---
title: "How we booked 570 calls with enterprise security leaders in twelve months. | Stone Haven Capital Group"
description: "180 qualified opportunities, $32M of pipeline and $9.6M closed. Twelve months. A cybersecurity vendor selling into the enterprise. No new sales hires, no conference sponsorships, no waiting on a channel partner to make the introduction."
canonical: "https://stonehaven.capital/showcase/enterprise-cybersecurity-vendor"
last-updated: "2026-08-22"
---

> 180 qualified opportunities, $32M of pipeline and $9.6M closed. Twelve months. A cybersecurity vendor selling into the enterprise. No new sales hires, no conference sponsorships, no waiting on a channel partner to make the introduction.

Stone Haven Capital Group

Schedule a Call

Case study · Enterprise Cybersecurity Vendor

# How we booked 570 calls with enterprise security leaders in twelve months.

180 qualified opportunities, $32M of pipeline and $9.6M closed. Twelve months. A cybersecurity vendor selling into the enterprise. No new sales hires, no conference sponsorships, no waiting on a channel partner to make the introduction.

- $9,601,200 of closed revenue across 54 contracts in twelve months, at an average of $177,847.

- 3,762,430 emails to 752,486 security leaders, producing 4,517 replies at 0.6%.

- 813 positive replies became 570 calls booked, 412 of them held, and 180 qualified opportunities.

- Average contract value rose 3.9x from a $45,600 baseline, on $32,012,460 of qualified pipeline.

- What went wrong: the opening angle led with breach scenarios and read as fear selling.

01

## Did they get a good result?

Yes. The short version, with nothing dressed up. Before we started, enterprise pipeline arrived through inbound and channel partners, which made it real and impossible to forecast, and left the team with no route at all to a security leader who had never heard of them. Twelve months on the vendor had 570 booked calls behind it, 412 of them held, 180 qualified security opportunities worth $32,012,460, and 54 contracts closed for $9,601,200.

What happenedThe number

Closed revenue$9,601,200 across 54 contracts

Average contract value~$177,847, up 3.9x from a $45,600 baseline

Qualified pipeline$32,012,460 across 180 security opportunities

Calls booked570 across twelve months, 412 of them held, carrying $72,986,400

Positive replies813, 18.0% of all replies, carrying $85,394,700

Emails sent3,762,430 across twelve months

Leads contacted752,486, of which 748,724 were new

Replies4,517, a 0.6% reply rate, or 16,261 and 2.2% counting out of office

Bounce rate1.6%, 60,199 bounces

The full programme in the sending platform.

02

## Did you get them in front of the right people?

This is the part that decides everything, and a send count says nothing about it. Three and a half million emails aimed at people with no budget and no mandate produce three and a half million pieces of nothing.

180 opportunities cleared qualification and carried $32,012,460 between them. 54 of those closed for $9,601,200, at an average contract of roughly $177,847.

Targeting shows up in the conversion and never in the send count. 4,517 replies yielded 813 positive ones. 570 of those became booked calls, 412 were held, and 180 cleared qualification. Average contract value came out close to four times where it started, which is the figure that says the engine was reaching larger security programmes rather than simply reaching more inboxes.

The pipeline as the client sees it.

03

## What worked, and why

### We kept the corporate domain out of it entirely.

A security vendor with deliverability problems on its own domain has a credibility problem, and in this market credibility is the product. Nothing cold ever left it. We built 499 separate sending domains carrying 1,498 mailboxes, each authenticated on SPF, DKIM, DMARC and MX before it sent anything. Warmup ran on all 1,498 continuously for the full year, while only half carried live campaign volume at a time. The remainder waited in reserve and rotated in as the earlier domains matured.

The estate moved 3,762,430 sends across twelve months and settled at a 1.6% bounce rate, 60,199 bounces, with placement holding at 92%. Those two figures are the whole engine. Let either slip and the domains stop landing, and everything downstream stops with them.

Every sending domain authenticated and warmed, with the corporate domain nowhere in it.

The reason it holds: the domain every customer and auditor already trusts was never exposed, while the risk sat entirely on infrastructure built to be thrown away.

### We built the list around who owns the security budget, and cut everyone who does not.

The people who sign a security contract are chief information security officers, heads of security engineering and infrastructure, and the IT directors carrying the mandate at organisations with no named CISO. They sit at enterprises, at regulated mid-market firms, and at the managed service providers who buy on behalf of others. The list was built on that profile across North America, Europe and the Asia-Pacific region.

