Your incident response firm does solid work. You've handled breaches, ransomware incidents, forensics - the hard stuff that most companies never want to experience but desperately need when it happens. The problem is nobody knows you exist until they're already bleeding.
Cold email for incident response is different from other service businesses. Your buyers don't wake up thinking about you. They think about you during a crisis - and then they call whoever they already know or whoever Google surfaces first. By then, you're too late.
But there's a middle ground. You can reach security leaders, CISOs, and IT directors before they need you - and position yourself as the firm they'll actually call. This post covers what actually works.
Your Real Target: The Pre-Incident Window
Most incident response firms try to sell their services like consulting firms. They don't. You're not competing on "better strategy" or "lower cost." You're competing on trust and top-of-mind awareness.
A CISO who has worked with your firm before - who knows your response time, your team's competence, your actual process - will call you first when something breaks. That's worth thousands in retainer agreements and emergency response fees.
Cold email's job isn't to close a deal. It's to start a relationship that makes you the obvious choice when an incident happens. You're building a warm network of security leaders who know you exist and what you do.
Target three types of people:
- CISOs and Chief Security Officers at mid-market companies (50-2000 employees) - they have budget authority and incident response is a line item in their planning
- IT Directors and Security Team Leads at companies with 100+ employees - they advise on vendor selection and often have emergency procurement authority
- Risk and Compliance Managers at regulated industries (finance, healthcare, legal) - they need documented IR plans and pre-arranged vendors
Skip Fortune 500 companies (they have internal teams and 18-month vendor selection cycles) and small businesses under 50 people (they don't have dedicated security staff and will never pay your rates).
The Segmentation That Actually Works
Your email message needs to change based on what kind of incident response problem the target faces. Generic emails get deleted faster in security than anywhere else - these people read a lot of vendor spam.
Segment your list by:
- Industry: Healthcare and finance have mandatory IR documentation requirements. Financial services cares about transaction fraud. Tech companies think about data exfiltration. Healthcare thinks about ransomware and data theft. Your message changes.
- Company size: A 150-person company in healthcare has one security person doing everything. A 500-person company has a small security team with some specialization. Your solution changes.
- Recent incidents in their sector: If there's been a major ransomware campaign hitting their industry in the last 60 days, that's your opening. They're thinking about it right now.
If you're working with less than 5,000 contacts to start, do this segmentation manually. If you're working at scale, use LinkedIn data or Clearbit enrichment to categorize by industry. Your email infrastructure should let you use conditional logic so you're sending different templates to different segments.
The Core Message Framework
Security leaders trust specificity. Vague claims about "fast response times" or "expert analysts" mean nothing. They want to know what you actually do and what problems you've actually solved.
Structure your email like this:
- Subject line: Reference something specific to their situation - their industry, a recent incident type, or their company directly
- Opening: Show you know their role and what keeps them up at night
- Proof: One specific capability or outcome - not a list of services
- Ask: A low-friction conversation, not a demo or meeting request
Here's what this looks like for a healthcare CISO after a ransomware campaign hit their vertical:
Subject: Ransomware response plan for [Hospital System Name] Hi [Name], We've handled 8 ransomware incidents at healthcare systems in the last 18 months - all within your state. Two of them were at competitors. One thing we're seeing: most systems don't have a documented handoff process between their SOC and external response team. When the breach happens at 2 AM, that confusion costs hours. We usually build that out in a single 90-minute session. If you're looking at strengthening your IR plan, worth a quick call? [Your name]
This works because it:
- Shows local experience (they care about firms who've worked in their region)
- References a specific, current threat (ransomware is hitting healthcare right now)
- Mentions a concrete capability with a time frame (90 minutes, not "process improvement")
- Asks for the smallest possible commitment (a call, not a meeting or proposal)
The email is 4 sentences. It respects that they're busy.
Real Numbers and Expectations
Cold email for incident response firms typically shows:
- Open rate: 25-35% (higher than most industries because your subject lines reference specific threats or company names)
- Reply rate: 3-7% (much lower than consulting because CISOs get crushed with vendor emails, but higher than pure cold outreach once they know you exist)
- Meeting rate from replies: 40-60% (most replies are "tell me more," not meetings. You'll do 1-2 follow-up emails before someone commits to 15 minutes)
- Close rate: 15-25% of people who take meetings (incident response closes slowly - people sign you up for emergency response, not immediate projects, so it's a waiting game)
Send 100 emails per week to your best segments. You should see 3-7 replies per week. Over 90 days, that's 40-60 replies and 10-20 meetings scheduled. Close rate varies, but expect to sign 2-5 clients per quarter from a solid cold email campaign.
The key metric that matters most: how many security leaders have you built a relationship with? After 6 months of consistent outreach, you should have a network of 50-100 CISOs and security directors who know who you are and what you do. That network is your insurance policy for when you want to land bigger deals or build retainer work.
Your Follow-Up Sequence
Most incident response emails won't get replies. Your job is to stay visible without being annoying.
If they don't reply to the first email, send exactly two follow-ups - spread them 7-10 days apart. The second follow-up should add new information.
Subject: One more thing about IR planning Hi [Name], I mentioned our healthcare experience - wanted to add: we keep two senior analysts on-call 24/7 for retainer clients specifically so we can be on-site or remote within 90 minutes of a confirmed breach notification. A lot of firms say that. We actually staff for it. If this is worth 15 minutes sometime next month, let me know. [Your name]
Then stop. If they haven't replied after two follow-ups, they're either not interested or not ready. Re-add them to your list in 6 months and try again. People move jobs, situations change, and a CISO who ignored you in March might be very interested in August after their security audit results come back.
The Gap Between Knowing This and Doing It
This framework is straightforward. It's not complicated. But there's a real gap between understanding cold email strategy and having an actual campaign running consistently.
You need: a clean list of CISOs and security leaders segmented by industry. Infrastructure that doesn't land you in spam folders (this matters more in security because these people have strict email filters). Copy that's specific enough to work but flexible enough to scale. Someone managing replies, tracking opens, and deciding who to follow up with.
That last part is the hard part. You're running a firm. You don't have 6 hours a week to manage list segments, write variations, and track metrics. When that's the case, that's the gap BEC Growth closes - we handle the entire operation from finding the right targets to managing the follow-up sequence so you can focus on delivering great incident response work. Not every firm needs to build this in-house.