Cybersecurity lead generation in Australia is harder than lead generation in almost any other B2B category, and the reason is structural. Your buyer is professionally sceptical, your competitors sound identical, the purchase is triggered by external events you do not control, and the person you need to reach is being pitched by every MSP, insurer and consultancy in the country.
It is also one of the best markets in the world to run outbound in right now. Gartner forecasts Australian organisations will spend more than AU$7.5 billion on information security in 2026, up 9.5 percent, with security software alone growing 12.3 percent (1). ASD received over 84,700 cybercrime reports in 2024-25 and the average self reported cost per report for businesses rose 50 percent to $80,850 (2). The demand is real and it is growing. Vendors who build a disciplined outbound engine now will take share for the rest of the decade.
This playbook is what we have learned running phone first outbound for Australian cyber vendors selling endpoint, identity, managed detection, GRC, backup and recovery, email security and security awareness into SMB, mid market and enterprise accounts.
TLDR
- Build the ICP around the trigger, not the firmographic. Security buys when something external forces the question.
- The list is the campaign. Named accounts, verified direct numbers, mapped budget holder and security lead per account.
- Phone leads. Email and LinkedIn support. Australian callers only.
- Lead with the buyer's obligation (insurer, regulator, customer questionnaire), never with your product.
- Book conversations, not demos. Qualify on the meeting, not before it.
- Measure connect rate, conversation to meeting rate, show rate and meeting to opportunity rate. Ignore dial counts.
Step 1: define the ICP around the trigger
Most cyber vendors define their ICP as "companies with 200 to 2,000 employees in financial services, healthcare and professional services". That is a list filter, not an ICP.
A working cyber ICP has three layers. Our ICP framework covers the general method; the cyber specific version looks like this.
Firmographic. Size, sector, geography, tech stack. The starting universe.
Situational. What has to be true in the account for your product to matter now. Examples: regulated under APRA CPS 234; designated critical infrastructure under SOCI; holds large volumes of customer PII; has a cyber insurance renewal in the next six months; supplies a large enterprise or government body that issues security questionnaires; has recently appointed a new CIO or Head of IT; has grown headcount 20 percent plus in twelve months.
Trigger. The event that releases budget. Insurer demands evidence of MFA, EDR or backups. A supplier questionnaire arrives from a tier one customer. A peer in the sector is breached publicly. A compliance deadline lands. The board asks a question the CISO cannot answer.
Your outbound campaign should be built to reach accounts where the situational layer is true and to surface the trigger in conversation. That is the difference between a campaign that books 5 meetings a month and one that books 25.
A worked ICP: managed detection and response for Australian mid market
An illustration of the three layers, for a vendor selling managed detection and response at $60,000 to $150,000 a year.
Firmographic. Australian headquartered or Australian operating companies with 200 to 2,000 staff, in financial services, health, professional services, education and critical infrastructure supply chains. Microsoft 365 or Google Workspace, a cloud presence, no in house SOC.
Situational. At least one of: regulated under APRA CPS 234 or captured by the SOCI Act; holds significant customer PII; supplies a tier one bank, insurer, government body or ASX 100 company; has appointed a new CIO, CTO or Head of IT in the last twelve months; has grown headcount more than 20 percent in a year; runs a security team of three people or fewer.
Trigger. Cyber insurance renewal in the next six months. A customer security questionnaire received in the last quarter. A publicly reported breach at a comparable organisation in their sector in the last ninety days. A board request for a cyber posture report. A failed or pending audit finding relating to detection or response.
From a universe of several thousand companies meeting the firmographic layer, the situational filter typically produces 1,500 to 2,500 accounts, and the trigger layer is surfaced in conversation rather than in the list. That is the campaign.
Step 2: map the buying committee per account
In Australian organisations under roughly 2,000 staff, there is usually no CISO. Security reports into IT. The budget holder is the CIO, CTO, Head of IT, or for anything material, the CFO or COO. Above that size the CISO often holds a dedicated budget, with finance and procurement involved above a threshold.
For each account on your list, identify two people.
The budget holder. Who signs. Usually CIO, CTO, Head of IT, or CFO.
The security lead. Who evaluates and champions. Security manager, IT security lead, or CISO where one exists.
Call both. Different openers, same account. Our companion guide on selling to CISOs in Australia covers the security leader persona in depth.
Step 3: build the list properly
The list is 60 percent of campaign performance. Three rules.
