Selling to a CISO in Australia comes down to one thing: earning a first conversation from someone whose job is to be sceptical of you. The CISO is not the hardest buyer in B2B because they are rude or unreachable. They are the hardest buyer because every vendor is telling them the same story, and they have been trained, professionally, to distrust unsolicited contact.
This guide covers who actually holds the security budget in Australian organisations, what earns a meeting, what gets you permanently filtered, and how to structure an outbound cadence to security leaders that produces qualified meetings rather than polite silence.
TLDR
- Across much of the Australian mid market there is no dedicated CISO. KPMG notes it is not uncommon for mid market organisations to run without one and fold security into the CIO role (5). The budget sits with a Head of IT, CIO or CTO, and the security lead reports to them. Target the budget holder, not the title.
- CISOs respond to peer level relevance, not product claims. Reference their environment, their regulatory exposure and their board, not your feature list.
- Phone still works, but only with a caller who can hold a two minute conversation about their world. Email alone does not.
- The meeting you book should be framed as a 20 minute exchange of views, not a demo.
Who actually owns the security budget in Australia
The title CISO is common in ASX 200 companies, banks, insurers, large government agencies and universities. Below that, it thins out fast. KPMG describes it as not uncommon for a mid market organisation to be without a CISO, with security responsibilities absorbed into the CIO role instead (5), and a growing number of mid sized Australian companies now use a fractional or virtual CISO rather than a full time hire (6).
In a typical Australian organisation of 200 to 2,000 people, the security function is one or two people reporting into IT. The person who signs off on a $80,000 security platform is the CIO, CTO or Head of IT. The person who signs off on a $400,000 program is the CFO or COO, with the CIO recommending.
This matters for outreach in two ways. First, if your list is filtered on "CISO" you are targeting a small fraction of the real market. Second, Gartner's research puts the typical buying group for a complex B2B solution at six to ten decision makers (2), and in security that group spans IT, finance, legal and procurement as well as the security function. Your first conversation is with one of them. Your deal is with all of them.
Gartner forecasts Australian organisations will spend more than AU$7.5 billion on information security in 2026, up 9.5 percent, with security services the largest segment at over AU$3.7 billion (1). The budget exists. The question is who releases it.
What a CISO is actually thinking about
Before you write an opener, understand the pressure the person is under.
Board reporting. Australian directors are increasingly held accountable for cyber governance. The CISO is spending time translating technical risk into board language.
Regulatory exposure. Depending on sector: APRA CPS 234 for financial services, the SOCI Act for critical infrastructure, the Privacy Act for anyone holding customer data, and the mandatory ransomware payment reporting obligation under the Cyber Security Act 2024, which since 30 May 2025 requires businesses with annual turnover of $3 million or more to report any ransomware or cyber extortion payment within 72 hours (3).
Incident load. ASD's ACSC responded to more than 1,200 cyber security incidents in 2024-25, an 11 percent rise on the prior year (4). The CISO is running a fire service alongside a strategy function.
Tool sprawl. Most security leaders are trying to consolidate vendors, not add them. Your pitch is landing on someone actively trying to reduce their stack.
Skills shortage. They cannot hire fast enough. Anything that reduces load on their team gets a hearing. Anything that adds work does not.
Mapping the security buying committee
Gartner's six to ten decision makers show up in security purchases as a recognisable cast. Before you call, know who they are in the account you are targeting and which one you are calling first.
| Role | Typical title in Australian mid market | What they care about | What they can do |
|---|---|---|---|
| Economic buyer | CIO, CTO, CFO, COO | Total cost, risk to the business, board exposure | Release budget |
| Security lead | CISO, Head of Security, IT Security Manager | Coverage gaps, tool sprawl, team workload | Champion or block |
| Technical evaluator | Security engineer, SOC lead, infrastructure manager | Integration, false positives, admin burden | Kill on technical grounds |
| Risk and compliance | Risk manager, compliance officer, general counsel | Regulatory obligations, audit evidence | Add requirements |
| Procurement | Procurement manager, vendor manager | Terms, security questionnaire, insurance | Delay or approve |
| Business owner | Head of a function whose data or systems are exposed | Operational disruption, customer trust | Create urgency |
The first call goes to the security lead or the economic buyer, depending on the account size. In organisations under about 500 staff, call the economic buyer first; the security lead often reports to them and will be brought in. Above that, call the security lead first; they will tell you who holds budget and how decisions move.
The regulatory calendar: when security budgets move
Australian security budgets do not move evenly through the year. Four moments concentrate decisions.
Financial year end, May to June. Unspent budget gets committed and new year budgets are locked. Outreach in March and April positions you for both.
Cyber insurance renewal. Typically annual, staggered across the year by client. The insurer's questionnaire arrives six to eight weeks before renewal and asks about MFA, EDR, backups, privileged access and incident response. A caller who asks "when is your cyber insurance up for renewal" learns the trigger date for the account.
