
Then all of it gets metered to your calendar, not to our sending capacity.
Two LinkedIn seats run human-paced and proxied. Founder-led copy with no merge fields, because a security leader will spot one and it costs you the meeting.
Leadership changes, closed acquisitions, identity and security requisitions, breach notifications, renewal cycles. Pulled fresh for each campaign, resolved to a named human, scored by how recent the trigger is.
The six vendors you already resell, their channel teams and their installed bases. Plus MSPs with no architecture practice. Partnership copy, not sales copy, and it compounds.
You set the weekly ceiling at kickoff and grade every meeting. Campaigns producing meetings you would not take again get paused that week, not at the end of the month.
You asked how we define mid-market plus, and you were right to, because everybody cuts it differently. Here is our opening cut for Secfolio. It is a starting band, not a finished ICP, and the whole point of the kickoff session is that you move these numbers.
On the size of that universe. We are not printing a total addressable market number in this document, because an invented one is worse than none. We size it live at kickoff, in front of you, against these exact filters, and you approve the band before a single message is written. If you want that number before Wednesday, say so and Chris will pull it against whatever cut you prefer.
Same seven solutions, sorted by one column nobody has sorted them by yet: who signs for it, and what happens in the world the week before they start looking.
This is the whole engagement in one table. Nothing above needs to be built, repositioned or renamed. It needs to be pointed at seven different people at seven different moments, which is a volume-of-permutations problem, and permutations are what a campaign count buys you.
It is also why the tier question in section 08 is not really about sending more email. Four campaigns every two weeks tests your two strongest pillars properly. Eight tests four of them properly. Whichever you pick, by month three you own a ranked answer to which of your seven actually sells, and to whom. That answer outlives this contract.
Two LinkedIn seats, run human-paced and proxied, one of them yours. Everything sent from your profile is written with no merge fields at all. A security leader who spots a variable in the first line has learned everything they need to know about how much attention you paid, and in a trust sale that is the whole meeting gone.
Alongside it, a posting cadence that does one job: make your profile survive the click. Someone receives a message, opens your profile, and either finds a person who clearly knows this material or finds nothing. That page is doing more selling than any email in this document, and right now it is doing it unassisted.
Five public sources sit behind the plays. Leadership changes, so we reach a new CISO or head of identity inside the window where they are still deciding what to keep. Closed acquisitions, which is the cleanest identity-sprawl trigger there is. Open requisitions for identity, security architecture and SOC roles, which is a build-versus-buy decision happening in public. Breach notifications filed with state attorneys general, sector regulators and, for public companies, the SEC, used to time outreach to peers rather than victims. And renewal and audit cycles, where a control requirement arrives with a date attached.
Each answers why this company and why this week. Everything is deduplicated and suppressed across plays, so nobody hears from Secfolio four different ways in the same fortnight.
How the data actually works, because this is the line most proposals fudge. A campaign pulls its dataset at the moment we build it. That is a snapshot, not a live monitor humming away in the background. The campaign runs, we score it, and the plays that earn it get promoted to a standing pull so that one keeps feeding itself. That promotion is a decision we make together off the numbers, usually around week six. We are not going to tell you five feeds refresh themselves every Monday for the length of the contract. At this fee they would not, and you would find that out in month two.
Both are the default in security outbound and both are why security leaders have stopped reading. "We ran a scan on your domain and here is what we found" arrives unrequested, reads as a threat even when it is not meant as one, and makes the recipient's first move a defence of their own program. Nobody buys from that position.
The fear version is worse. "Companies like yours are being hit" is the email every CISO deletes without finishing, because they have been receiving it weekly for a decade and they have long since stopped being frightened by strangers. It also insults the person's competence, which is the exact opposite of what a trust sale needs in touch one.
So the signal sets the targeting and the timing, and the copy opens on something neutral and observable: a start date, a closed deal, an open role, a question the board is already asking. The trigger is why we are in their inbox. It is never the reason we say we are there. Every sequence in the next section works that way and you can check them line by line.
Real copy, not placeholder. Every play is three touches: first fresh, second threaded, third a fresh angle. One ask, held word for word across all three. Values in {{braces}} populate from the signal that selected the company. Play five has none, on purpose.