What came out mattered as much as what went in. Resellers with no security practice, staffing firms, consultancies, and everything below the headcount where a security function exists at all were removed outright, which cut most of the starting pool before a word was written.

The targeting profile: titles, industry, intent and the exclusions.

Why it holds: a job title tells you who could sign. Funding, breach disclosures, compliance deadlines and security hiring tell you whose programme is being rebuilt right now.

### We put the specific thing we do into the first line.

Security leaders take more cold email than almost any other buyer and triage it in seconds. The opener named one exposure we address and asked whether it was live for them. No preamble, no credential paragraph, nothing to scroll past.

Every send went out as plain text with spintax through every line, so no two messages left the estate identical.

The live sequence and the opener behind it.

What that buys: a security leader deciding whether to keep reading gives you one line. Spending it on introduction rather than on substance wastes the only line you get.

### We ran a five-touch cadence and let only committee-level replies reach the account team.

Five steps on four and seven day gaps, three variations on the opener and three on each follow-up, all A/B tested. A qualification layer sat between the inbox and the account team, passing through only conversations where a security programme, a budget owner and a live evaluation window were all present.

The reason: an account executive burning a quarter on a conversation with no budget behind it is the expensive failure in this market. That filter is what kept 633 positive replies away from the team.

Five steps on widening gaps, with three variations at every step.

### We read the numbers every week and killed what was not working.

Angles were judged on how many conversations reached a budget owner, never on raw reply volume. Anything producing replies that stalled before qualification came off within days, and the survivors absorbed its share of the list. Across twelve months that is fifty reviews, and the compounding is where the result comes from.

04

## The five angles we test, in every market

Which message a market responds to is not something anyone reasons their way to in advance. The market answers that question and you have to ask it. So five variations of the opener run at once, one per angle, and the reply data settles it. These five travel across sectors because each is built on a different reason a person replies rather than on anything about the product.

05

## 1. The teardown

Hand them a specific read on something of theirs. Expensive to produce, which is why it goes only to accounts worth the hour, and close to impossible to ignore when it lands.

We mapped what is reachable on your perimeter from the outside. Eleven items, two worth your morning. Want the list?

06

## 2. Pain led

Name the constraint they live inside, in the words they would use, then ask whether it applies. Strongest where the problem is an open secret nobody says out loud.

Most teams your size are running three tools that each claim to own identity. Is that where you are?

07

## 3. Social proof

Put a comparable organisation in front of them with a real outcome attached. Never draw the parallel yourself. They get there faster than you would.

A bank about your size cut alert volume by two thirds last quarter without adding headcount. Worth ten minutes on how?

08

## 4. The timing hook

Attach the ask to something that just changed for them. Only works when the change is public and recent enough that mentioning it proves you looked.

Saw the SOC 2 Type II landed in March. Does the next audit cycle take in the cloud estate as well?

09

## 5. Risk reversal

Move the risk onto your side of the table. If nothing comes of it, nothing is owed. Carries markets where people have been sold to badly before.

No procurement process to start. We run the exposure review and you keep the findings whether or not we ever work together.

10

## How we use them

All five go out together across a split list. Within a few weeks the reply data has named the one or two the market wants, and the others come off before they consume any more contacts. Which one wins is not something we can call in advance. That one or two of them will win is. Running all five at once turns a guess into an outcome. The same five port to LinkedIn with tighter wording and the same underlying logic.

11

## What did not work, and what we did about it

Three of them, and you should hear them from us.

### We led with breach scenarios and it read as fear selling.

The opening angles framed what happens when an exposure goes unaddressed, on the reasonable theory that security buyers respond to consequence. Security buyers hear that framing every day from every vendor and have built a reflex against it. What replies we did get came back defensive, several were hostile, and one prospect forwarded the email to a peer group with a comment we had earned.

The opener as it first went out.

What we changed: the framing moved from consequence to specificity. Rather than what could happen, the opener named one thing we could already see and asked whether it mattered. Nothing about the underlying offer changed. Reply quality changed inside a fortnight.

### The calendar link went out too early.

The first sequence carried a booking link from step one, on the grounds that a booked call is the point. To a buyer who has never heard of you, a link on first contact reads as a demand for thirty minutes from someone with no claim on them. It suppressed replies from exactly the senior end of the list we wanted most.

What we changed: the link came out of the opener entirely and moved into the reply, sent by a person once the prospect had already said something. Booking rate per positive reply rose sharply, and the seniority of who booked rose with it.

### The offer sat too far down the message.

Early drafts opened with context, worked through relevance, and reached the actual proposition in the fourth paragraph. On a phone that is below the fold. A security leader clearing an inbox between meetings never reached the part that would have made them reply.