Named accounts, not a database dump. 1,500 to 3,000 accounts that fit the situational ICP, built and verified by a person, not exported from a global database on a keyword filter.
Verified direct numbers. Australian mobile and direct dial coverage in global databases is thin. Local providers with ABN verified records consistently outperform on mobile hit rates for Australian contacts (3). Expect to combine two or three sources and verify by hand for senior contacts.
Fresh. B2B contact data decays quickly as people move roles. A list built in January is materially degraded by June. Refresh quarterly and re verify anyone you have not reached in 90 days.
If you are outsourcing outbound, ask the provider who builds the list, from what sources, and whether you own it at the end. See our guide on where Australian B2B leads actually come from.
Segmenting the list into three tiers
A single flat list wastes the best accounts. Split it before the first call.
Tier one: 200 to 300 accounts. Strongest situational fit, known trigger (renewal date, questionnaire, recent appointment), two mapped contacts with verified mobiles. These get the full cadence, personalised research before every call, and the senior caller.
Tier two: 600 to 1,000 accounts. Good situational fit, trigger unknown. Full cadence, lighter personalisation, first pass by the whole team to surface triggers.
Tier three: the remainder. Firmographic fit only. Worked in the gaps, used to test new openers, and promoted to tier two when a conversation reveals a trigger.
Report conversion by tier. Tier one should convert conversations to meetings at the top of the range; if it does not, the ICP definition is wrong and no amount of volume in tier three will fix it.
Step 4: choose the channel mix
For Australian cyber, phone leads and everything else supports. Three reasons.
Security aware buyers distrust unexpected email. Your prospect's own IT team is training them not to click unknown links. Cold email into a security audience fights the behaviour the buyer is paying for. Reply rates sit at 1 to 3 percent and only a fraction convert to meetings.
The pitch needs a conversation. Cyber is a trust and context purchase. Two minutes of live conversation about their environment does what six emails cannot.
SMB and mid market decision makers answer the phone. Below enterprise, IT managers and business owners pick up. Across more than 218,000 cold calls into Australian senior decision makers, Nousu's published data shows phone first outbound converting conversations to meetings at 15 to 25 percent (4).
Run phone, email and LinkedIn as one sequence against one list, with phone as the lead touch. For the full channel comparison including partners, events and inbound, see best sales channels for cybersecurity companies selling to Australian SMBs.
Step 5: write messaging that leads with the obligation
Security buyers filter product led outreach in seconds. What they engage with is a question about an obligation they already have.
Insurance. "Most firms your size we talk to are being asked by their insurer for evidence of MFA, EDR and tested backups at renewal. Has that landed on your desk yet?"
Customer questionnaires. "Have any of your larger customers sent through a security questionnaire in the last twelve months, and who ended up filling it in?"
Regulation. For financial services: "How is the team tracking against CPS 234 this year?" For critical infrastructure: "Where has the SOCI risk management program landed for you?" For anyone with customer data: "With the Privacy Act changes, who owns the data breach response plan internally?"
Essential Eight. "If you had to put a maturity level on the Essential Eight today, roughly where would you land?"
Board pressure. "What is the board asking you about cyber this year that they were not asking two years ago?"
None of these mention your product. All of them surface whether a trigger is live. The product conversation belongs in the meeting.
What to avoid. Fear based hooks. Breach statistics as an opener. "Only" and "first" claims. Feature lists. Asking for a demo on the first touch.
Step 6: run the cadence
An eight touch, three week cadence per contact, with two contacts per account, is the standard we run for mid market cyber.
| Day | Touch | Note |
|---|---|---|
| 1 | Call | No voicemail first attempt |
| 1 | Three sentences, no links, no attachments | |
| 3 | Call + voicemail | Under 25 seconds, references the email |
| 5 | Connect or comment, no pitch | |
| 8 | Call | Different time of day |
| 10 | Useful artefact, still no pitch | |
| 15 | Call | |
| 21 | Break up email | Short, leaves door open |
Best call windows for Australian IT and security leaders in our data are 8:00 to 9:30am and 4:00 to 5:30pm local time. Local time means the prospect's time zone. Perth is two to three hours behind Sydney depending on daylight saving.
After the cadence, park unengaged accounts for 90 days. Persistence beyond this point damages the account and your brand in a small market where security leaders talk to each other.
Handling the objections you will hear
Six objections dominate cyber cold calls into Australian mid market accounts. Script the responses, then coach callers to deliver them as conversation.
