Skip to Content
HandbookSalesOutbound sales

Outbound sales

Hold up, we’re doing outbound?

Yes! Most people haven’t heard of SucuriLabs yet. We don’t have an inbound pipeline to rely on, so outbound is how we meet the people we build for.

We’re trying to reach more of our ICP: security and IT teams that spend too much time investigating email threats. Waiting for them to find us won’t tell us whether we’re solving their problem. Talking to them will.

That doesn’t mean copying the same boring outreach everyone else sends. Our audience is technical and can spot a generic pitch a mile away. Outbound should be a focused conversation with someone who has a reason to care, not a race to send the most messages.

Let’s get on the same page - what is outbound?

Outbound means we start the conversation. The person might:

  1. Never have heard of SucuriLabs
  2. Know what we do, but never have spoken to us
  3. Have spoken to us before, but not be in an active sales conversation

The first two are cold outreach. Reconnecting with someone we already know is warmer, but knowing us doesn’t mean they’re interested in buying.

We contacted them. They don’t owe us their time or a meeting.

What we’re doing today

Our model is simple:

  • The founders handle prospecting, first calls, demos, and follow-up.
  • We contact prospects manually on LinkedIn.
  • We keep prospect records, conversations, and next steps in TwentyCRM.
  • Our custom company-enrichment pipeline uses third-party sources and updates company information weekly.

We use who we build for and the ICP fit score to find companies worth talking to. The score tells us how well a company fits, not whether someone wants to buy. We still need to have the conversation.

The goal is to book useful demos and, when there’s a fit, agree on a paid pilot. We’re also learning which problems people care enough about to solve. Write down what you learn so the next conversation is better.

How we talk to outbound prospects

Remember, we contacted them. Be transparent about why we reached out and who we build for. How well we understand their problem will dictate how well we can explain SucuriLabs.

If they’re interested, we’ll show them the product and help them evaluate it. If we’re not a fit, we’ll say so honestly. We need to earn the right for each step and not assume their interest.

So, what does that mean for a first conversation? We:

  1. Do research and get context
  2. Are human and transparent when we meet them
  3. Explore their role and current setup
  4. Qualify or disqualify
  5. With permission, give a brief SucuriLabs pitch
  6. Ask the hard question
  7. Agree on a relevant next step and schedule it on the call
  8. Update TwentyCRM
  9. Rinse, lather, and repeat

Goal: help them decide if SucuriLabs solves a real problem, not close in one call.

In order:

1. We do research and get context

Start with the prospect record and company information in TwentyCRM. Then check their LinkedIn profile and company website. Find out:

  • Do they use Microsoft 365?
  • Does the company fit our ICP, and what does the fit score actually say?
  • What’s their role, and do they investigate email threats themselves?
  • Is there a useful reason to talk now, such as a Microsoft 365 migration or a growing IT team?
  • What did they say when they agreed to the meeting?
  • Have we already spoken to them? What did we learn?

AI can help with research, but check the sources. A guess about their email setup or a made-up incident isn’t a good reason to contact someone. We write our own outreach, just as we write our own marketing copy.

Use this to form a simple hypothesis about what might be worth discussing. The call is where we find out whether it’s true.

2. We are human and transparent when we meet them

We contacted them. This call only makes sense if we can solve a real problem for them. Start with:

“Hey [name], thanks for making the time. I know I reached out to you on LinkedIn, so I appreciate you taking the call.”

“Before we dive in, what made you decide to take it?”

Often this is enough. If they’re vague or skeptical, explain the reason you reached out:

“I saw [confirmed detail, such as your Microsoft 365 migration]. I’m curious how your team handles suspicious emails today, and whether investigating them takes more time than you’d like. Is that a problem you’re dealing with?”

If they answer clearly, set a simple agenda:

“Got it. I’d like to understand how you’re handling that now, what’s working and what’s not, and then show you how SucuriLabs could help. If it isn’t relevant, we’ll keep this short. Sound fair?“

3. Explore their role and current setup - find the problem

Companies don’t buy software; humans do. Start with their role and team:

“Tell me more about your role and team. Who handles suspicious emails?”

Then move to the work itself:

“Walk me through what happens when someone reports a suspicious email.”

“What tools do you use to investigate it? How did you end up with that setup?”

“What works well? What drives you crazy?”

You’re trying to understand the problem, its impact, and whether they want to do something about it. Dig in as needed:

  • Time: “How long does an investigation take? Which checks are still manual? How many reports does the team handle?”
  • Evidence: “What do you need to know before you can decide whether a message is malicious? What’s hard to find?”
  • Response: “Once you decide, how do you quarantine or restore the message? How do you check what action was taken?”
  • Priority: “Is this something you’re trying to improve now, or something you can live with for the moment?”
  • Decision: “If you wanted to try a tool like this, who else would need to be involved? How does that work at your company?“

4. Qualify or disqualify

We’re looking for three things:

  • Fit: The company and the person match who we build for.
  • A real problem: They can describe something SucuriLabs can solve, and agree it’s worth exploring.
  • An agreed next step: They’re willing to do something specific to find out whether we can help.

