Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training
Direct Answer
Threat Intelligence Selling to the SOC Manager and CTI Lead is a 60-minute training for AEs, SEs, and channel managers running $90K–$650K ACV cycles against incumbents like Recorded Future, Mandiant Threat Intelligence (Google Cloud), CrowdStrike Falcon Intelligence, Anomali, EclecticIQ, ThreatConnect, Flashpoint, Intel 471, Silent Push, and DomainTools.
The session teaches sellers to qualify against the three-buyer reality (CISO, SOC Manager, Cyber Threat Intelligence Lead), run a structured discovery on finished-intelligence-to-action economics, demo against the customer's actual threat surface, and trap-set the multi-year renewal at month 12.
Built on MEDDPICC, Force Management's Command of the Message, and Andy Paul's "Sell Without Selling Out" discovery cadence.
Section 1 — Why Threat Intelligence Selling Is Different (5 min)
Open the room by killing the SaaS-seller default. Threat Intelligence (TI) sales are deeply technical. The CTI Lead is often a former intelligence analyst from NSA, GCHQ, or military intelligence. Generic feature-pitch tactics fail in the first 5 minutes.
Set the frame on the whiteboard.
- Three buyers, three priorities. The CISO funds; the SOC Manager operationalizes; the CTI Lead is the technical evaluator. Recorded Future's 2026 customer survey shows 71% of CTI decisions decided by the CTI Lead.
- Finished intelligence beats indicators-only feeds. Customers no longer buy IOC feeds alone — they buy analyst-finished intelligence reports (PIRs satisfied, attribution, intent assessments).
- Operationalization is the value metric. A TI feed that does not integrate with SIEM, SOAR, EDR, and ticketing is shelf-ware. Recorded Future, Mandiant, and CrowdStrike Intel lead on operationalization depth.
End the segment with Mark Roberge's rule: *"Sell the analyst hours saved, not the feed volume."*
Section 2 — The 60-Minute Discovery Block (15 min)
- Opening (3 min): "Walk me through your current TI program — feeds, finished reports, PIR list, integration points."
- PIR baseline (10 min): "What's your current priority-intelligence-requirement list — geopolitical, sector-specific, brand-monitoring, executive protection?"
- Operationalization baseline (10 min): "What percentage of TI signal is auto-actioned in your SIEM, SOAR, or EDR? Best-in-class is 70%+ auto-actioned."
- Finished-intelligence cadence (10 min): "How many finished intelligence reports does your incumbent deliver monthly? Top quartile delivers 20+ targeted reports."
- Attribution depth (8 min): "Does your incumbent provide attribution down to threat-actor group with confidence ratings? Mandiant is the benchmark."
- Brand-monitoring telemetry (7 min): "Are you monitoring brand impersonation, executive impersonation, and supply-chain telemetry? Flashpoint and Silent Push lead."
- Renewal posture (5 min): "When is your current TI contract up? What contractual extraction friction would we navigate?"
Section 3 — The POC That Wins (15 min)
Failure modes to ban. IOC-feed-only POCs. No-PIR-mapping POCs. 30-day POCs.
Wins to coach. Custom PIR mapping delivered. Walk through Recorded Future's and Mandiant's published POC agendas — both customize the PIR list per customer before the POC. Finished intelligence reports delivered weekly. Deliver 3+ targeted finished reports within the POC window.
Operationalization demo live. Show TI signal flowing into the customer's SIEM and SOAR with auto-action workflows.
End with Andy Paul's rule: *"Show the customer their analyst time freed, not your feed expanded."*
Section 4 — Handling the Incumbent Trap (10 min)
The room will face Recorded Future, Mandiant, and CrowdStrike Falcon Intelligence in eight of ten enterprise deals. Coach the room on three counter-moves.
Counter-move 1 — The operationalization wedge. Ask the SOC Manager: *"What percentage of your incumbent's signal is auto-actioned? Top quartile is 70%+."*
Counter-move 2 — The attribution-depth wedge. Ask the CTI Lead: *"Does your incumbent provide threat-actor attribution with confidence ratings? Mandiant publishes named-actor attribution publicly."*
Counter-move 3 — The finished-report cadence wedge. Ask: *"How many finished reports does your incumbent deliver monthly that are customized to your PIR list? 20+ is best-in-class."*
Show Force Management's command-of-the-message rule: *"Displace on operationalization, not the feed count."*
Section 5 — Pricing Conversation and Procurement (10 min)
Landmine 1 — Per-feed vs. Per-PIR pricing. Per-PIR scales with the customer's intelligence program; per-feed punishes adoption.
Landmine 2 — Multi-year discount math. Three-year deals justify 10–15% discount; five-year deals justify 18–25%.
Landmine 3 — The procurement-only meeting. No procurement-only rule — refuse procurement-only meetings.
Section 6 — The Trap-Set for Renewal at Month 12 (5 min)
Trap-set 1 — Auto-action coverage at 70%+ within 6 months. The number is the renewal narrative.
Trap-set 2 — Finished-report cadence at 20+ monthly within 3 months. Below 10 is renewal-risk red.
Trap-set 3 — PIR refresh every quarter. Lock in the consultative cadence.
Trap-set 4 — Joint TI ROI dashboard in QBR. Build the analyst-hours-saved dashboard into the QBR. By month 12, the dashboard is the renewal narrative.
Close the session by reading Jeb Blount's rule from *"Fanatical Prospecting"*: *"The renewal is sold on day one."*
FAQ
Should we lead with feeds or finished intelligence? Lead with finished intelligence for the CTI Lead; lead with operationalization for the SOC Manager.
How do we handle a customer mid-Recorded Future or Mandiant renewal? Run a complementary deployment focused on a non-overlapping PIR (e.g., brand monitoring while the incumbent runs sector intel). Build proof for the displacement conversation at next renewal.
What is the right POC size for a Tier-1 enterprise? 60 days, custom PIR mapping, 3+ finished reports delivered, SIEM/SOAR integration live.
How do we price against Mandiant's premium positioning? Mandiant wins on attribution depth; we win on operationalization breadth and PIR customization. Position complementary at the entry tier.
What if the customer asks us to integrate with their existing SIEM, SOAR, and EDR? Yes — every modern TI vendor integrates with Splunk, Sentinel, Chronicle, ServiceNow, Cortex XSOAR. Demo live in the POC.
Sources
- Gartner — Market Guide for Security Threat Intelligence Products and Services (2026)
- Forrester — The Forrester Wave: External Threat Intelligence Service Providers (2026)
- Recorded Future — Annual Customer Outcomes Report (2026)
- Mandiant (Google Cloud) — M-Trends Threat Intelligence Report (2026)
- CrowdStrike — Global Threat Report and Falcon Intelligence Benchmarks (2026)
- SANS Institute — Cyber Threat Intelligence Survey (2026)
- Force Management — Command of the Message and MEDDPICC Reference (2026)
- Mark Roberge — "The Sales Acceleration Formula" Premium-Pricing Chapter
- Andy Paul — "Sell Without Selling Out" Discovery Cadence
- Jeb Blount — "Fanatical Prospecting" Renewal-First Doctrine