Cybersecurity cold email sequence — 54% response rate
9 steps over 30 days. Email, phone calls and LinkedIn. 270 prospects contacted.
Charles Perret
Founder of devlo.ch · March 2026
The 9 keys in the sequence
6 emails, 2 phone calls, 1 LinkedIn message — over 30 days.
Why this sequence works
This campaign observed a 54% response rate with a carefully orchestrated multi-channel sequence. The six emails do not repeat the same message: each touchpoint offers a new angle of value. The introduction sets out the problem, the second email proposes a concrete action, the third shares a technical resource and the fourth offers an easy route to the right contact.
Making the first phone call at Touch #5, after four emails, is a deliberate sequence choice. The prospect may already recognise the sender’s name, and the call can revisit issues introduced by email. Treat that familiarity effect as a hypothesis to test with each audience.
A/B testing the first subject line lets you compare formulations on a defined sample. The “virtual coffee” PS in Touch #2 humanises an otherwise technical exchange. Measure the effect on opens and responses by variant.
What you can learn from this campaign
- Organise 30 days into 9 sections. The follow-up schedule is staggered: 3 days between the first emails, then 4–5 days, with calls concentrated in the second half of the fortnight. This gradual build-up prevents the prospect from becoming overwhelmed too soon.
- Using a variety of channels increases reach. A CISO might ignore emails but answer the phone, or vice versa. Combining email, phone and LinkedIn creates different contact opportunities; measure each channel’s contribution within your cohort.
- Quantitative social proof instantly lends credibility. A quantified result supports credibility only when it is verified and attributable to the named client. Compare it with qualitative copy in a controlled test before drawing conclusions about CTA performance.
- The breakup email (Touch #8) wins over the undecided. By announcing the end of the sequence, you give the prospect an easy way to respond: postpone, decline or accept a call. Measure this variant against a standard final email.
- Make the call after four emails, not before. Touch #5 is the first call. By this stage, the prospect has had four opportunities to see your name. Verify within your cohort whether that context improves pick-up compared with a first-contact call.
When to use this sequence
Targeting CISOs and security decision-makers
Your ICP includes CISO, CIO, DPO, CTO and other similar roles. These professionals receive a high volume of communications — the multi-channel approach is designed to reach them.
Sales of cybersecurity or IT solutions
Whether your product focuses on access management, threat detection, security auditing, compliance or infrastructure protection, the value proposition can be easily adapted.
Regulated industries
Finance, healthcare, the public sector, energy — organisations in these industries face compliance obligations that make cybersecurity a top priority. The urgency is already there.
Sales cycle of 3 to 6 months
The 30 days of this sequence cover the initial engagement phase. For complex deals involving multiple decision-makers, it is used to secure the first meeting.
Who can use this sequence?
Cybersecurity sales teams
If you sell IT security solutions (SIEM, PAM, IAM, penetration testing, GRC), this sequence is your starting point. Tailor the value proposition to your product.
SDRs aimed at IT security professionals
The call script includes qualification questions and objection-handling techniques specific to the cybersecurity sector. Ready to use.
Cybersecurity channel partners
System integrators, resellers, security consultants — if you represent a software vendor, this guide will help you structure your sales approach from start to finish.
Any B2B publisher selling to CISOs
Even outside the realm of pure cybersecurity, if your buyer persona is the CISO (e.g. backup, cloud, compliance), the structure and timing of this sequence still apply.
Frequently Asked Questions
How many keystrokes are required in a cybersecurity sequence?
This campaign uses nine touchpoints over 30 days to alternate email, phone and LinkedIn without repeating the same message. Treat that format as a starting point: adapt the number of touches and channels to audience signals, then compare cohorts.
When is the best time to contact a CISO?
Test several calling windows around the audience’s time zone and working patterns. In this sequence, the first call comes at Touch #5 after four emails; compare that placement with an earlier call before treating it as a rule.
How can I tailor this sequence to my business?
Adapt three elements: (1) replace the icebreaker with a real event from the prospect’s context. (2) Use only verified metrics in the value proposition. (3) Cite a comparable client with permission. Test the structure and timing on your own audience as well.
Want a customised sequence for your industry?
devlo designs and executes bespoke B2B cold email campaigns. ICP, buying signals, multi-channel sequences — we take care of everything.
Last updated: March 2026