The strongest trigger in this category and the one we would build first. A new CISO, VP of security or head of identity spends their first ninety days finding out what they inherited, and they arrive with permission to change things that the previous person could not. They are also, briefly, willing to talk to strangers, because they are actively assembling a bench. That window closes. The copy never mentions that they are new to security, only that they are new here, which is the difference between a congratulation and a condescension.
The cleanest match between a public event and one of your seven pillars. A closed acquisition means two identity stacks that have to talk to each other before anyone has time to design how. The temporary trust that gets stood up to make the integration painless is exactly the lateral movement path identity microsegmentation exists to remove, and it reliably survives the integration by years because taking it down breaks something nobody can name. Note what the copy does not do: it does not tell them their integration is insecure. It names a window that everyone who has done one recognises.
Read the targeting rule before the copy, because it is the whole play. When a breach is disclosed publicly, every reseller in the country emails the company that got breached. We do the opposite. We contact peers of that company, matched on sector and size, and we never mention the incident, the company or the word breach. What we use is the second-order effect, which is completely reliable: after anything public in a sector, boards start asking a different question, and the people in your buyer's seat have to answer it with a document they do not have. That is a real, dated need and nobody is frightened into it.
An open identity or security architecture role tells you three things at once: the function is funded, whoever owns it now is not owning it well enough, and a build-versus-buy decision is live this month. The obvious play, "do not hire, use us instead," insults the person who wrote the requisition and gets deleted. The play that works is the opposite. Assume the hire happens, and be the thing that makes their first quarter productive. Your reseller position is genuinely built for that, which most people pitching against a requisition cannot say.
The format that beat email outright in the cybersecurity engagement we already run, and the direct answer to the proof problem in section 01. A recurring closed-door session for security leaders, one topic, forty five minutes, nobody presenting. It works because it inverts the trust problem: instead of asking a stranger to believe you are credible, you put yourself in a room where credibility is demonstrated in real time, and you leave with a relationship rather than a meeting. This one runs from your profile, in your voice, with zero variables anywhere in it. Everything below is written to be read aloud without sounding like a tool sent it.
Two constraints that shape everything above. Neither is a reason not to run this. Both are reasons to run it differently from how a twelve-person sales team would.
How many real conversations a week do you want, not how many could you theoretically survive. Every meeting lands on the same calendar that has to do the delivery. Too high and we cost you the implementation work you are already paid for. Too low and we are wasting your money. It is the most important number in the engagement and it is yours, not ours.
Title, company size, industry, whether they had a trigger, whether they showed up. Fifteen minutes in week one. It prevents roughly ninety percent of the arguments people have with outbound vendors in month two, because when we disagree about a meeting there is a document rather than two opinions.
The single highest-leverage asset in this entire document, and it costs an afternoon. "A regional bank with eleven hundred staff, two directories after an acquisition, here is what we found and what we removed." No name required. It converts a stranger's polite interest into a second call, and right now you do not have one published anywhere.
Everyone we message opens it before they reply. If it looks like a company page with a person attached, the message underperforms no matter how good it is. Posting cadence is part of the build, not an upsell, and it is one of the few things here that keeps compounding after the contract ends.
Reseller-specific and easy to get wrong. We need your live pipeline, your existing customers, anything registered with a vendor under deal registration, and any account a channel partner has claimed. Emailing into a registered deal is not a lost lead, it is a damaged vendor relationship, so this list is a precondition for week one rather than a nice-to-have.
Notice that every sequence in section 04 holds the same question word for word across all three touches. That is deliberate. When somebody finally replies, they are replying to a specific thing you offered, which means your first call opens on that thing rather than on "so, tell me about your business."
You resell software, so you already know the licence is the cheap part and the person who knows how to run it is the expensive part. Both are included here.
Plus the person who runs them. Which, in a two-person company where one of those people is also the architect and the implementer, is the hire you cannot make yet.
Every tool above sits on our licences and is run by our team. At the Engine tier you pay $3,500 a month and the stack behind it lists at more than that on its own, before anybody's time.
Working session with you: the revenue band, the headcount floor, the title list, the three industry theories, and the ceiling on your calendar. Written definition of a qualified meeting. Suppression and deal-registration lists loaded. Both LinkedIn seats connected and the first founder-led messages go out. Cold domains ordered and warming starts in parallel.
