Penetration testing firms live in a weird position. You're selling something that most companies know they need but haven't prioritized yet. They've got compliance requirements, risk management obligations, and a nagging awareness that their security posture is probably worse than they think - but nobody's knocking on the door asking for a pentest.

That's where cold email works. Unlike outbound sales for, say, accounting or consulting, pentesting has a specific advantage: decision-makers are actively worried about security. They're reading about breaches. Their board is asking questions. They're just not actively shopping for your services yet. Cold email can change that timing.

Here's what actually works for penetration testing firms.

Your Real Prospect List Is Smaller Than You Think

Most pentest firms cast too wide a net. You don't need to email every tech company in a 10-mile radius. You need to email companies that fit three specific criteria: they have meaningful infrastructure to test, they have compliance requirements that mandate security testing, and they have budget.

That's usually companies with 50-500 employees. Too small and they don't have the infrastructure or compliance burden. Too large and they already have security vendors embedded. Mid-market is the sweet spot.

Build your list by industry first. Finance, healthcare, SaaS, and insurance have the strongest compliance drivers (HIPAA, SOC 2, PCI-DSS, SOX). Construction, manufacturing, and retail are also solid if they process payments or handle customer data. Government contractors are gold if you have the certifications to match.

Use LinkedIn filters, ZoomInfo, or Hunter to target companies by size, industry, and location. You're looking for 500-2,000 contact records per campaign, not 50,000.

Your Opening Line Needs to Name a Real Risk They're Facing

Generic openings don't work in security. People get emails about "improving security posture" constantly. What works is naming a specific threat or compliance gap that's relevant to their industry.

Here's an opening that works for SaaS companies:

We've tested 40+ SaaS platforms this year, and about 60% had at least one exploitable vulnerability in their cloud infrastructure or API layer that could have exposed customer data.

That's specific. It's tied to their industry. It's not a scare tactic - it's a statement of fact based on your actual work. A founder or CTO reading that knows it applies to them.

For healthcare organizations, you might open with:

Most healthcare networks we test have at least one path for an attacker to reach PHI without going through primary security controls - usually through vendor access or legacy systems that never got segmented.

Again - specific to their world, based on real findings, not hypothetical.

Lead With Your Findings, Not Your Services

The mistake most pentest firms make is leading with what they offer: "We provide comprehensive penetration testing services." Nobody cares. They care about what's broken.

Your email should mention one specific finding you typically uncover in their industry. You're not describing the methodology or the scope - you're describing the actual risk.

A complete short email might look like this:

Hi [Name], We just finished a pentest at another [Industry] company similar to yours. Found exposed API credentials in their code repository that had been there for 8 months - nobody knew they existed. I'm bringing it up because most [Industry] teams we talk to haven't actually audited what's in their repos. It's one of those things that doesn't show up on a regular vulnerability scan. Would be worth a quick conversation about whether you've looked at that yet. Takes about 30 minutes. [Your name]

That's 80 words. It names a real finding. It frames the conversation as "have you looked at this" not "let us sell you something." The CTA is small and time-bound.

Hit The Right Person - And Know That Person Might Change

Your ideal contact is either the Security Lead, the Infrastructure/DevOps lead, or the CTO. In smaller companies (50-150 people), sometimes it's the IT Director. In larger companies, there's usually a dedicated security team.

LinkedIn is useful here - you can see someone's actual title and history. Look for people who've been in security-related roles for 2+ years. They understand the problem. New hires in security roles are also good - they're often mandated to run audits and assessments.

Avoid HR, Compliance Officers who aren't technical, and Finance. They're not going to champion a pentest. The technical person needs to want it first.

Your Follow-Up Sequence Matters More Than Your First Email

Most pentest firms send one email and call it a day. That's leaving money on the table. Your real response rate comes in the follow-ups.

Run a 4-email sequence over 10 days:

Aim for a 15-25% response rate on that sequence. It won't all be "yes," but it will be engagement.

Pricing Expectations Kill More Deals Than Rejections

Don't quote pricing in email. Ever. Security assessments have too many variables - scope, infrastructure size, testing methodology, reporting depth. You'll either quote too high and lose them, or quote too low and leave money on the table.

Your email should end with a conversation that lasts 15-20 minutes on a call where you understand their actual infrastructure, what they're testing for, and what their compliance requirements are. Then you give them an accurate proposal.

Track What Actually Converts

Send campaigns in batches of 100-200 per week, not 5,000 all at once. This lets you watch response rates, adjust subject lines if needed, and actually handle the conversations that come in.

Track: open rate (good baseline is 25-35%), reply rate (good is 5-10%), meeting booked rate (good is 1-2% of emails sent). If your reply rate is 3%, it usually means your opening line isn't resonating - swap it out and test a new angle.

For more on how to structure testing effectively, see our cold email split testing guide.

The Gap Between Knowing This and Running It

You can build your own list, write your own emails, and manage a sequence. Many pentest founders do. But it takes time to figure out which industries respond, which opening lines work, how to handle replies without derailing your actual delivery work, and how to keep campaigns running consistently while your team is booked with assessments.

That's the gap BEC Growth closes for penetration testing firms - we handle the list building, email writing, sending infrastructure, and reply management so you're not juggling client work and outbound sales at the same time. If you want cold email working at scale without the operational overhead, that's worth a conversation.

Related Guides