What we changed: the proposition moved into the first two lines and everything that had preceded it was deleted rather than relocated. The message lost half its length and beat the version that explained itself.

Nothing that runs for a year runs clean, and a document showing none of this has had the section taken out. We would rather you saw the corrections, because those are the parts that recur on your engagement.

12

## Why this works in enterprise security specifically

The security vendors that come to us arrive with the same complaint, close to word for word. The product wins whenever it gets evaluated, inbound produces a trickle nobody can forecast, and the partner channel introduces them to whoever the partner happens to know. None of that is a route to the accounts they actually want.

This market suits the channel for three specific reasons:

- The trigger is public. Funding, breach disclosures, compliance deadlines, audit cycles and security hiring all surface months before a budget is committed. That signal is searchable, so the timing problem answers itself.

- One contract covers a quarter of the programme. At an average contract of roughly $177,847 with renewal behind it, a handful of results carries the whole engagement. Almost no other channel has that arithmetic.

- Asking costs them nothing. A question about whether one specific exposure is live can be answered in a line by someone who already knows, and the quality of what comes back reflects that.

13

## Why would this work for your business?

### Possibly it will not, and establishing that now is free. Read down the table.

This works ifThis does not work if

Pipeline arrives through inbound and partners you do not controlDemand already outstrips what the team can service

There are hundreds of thousands of security leaders you could serve and no route to themYour market is a few dozen accounts the founders already know personally

A single contract is worth six figures and renewsYour economics cannot carry a programme that pays back across a full sales cycle

Something observable tells you a security programme is being rebuiltNothing separates an account that needs you this year from one that never will

Someone can filter replies before they reach an account executiveEvery reply has to land on the head of sales

If the left column describes you, what carries over is the method rather than anything particular about this client. A vendor with a product that wins evaluations, a channel that introduces it to the wrong accounts, and no way to reach the right ones directly. All of the above came out of process, and the process does not change for you.

14

## One more thing worth understanding

The first six weeks of a programme like this look like nothing is happening, and sitting through that is the hardest part of the engagement.

Domains warm before they send. Sequences run their full length before anyone can judge them. A five-step cadence on four and seven day gaps means a contact entered in week one does not finish its sequence until week four, and the replies that matter tend to arrive on the later steps. Meanwhile the dashboard shows sends climbing and almost nothing coming back.

Every client we have worked with has had this conversation in week four, and it is a reasonable conversation to have. The honest answer is that the shape of the curve is known and its timing is not something anyone can compress. The mistake available at that moment is to change the copy, widen the list or raise the volume, each of which resets the clock rather than moves it.

So we say it in advance. Weeks one to six are construction. Somewhere between weeks six and ten the reply data becomes readable and the angles start separating. From there it compounds, and by month four the pipeline arrives on a schedule you can plan against. Anyone promising results inside the first month is describing a different kind of programme.

15

## Before and after

Before After

Source of enterprise pipelineinbound and channel partners only a direct engine running alongside both

Access to security leadershipwhoever a partner happened to know 570 booked calls across twelve months, 412 held

Qualified pipelinenone from direct outbound $32,012,460 across 180 opportunities

Average contract value$45,600 $177,847, a 3.9x increase

Outbound volumenone 3,762,430 emails to 752,486 contacts

16

## If you want to know whether your market has this in it

A quarter of an hour usually settles it. Tell us which organisations you want as customers and what a contract is worth across its life. We come back with how many of them are genuinely reachable, what conversation volume is realistic against that number, and a direct answer on whether this channel suits you.

If the answer is no, we say so on that call. Neither of us gains from finding out in month three.

## Want to know whether your market has this in it?

The first conversation is short. You tell us who your buyers are and what one is worth to you. We tell you how many we can actually reach, what the meeting volume looks like, and whether outbound is the right lever for you at all.

If we think it is not, we will say so.

Book a consultation call

→

## Read another one

[Executive Search Firm](https://stonehaven.capital/showcase/executive-search-firm/)[How we closed 14 supply chain and operations placements worth $1,089,760 for a retained search firm in six months.](https://stonehaven.capital/showcase/executive-search-firm/)[Fractional CFO & Outsourced Accounting](https://stonehaven.capital/showcase/fractional-cfo-outsourced-accounting/)[How we closed 48 fractional CFO retainers worth $3,452,880 for an outsourced finance firm in six months.](https://stonehaven.capital/showcase/fractional-cfo-outsourced-accounting/)[All case studies](https://stonehaven.capital/case-studies/)