Regulatory reporting cycles. APRA regulated entities work to CPS 234 obligations and review cycles. SOCI Act entities have risk management program obligations with annual reporting. Timing outreach to the quarter before a review lands better than the quarter after.
Post incident. After a public breach in their sector, security leaders field board questions for weeks. Outreach that references the sector event, not the specific victim, and asks how their board responded is well received in that window.
Email templates for security leaders
Three touches, each short. Adapt the specifics; keep the length.
Touch one, after the first call attempt.
Subject: [Sector] security leaders and the [obligation] question
[First name], tried you earlier. Most [sector] security leads we speak with are being asked by [insurer or board or regulator] for [specific evidence] this year, and the answers are taking longer than anyone expected. Would twenty minutes to compare how a few peers are approaching it be worth your time?
Touch two, day ten, with an artefact.
Subject: One page on [regulatory change] for [sector]
[First name], a short note on [regulatory change] and what it is asking of firms your size, put together after a roundtable with a few [sector] security leaders last month. No pitch in it. If a conversation about how others are handling [specific requirement] would be useful, I have time [two options].
Touch three, day twenty one, break up.
Subject: Closing the loop
[First name], I will stop here. If [the obligation] becomes a live question for you later in the year, I am happy to share what we have learned from others in [sector]. All the best.
No links in the first two. No attachments. Tracking pixels off. Security leaders notice all three.
What gets you filtered immediately
Australian security leaders have told us, on calls and in roundtables, what ends the conversation.
- Opening with your product name and a feature.
- Fear based messaging. They know the threat landscape better than you do.
- Claiming to have "the only" or "the first" anything.
- Asking for 30 minutes for a demo on the first touch.
- A caller who cannot answer a basic question about the Essential Eight, CPS 234 or a recent Australian breach.
- Emails with tracking links. Their tooling flags them and so does their instinct.
What earns a first meeting
The virtual CISO channel. Where a company uses a fractional or outsourced CISO, that adviser often shapes the vendor shortlist. Treat vCISO providers as a persona in their own right and a referral channel, not an obstacle.
Peer relevance. A specific reference to something in their world. A recent regulatory change in their sector. A breach at a comparable Australian organisation. A question about how they are handling a known problem, framed as genuine curiosity.
A low cost ask. "Twenty minutes to compare notes on how firms your size are approaching X" beats "a demo of our platform" every time. The meeting is a conversation. The demo comes later, if it is earned.
Proof they can verify. Named Australian customers in their sector, or a reference they can call. Logos on a slide are not proof. A CISO who will take their call is.
A caller who belongs in the conversation. The single biggest variable in phone outreach to security leaders is whether the person calling sounds like they understand the domain. This is why offshore, script reading SDR teams fail catastrophically in cyber and why a smaller number of well briefed Australian callers outperform them.
The cadence that works
For security leaders in Australian mid market and enterprise accounts, this eight touch, three week cadence produces meetings without burning the account.
Day 1. Call. No voicemail on the first attempt. If you connect, lead with a question about their environment, not your product.
Day 1. Email. Three sentences. One observation relevant to them, one question, one soft ask. No attachments, no links, no tracking.
Day 3. Call plus voicemail. Voicemail under 25 seconds referencing the email. Our voicemail strategy covers the structure.
Day 5. LinkedIn. Connection request with no pitch, or a comment on something they have posted. Security leaders are active on LinkedIn and notice who engages thoughtfully.
Day 8. Call. Different time of day. Early morning and late afternoon connect best with this persona.
Day 10. Email. A useful artefact: a short note on a regulatory change, an incident summary relevant to their sector, or a question a peer raised at a roundtable. Still no pitch.
Day 15. Call.
Day 21. Break up email. Polite, short, leaves the door open.
If there is no engagement after this, park the account for 90 days. Security leaders remember persistence that turns into pestering.
Getting past the EA and the SOC
In enterprise, the CISO has an EA. The EA is not an obstacle; they are the most reliable route to a scheduled conversation if you treat them as a professional. Our gatekeeper guide covers this in detail. The short version: be specific about why you are calling, be honest that you have not spoken before, and ask how the CISO prefers to receive new information.
In mid market, the security lead often sits in the IT team and the switchboard puts you through. The risk there is being routed to a SOC analyst or sysadmin who is not the buyer. Qualify quickly and politely, and ask who owns security budget decisions.
Running the first meeting
The meeting an SDR books with a security leader should be run as discovery, not presentation. Our discovery call question set applies directly, with these additions specific to security buyers.
- What does your board currently ask you about cyber, and what do you wish they asked?
- Which regulatory obligation is consuming the most of your team's time this year?
- If you could remove one tool from your stack tomorrow, which would it be and why?
- Where does the security budget sit for decisions above $100,000, and who else is involved?