"We have a SOC / MSSP / provider already." Ask what it covers, what the last report told them, and what happens at 2am on a Sunday. Most mid market providers cover less than the buyer believes.
"We are covered by our insurer." Insurance pays after the event. Ask what the insurer required at the last renewal and whether the requirements have changed. They usually have.
"We did a penetration test last year." A point in time test is not detection. Ask what changed in the environment since and who is watching now.
"Not a priority this year." Ask what is, and whether any of it touches data, customers or the board. Security is usually inside the priority they name.
"Send it to the security team." Good. Ask for the name, and ask whether the person you are speaking with would want to know if the security team found something material. That keeps the economic buyer in the loop.
"We are too busy right now." Acknowledge it, ask when the current project lands, and book the callback with a specific date. Busy is a timing signal, not a rejection.
Step 7: book the right meeting
The single biggest mistake in cyber outbound is booking a demo. A demo request on a first touch gets declined. A demo booked from a cold call has a poor show rate because the buyer agreed to end the call, not to see your product.
Book a 20 minute conversation. Frame it as an exchange of views on how comparable organisations are handling a specific problem. Let your AE or founder run it as discovery. If there is a real opportunity, the demo is the second meeting and the buyer asks for it.
Define what "qualified" means before the campaign starts and hold the SDR function to it. A reasonable definition for cyber: the contact owns or materially influences security spend, the organisation fits the situational ICP, a trigger or active initiative was confirmed on the call, and the meeting is with the right internal person on your side. Our guide on how an outbound agency should define a qualified meeting goes further.
Step 8: measure what predicts pipeline
Ignore dial counts. Track the four numbers that predict revenue.
| Metric | Realistic range, Australian cyber outbound | Below this, fix the campaign |
|---|---|---|
| Connect rate (conversations per dial) | 8 to 15% mid market, 5 to 10% enterprise | Under 6%: list quality or call timing |
| Conversation to meeting | 15 to 25% | Under 10%: messaging or caller capability |
| Meeting show rate | 75 to 85% | Under 65%: meeting framed wrong or booked too far out |
| Meeting to opportunity | 40 to 60% | Under 30%: qualification definition or ICP |
A dedicated phone first program in cyber should produce 12 to 25 qualified meetings a month once ramped, depending on ICP breadth and deal size. Our SDR metrics guide covers the full diagnostic framework. Use the ROI calculator to translate meetings into pipeline for your deal size.
Step 9: stay compliant
Three regimes apply to Australian cyber outbound.
Calls. The ACMA Telecommunications (Telemarketing and Research Calls) Industry Standard applies to all telemarketing calls to Australian numbers regardless of whether the number is on the Do Not Call Register, and sets identification, caller ID and calling hour requirements. Penalties for breaches can reach $250,000 (5). Business numbers are largely outside the Register's scope, but the standard still applies.
Email and SMS. The Spam Act governs commercial electronic messages. Consent, identification and unsubscribe requirements apply.
Data. The Privacy Act governs how you collect and use personal information, including purchased contact data.
Our cold calling laws guide covers the practical rules. Cyber vendors have a particular reputational exposure here: a security company that runs non compliant outreach does not get a second chance with the buyer.
The weekly review agenda for a cyber program
Forty five minutes. Same agenda every week.
- Numbers by tier. Dials, connects, conversations, meetings booked, meetings held, disputed. Tier one against tier two against tier three.
- Recordings. Eight calls: three that booked, three that did not, two chosen by the caller for a specific question. Listen for whether the obligation led, whether the second question landed, and how objections were handled.
- Trigger log. Every trigger surfaced this week (renewal dates, questionnaires, new hires, board requests), by account. Accounts with live triggers move to tier one.
- Messaging changes. One opener change or one objection response change, tested for the following week. Not five.
- AE feedback. For each meeting held: was the person right, was the need real, what did the handover miss.
- List decisions. Segments to cut, segments to scale, accounts to add from this week's signals.
The handover template for security meetings
Every booked meeting carries this in the CRM and the invite.
Confirmed. Role and reporting line. The pain or obligation in the prospect's words. Current provider or tooling if stated. Timing signal if stated (renewal, audit, board date).
Inferred. Who the SDR believes holds budget. Whether the contact showed champion behaviour. Which trigger is most likely live.
Unknown. Decision process. Other vendors in consideration. Budget range. Regulatory obligations not yet discussed.