Leadership-change, acquisition, requisition and breach-notification sources wired up so any campaign can pull from them, with recency scoring. First target lists back to you for review before anything sends. The closed-door session gets a topic, a date and a format, and the write-up template that play five hands out gets built.
All sequences written against your two or four lead pillars and scored line by line. External exposure management positioned as the first-call offer for the cold plays. Low-volume soft launch on the new domains to prove deliverability before anything scales. Your meeting feedback sheet live and in use.
Cold plays running at metered volume against the week-one ceiling. First session held. Replies routing to you. First grading round complete, first campaigns paused or doubled. Weekly strategy call starts and keeps running for the length of the engagement.
Week one sends only because LinkedIn needs no warming. Cold email domains have a warming floor of two to three weeks and we will not shorten it. Anyone who tells you otherwise is planning to burn a domain and hand you the reputation damage afterwards, and given you are selling security, arriving in a prospect's spam folder is a worse first impression for you than for most of our clients. If you already have warmed sending infrastructure anywhere, tell us at kickoff and we will inherit it rather than start again.
We also run outbound for a cybersecurity platform selling into enterprise IT leadership, which is where the channel findings in this document come from. Chris can talk through that one live. These four are here for a different reason: each is a problem your engagement is made of, already solved.

Needed direct contact with decision-makers across thousands of US school districts, a universe that exists only inside public records, with the actual humans buried behind institutional entities.
Mapped every administrator in every US public school district from public data, resolved them to verified direct contacts, and ran parallel campaigns off that dataset. That is the identical build to turning breach notification filings, acquisition announcements and requisition boards into a ranked list and then into the named security leader at each company. It is the single most transferable thing in this list.

A saturated mid-market category, a sales team stretched thin, and a need for targeting that cut through noise rather than more volume. Security is the most saturated inbox in B2B, so this is the closest structural match to what you are walking into.
Intent-based outbound triggered on firms hiring specific roles and engaging with specific content, multi-touch across email and LinkedIn. Play four in section 04 is that exact mechanic pointed at identity and SOC requisitions instead.

Real credibility in the space but no systematic outbound, and no clarity on which of many possible angles would produce pipeline. That is your question, almost word for word.
40+ campaign types A/B tested weekly across email, LinkedIn and inbound-led targeting, doubling down only on what converted. This is the direct answer to the thing you cannot decide internally: of your seven solutions, which one should Secfolio lead with, and into which industry? You do not have to pick that in advance. Outbound at a high enough campaign velocity is how you find out with data instead of an opinion, which is exactly what the tier question in section 08 is buying.

Owner-operators who do not answer generic email, in a category that traditionally closed on a handshake, with long relationship-driven cycles and a buyer who was never sitting in front of a screen when the email arrived.
Signal data identified operators at the moment of expansion, with sends timed to the hours those buyers were actually reachable. The transferable finding is about timing and trust rather than the vertical: in categories that close on relationship, when a message arrives moves reply rates more than what the subject line says. Security is the same shape with higher stakes.

A local provider competing against incumbents, where email and LinkedIn alone were not going to move the buyer. Charm built and staffed the dialling teams, then layered email and LinkedIn around the call cadence against the same prospect. It is in this document for one reason: if one of your seven pillars turns out to need a phone layer in front of it rather than more email, we have built one before rather than outsourced it.
Note: the metrics on this engagement are still being verified, so we have left them out rather than print numbers we have not checked.
Three months, which is what we discussed on the call. Long enough to find out which of your seven sells and to whom. Short enough that you are not signing away a year to find out.
Because the number is the whole difference between the two tiers and most vendors will not define it. A campaign is one permutation: an industry × a segment × a title × an angle. Worked example from your own solution list: financial services × $50M to $500M revenue × Director of Identity and above × identity microsegmentation after an acquisition. That is one campaign. Change the industry, the size band, the title or the pillar and it is a different one, with its own list, its own copy and its own score. Each campaign is a separate answer to "what should Secfolio say, and to whom." Seven solutions times three industries times two title tiers is forty two possible answers before you have tried a single new angle. That is why the count matters more here than it does for most companies, and it is the honest argument for the second tier.