Ask about timing and impact. A company can be a good fit without being ready to buy right now.

If we can’t solve their problem, say so:

“Based on what you’ve told me, I don’t think we’re the right fit because [reason]. If [relevant change] happens, feel free to reach out.”

If they’re a fit but the timing isn’t right, agree on whether and when to follow up. If they’re not interested, leave it there.

Bonus: end early if we’re not a fit or they’re disinterested. If they already understand what we do and want a demo, go straight to that next step.

5. With permission, give a brief SucuriLabs pitch

Open with what you heard:

“Based on what you shared about [their problem], let me show you how SucuriLabs handles that, and you can tell me if it’s relevant. Sound good?”

Keep the explanation tied to their problem. A starting point:

“SucuriLabs builds tools for security engineers to investigate and stop email threats. We bring the message, sender analysis, links, attachments, and the reasons it was flagged into one place, so you can check the evidence and decide what to do. You can review the verdict, quarantine or restore the message, and see what actions were taken.”

If their problem is manual investigation, show them the investigation. If it’s handling malicious messages, explain the response options and active prevention. They don’t need a tour of every feature.

6. Ask the hard question

Ask:

“Does that sound like it solves the problem you described?”

If they’re uncertain:

“What’s missing? What would you need to see to know whether this would help?”

Wait. Embrace the pause. Get their answer. If we don’t solve a problem for them, this isn’t worth continuing.

7. Agree on a relevant next step and schedule it on the call

If they’re a fit and interested, book a demo focused on their problem:

“Would it help to walk through an investigation with your team? Who should join us? Let’s find a time.”

After the demo, if they want to evaluate SucuriLabs at their company, discuss a paid pilot. We agree on the scope, goals, duration, price, and setup requirements case by case. Work out what they want to test, who needs to be involved, and what a useful result would look like before starting it.

If they’re hesitant, ask:

“Here’s what I’m hearing: [summary]. I’m not sure we’re a fit yet. What would help you figure that out?”

Whatever the next step is, agree on who will do what and when. “We’ll be in touch” isn’t a next step.

8. Update TwentyCRM

Record what happened while it’s fresh:

  • The problem they described and how they’re handling it today
  • What we confirmed about fit, and anything still unknown
  • Who’s involved in the decision
  • The outcome of the conversation
  • The agreed next step, who owns it, and when it will happen

Then reflect the outcome in the CRM:

  • Qualified with a next step: Create or update the opportunity and record the agreed action.
  • Good fit, but not ready: Record why and set a follow-up if they agreed to one.
  • Not a fit: Record the reason so we don’t keep having the same conversation.
  • Not interested: Record that and stop chasing them.

9. Rinse, lather, and repeat

Follow up with a reason, at the time you agreed. Keep the LinkedIn conversation and meeting notes in TwentyCRM so we know where things stand.

Depending on what they need, you can:

  • Book a technical demo with their security or IT team
  • Ask for an introduction to the person who handles email investigations or approves the purchase
  • Share the incident triage docs or Microsoft 365 setup guide
  • Agree on a paid pilot and schedule its kickoff
  • Review the pilot results against the goals you agreed on

Keep it useful and low-volume. A fifth generic follow-up won’t become relevant just because you sent it. Stay focused on their problem, and don’t assume interest just because a prospect became an opportunity.

When a conversation becomes an opportunity

Create an opportunity when all three are true:

  • ICP fit is confirmed: The company and person match who we build for.
  • The problem is agreed: They described a specific problem we can solve and want to explore it.
  • A next step is agreed: A demo, a meeting with their team, or a paid-pilot discussion has an owner and a date.

A reply or a meeting booking alone doesn’t tell us those things. Neither does a high ICP fit score. Keep the record honest about what we’ve actually learned.

How our outbound data pipeline works

Custom company enrichment (weekly)

Our enrichment is custom-built and uses third-party sources. Company information is updated weekly, and TwentyCRM is where we keep the prospect records and sales activity.

Prospects are matched using their work-email domain or LinkedIn profile. The ICP fit score is recorded on the Prospect object and refreshed when the company is re-enriched.

Our current hard exclusions are companies that don’t use Microsoft 365, public-sector companies, banks, and prospects using personal email addresses.

Check the ICP fit status before using the number. Missing data isn’t a score of zero, and a missing status means the prospect hasn’t been evaluated. Company matching can be wrong, so check the record before reaching out.

Where data lives and flows

SystemRoleHow often updated
TwentyCRMProspect records, ICP fit fields, opportunity tracking, conversation notes, and next stepsAs we work prospects; company enrichment is refreshed weekly
Custom enrichment pipelineMatches companies using third-party sources and refreshes company informationWeekly
LinkedInManual prospect research, outreach, and follow-upAs we contact and talk to prospects
Last updated on