Suggested opening for the AE. One sentence that picks up where the call left off, referencing the obligation the prospect named.
The mistakes that burn security buyers
We see the same five errors across cyber vendors that come to us after a failed program.
- Offshore callers. The buyer asks "who are you" and the answer ends the call. In cyber, more than any other category, the caller has to sound like they belong in the conversation.
- Product first messaging. The buyer hears the same pitch weekly. Yours is filtered before the second sentence.
- Demo as the ask. Low acceptance, poor show rate, wrong first meeting.
- Global database lists. Thin Australian mobile coverage, stale titles, no budget holder mapping.
- Volume over precision. 10,000 emails a month into a security aware audience produces spam complaints, domain damage and a brand problem in a small market.
How Nousu runs cyber outbound
Nousu Collective runs phone first outbound for Australian cybersecurity vendors from Sydney with a 100 percent Australian team. Programs typically go live in about two weeks. We build named account lists to your situational ICP, map budget holder and security lead per account, brief callers on the regulatory and threat context, and book conversations rather than demos. Weekly reporting covers connect rate through to meetings held, with call recordings available for review. See our cybersecurity industry page, the cyber security managed services case study and our outsourced SDR service.
The bottom line
Cybersecurity lead generation in Australia rewards precision and punishes volume. Build the ICP around the trigger, build the list by hand, lead with the phone and the buyer's obligation, book a conversation rather than a demo, and measure the four numbers that predict pipeline. Vendors that do this consistently produce 12 to 25 qualified security meetings a month. Vendors that run generic SaaS outbound into security buyers produce blocked domains.
Want a view on how your ICP and trigger map would perform in outbound? Book a 15 minute call.
Frequently asked questions
What is the best way to generate leads for a cybersecurity company in Australia? Phone first outbound into a named account list built around situational triggers (insurance renewals, customer security questionnaires, regulatory obligations), supported by email and LinkedIn, with Australian callers briefed on the domain. Partners, executive roundtables and inbound complete the mix.
Does cold calling work for cybersecurity sales? Yes, particularly below enterprise where IT managers and business owners answer their own phones. The caller must be able to hold a credible conversation about the buyer's environment. Script driven or offshore callers underperform badly in this category.
Who should cybersecurity vendors target in Australian companies? Both the budget holder (usually CIO, CTO or Head of IT in organisations under about 2,000 staff, with CFO or COO above a spend threshold) and the security lead who evaluates. Map both per account.
How many qualified meetings should a cybersecurity outbound program produce? A dedicated phone first program typically produces 12 to 25 qualified meetings a month once ramped, depending on ICP breadth and deal size.
How do we stay compliant running outbound to Australian businesses? Follow the ACMA telemarketing standard for calls (identification, caller ID, calling hours), the Spam Act for email and SMS, and the Privacy Act for how you handle contact data. Business numbers are largely outside the Do Not Call Register but the standard still applies.
How long does it take to build a qualified account list for a cybersecurity campaign in Australia? About two weeks for 1,500 to 2,500 accounts with two mapped contacts each and hand verified senior mobiles, drawing on a local Australian data platform, a global platform and LinkedIn Sales Navigator. Faster than that usually means a database export rather than a built list.
Should cybersecurity SDRs call the CISO or the CIO first? In organisations under about 500 staff, the CIO, CTO or Head of IT, because security usually reports to them and they hold budget. Above that, the security lead first, then the budget holder they identify. Map both per account and call both with different openers.
Sources and references
- Gartner. Gartner Forecasts Information Security Spending in Australia to Reach Over $7.5 Billion in 2026. 16 March 2026.
- ASD's ACSC. Annual Cyber Threat Report 2024-25 fact sheet for businesses and organisations. https://www.cyber.gov.au/sites/default/files/2025-10/Annual%20Cyber%20Threat%20Report%202024-25%20factsheet%20for%20businesses%20and%20organisations.pdf ; Department of Defence media release, 14 October 2025.
- SyncGTM. 6 Best B2B Databases for Australia in 2026. https://syncgtm.com/blog/best-b2b-database-australia ; SMARTe. "Best B2B Data Providers in Australia for 2026.".
- Nousu Collective. Inside 200,000 Cold Calls.
- Do Not Call Register (ACMA). Industry Standards.
Ready to grow your pipeline?
Let's discuss how we can help you book more qualified meetings.
Book a Call with Our Outbound Team