And here is the other thing the count buys. When a campaign scores, we promote its data pull to a standing one, so that play keeps feeding itself instead of getting rebuilt from scratch every time. Those promotions come out of the same count. That is the real reason sixteen a month gets you to a stable set of evergreen plays in about half the time eight does, and it is why we would rather sell you the count than a promise that the whole thing runs itself from day one.
Four campaigns every two weeks. Eight a month. Two pillars tested properly.
Eight campaigns every two weeks. Sixteen a month. Four pillars, three industries, in parallel.
We are not going to invent your deal size to make a slide look good. Here is the full spend and the two inputs that turn it into a real return figure, both of which are yours.
Engine tier, three-month commitment. $18,000 at Engine ×2. No setup fee, no tool costs, no per-seat charges on top.
In a reseller model the number that matters is margin, not deal value. Bring your average margin per implementation and we will run this live on Wednesday.
Against your written definition and your calendar ceiling, not against ours. Reported weekly, graded by you.
Two numbers we need from you: average margin per closed implementation, and average cycle length in weeks from first call to signed. Those two turn everything above from a fee into a payback period. One thing worth saying plainly: with a cycle that is likely to run months rather than weeks in this category, the honest measure of the first ninety days is qualified conversations and a ranked answer on messaging, not closed revenue. Anyone promising you closed revenue inside a quarter in enterprise security is selling you the last eighteen months of somebody else's disappointment.
The first ninety days are for finding out which pillar, which industry and which title converts, and that testing only happens if it is funded. Performance pricing on day one pays a vendor to run the safest, highest-volume campaign that produces a meeting, which is the opposite of what you need while the question is still open. At month three you choose: stay on retainer, move to performance now that we both know the real numbers, or take the answers and run it in-house. All three are fine. The campaign matrix, the copy and the signal feeds are yours either way, which is the part most agencies keep.
The questions this proposal could not answer from the outside. None are hard. They are just yours, and we would rather ask than assume. Answers on Wednesday and we can start the week after.
Cyber storage, post-auth data security, passwordless, identity microsegmentation, defensive automation, deepfake security, external exposure management. Which two carry the best margin, which two close fastest, and which one would you quietly rather stop selling? We will lead with the top two, or the top four at Engine ×2, and let the data argue with you from month two.
The two numbers that turn section 08 from a fee into a payback period. In a reseller model the deal value is the wrong figure and your margin is the right one, so that is the one we want. If you only have a range, give us the range.
Which of the six have deal registration rules that limit who you can approach, which have territory or named-account restrictions, and which have co-marketing or MDF budget you are not currently using. That last one is a funding source for this engagement that most resellers forget they have. It also changes what we are allowed to say in copy, so we need it before week one rather than after a mistake.
Industry, size, what you found, what you removed, what changed. No name needed. This is the highest-leverage thing on this list and the one we would chase first, because it is what converts a polite reply into a second call and you currently have none published.
We proposed financial services, healthcare and manufacturing in section 02. You have sat in rooms we have not. If your gut says defence contractors, or legal, or regional banks specifically rather than financial services broadly, say so on Wednesday and we run yours first. Being wrong quickly is the point, but starting from your instinct is faster than starting from ours.
Play five and the LinkedIn layer depend on you being visible: messaging from your own profile, a posting cadence, and hosting a session every other week. It is the highest-return part of this build for a company at your stage and it is also the part that requires your time rather than ours. If the answer is "not much," tell us and we will reweight toward email, but you should know that trade before we make it rather than after.
The one we described on the call. We size the universe live against your filters, you approve the band, we rank your seven, write the meeting definition and set the ceiling on your calendar. It ends with a target list on screen, not with a follow-up email.
LinkedIn goes out from your profile in the first few days, in your voice, with nothing merged into it. In parallel, domains warm, signal feeds get built and suppression lists load. You review every target list before a single message sends.
Cold plays live around week four at metered volume. First session held. You grade every meeting weekly and campaigns get paused or doubled on your scores rather than on our opinion. Weekly strategy call from day one. At month three, you choose what happens next.
Pick a kickoff date. Week one is the parameter session, the ranked pillars, the approved band, and your own profile talking to security leaders who have a reason to answer. None of that waits on infrastructure to warm.
Pick your kickoff date →