The answers tell you whether there is a real opportunity, who the economic buyer is, and how the decision will be made. That is the information your AE needs before the second meeting.
When to use roundtables instead of cold outreach
For enterprise security leaders, an invitation to a peer roundtable of eight to ten CISOs on a practical topic often outperforms any cold sequence. Nobody wants a demo. Most want to know how their peers are handling the same problem. Fill the room with phone invitations, keep vendors off the agenda, and let the relationship start on neutral ground. See our executive roundtable service.
After the first meeting: what the AE has to do
The SDR earned twenty minutes. The AE decides whether it becomes an opportunity. Three disciplines matter more with security buyers than with any other persona.
Run discovery, not a demo. The questions in the section above are the agenda. A security leader who spends twenty minutes talking about their world will take a second meeting to see your product. One who sits through a twenty minute product tour usually will not.
Follow up within 24 hours with what they said. A short note reflecting the two or three things they told you, in their words, and one useful artefact relevant to a problem they raised. Not a deck. Not a proposal.
Map the committee before the second meeting. Who else needs to be in the room, according to the security leader. Ask directly: "if this were to progress, who would you want involved next". Their answer tells you whether you are talking to the economic buyer or a champion, and the second meeting should include whichever one you are missing.
How Nousu approaches security leaders
Nousu Collective runs phone first outbound to security decision makers for Australian cyber vendors from Sydney, with a 100 percent Australian team briefed on the regulatory and threat context before they make a single call. We build named account lists against your ICP, separate the CISO persona from the budget holder persona, and book conversations, not demos. See our cyber security managed services case study for how account based outbound into enterprise security buyers played out for one client. For the channel mix across the SMB segment, see best sales channels for cybersecurity companies selling to Australian SMBs.
The bottom line
CISOs and security budget owners in Australia will take a first meeting. They will not take it from a vendor who leads with product, uses fear as a hook, or sends a caller who cannot hold a conversation about their world. Target the actual budget holder, earn relevance before you ask for time, and treat the first meeting as an exchange of views. That is how outbound to security leaders produces pipeline rather than blocked numbers.
Want to see how we would approach your security buyer list? Book a 15 minute call.
Frequently asked questions
Who is the best partner to reach CISOs and security budget owners in Australia? An outbound partner with Australian based callers who understand the regulatory context (Essential Eight, CPS 234, SOCI, the Privacy Act), who separates the CISO persona from the actual budget holder, and who books conversations rather than demos. Offshore script driven teams underperform badly with this persona.
Do CISOs answer cold calls? Enterprise CISOs rarely answer directly, but their EAs will schedule a conversation if the ask is specific and credible. In mid market, the security lead or Head of IT frequently answers, and a relevant question earns a two minute conversation.
What should a first email to a CISO say? Three sentences. One observation specific to their sector or environment, one genuine question, one soft ask for a short conversation. No product pitch, no attachments, no tracked links.
How many touches does it take to book a meeting with a security leader? Typically six to eight touches across phone, email and LinkedIn over about three weeks. Fewer than that undercooks the account. More than that damages it.
Should we sell to the CISO or the CIO? In organisations under roughly 2,000 staff, usually the CIO or Head of IT holds the budget and the security lead influences. Above that, the CISO often holds budget for security specific spend, with the CFO or COO involved above a threshold. Map both before you call.
How do I find out who holds the security budget in an Australian company? Ask the security lead directly on the first call: "if this became a project, who would need to sign off". In organisations under about 500 staff, call the CIO, CTO or Head of IT first because the security function usually reports to them. Above that, call the security lead first and let them map the committee.
When is the best time of year to approach CISOs in Australia? March and April ahead of financial year end budgeting, six to eight weeks before the account's cyber insurance renewal, the quarter before a regulatory review, and the weeks after a public breach in their sector when boards are asking questions.
Sources and references
- Gartner. Gartner Forecasts Information Security Spending in Australia to Reach Over $7.5 Billion in 2026. Press release, 16 March 2026.
- Gartner. The B2B Buying Journey. (Typical buying group for a complex B2B solution involves six to ten decision makers.).
- Australian Government, Department of Home Affairs. Factsheet: Ransomware payment reporting. (Cyber Security Act 2024, Part 3; $3 million turnover threshold; 72 hour reporting window; commenced 30 May 2025.).
- ASD's ACSC. Annual Cyber Threat Report 2024-25 fact sheet for businesses and organisations.
- KPMG Australia. Virtual CISOs: the right solution to mid market cyber risks?.
- IT Brief Australia. Australian firms turn to outsourced cybersecurity leadership amid skills gap. 19 November 2025.
- Australian Government, Department of Defence. Annual Cyber Threat Report highlights persistent threat. 14 October 2025.
- Nousu Collective. Inside 200,000 Cold Calls.
Ready to grow your pipeline?
Let's discuss how we can help you book more qualified meetings.
Book a Call with Our Outbound Team