Pulse - Value Added
Rent this Advertising Space
FRACTIONAL CRO · MARYLAND-BASED, NATIONWIDE · $0→$200M

Kory White

RevOps & Revenue Leadership

Get a 30-minute revenue checkup — Kory reviews your pipeline and forecast, then names the 1–2 fixes that move revenue fastest. 25 yrs scaling teams $0→$200M.

30-minute revenue checkup →
Hire a Fractional CROHow We Help?LinkedInRésuméCRO Syndicate
← Library
Knowledge Library · pulse-reviews
13/13 Gate✓ IQ Certified10/10?

Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training

Curated by · Fractional CRO · Maryland
PULSEKNOWLEDGE LIBRARY
pulserevops.com
Sales TrainingsThreat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training
📖 3,237 words🗓️ Published Jul 29, 2026
Direct Answer

Threat intelligence sells to three buyers at once: the CISO funds it, the SOC Manager operationalizes it, and the CTI Lead technically validates it. A 60-minute training should teach reps to run joint discovery on priority intelligence requirements, prove auto-action coverage inside the customer's own SIEM and SOAR, and set renewal traps at kickoff rather than month twelve.

The outcome you should expect from this training

Run this session correctly and you should see three measurable shifts inside a quarter, not vague "better conversations."

Shift one: fewer single-threaded cycles. Before the training, most reps book discovery with whoever answered the email — usually the SOC Manager, occasionally a threat intel analyst with no budget authority. After the training, the rep's first calendar invite carries three named attendees and a one-page pre-brief. The rep who can't get all three on the call has learned something valuable in week one instead of month four: this account isn't ready, and the pipeline entry should be re-staged rather than forecast.

Shift two: discovery that produces artifacts. The output of a good threat-intelligence discovery call is not notes. It's a written priority-intelligence-requirement (PIR) list — the customer's own words about what they need to know and why — plus a current-state map of where intelligence lands today (feed → SIEM → analyst queue → ticket → action) and where it dies. That artifact is what the SE builds the proof-of-concept against and what the champion forwards internally when you aren't in the room.

Shift three: pricing conversations that survive procurement. Threat intelligence pricing is genuinely confusing — module-based, seat-based, feed-based, and analyst-hours-based models all coexist in the category, sometimes inside a single vendor's price book. Reps who leave the pricing conversation to a PDF sent after the fact routinely find their proposal reduced to a line-item comparison against an incumbent renewal quote. Reps trained to anchor on the unit the customer already measures — analyst hours, mean time to triage, percentage of alerts enriched automatically — keep the conversation on value density instead of feed count.

Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training — figure 1

What this training is *not* going to do is turn an AE into an intelligence analyst. The CTI Lead has usually spent years in a government, military, or financial-sector intelligence shop. They will detect a rep performing expertise within two questions. The realistic goal is a rep who knows the vocabulary, knows which questions matter, and knows when to hand the technical conversation to the SE without losing control of the commercial one.

A useful adjacent benchmark: the same three-buyer dynamic shows up in vulnerability management, attack surface management, and managed detection and response. If your team already runs a competent MDR motion, most of this training transfers — the difference is that MDR sells an outcome (someone watches your alerts) while threat intelligence sells an input (better context for decisions your team still has to make). Selling an input is harder, because the buyer must connect it to an outcome themselves. That's the whole reason operationalization dominates the sales conversation.

What actually drives the outcome

Four mechanisms do the work. Understanding *why* they work is what lets a rep improvise when the script breaks.

Mechanism one: the buying committee is structurally split. The CISO's question is "does this reduce the risk I have to report to the board?" The SOC Manager's question is "does this reduce alert volume or make triage faster without adding a tool my team has to babysit?" The CTI Lead's question is "is the analysis actually good, and can I defend its sourcing and confidence ratings to my own leadership?" These are three different products in one purchase order. A pitch that satisfies one usually reads as irrelevant to the other two. Reps who present one deck to all three lose on the "so what" test from whichever buyer wasn't addressed.

Mechanism two: intelligence has no value until it changes an action. A feed of indicators sitting in a portal nobody logs into is a subscription, not a capability. The value chain runs: collection → analysis → dissemination → action → feedback. Most failed deployments break at dissemination-to-action, because the intelligence arrives in a format (PDF report, portal dashboard) that requires a human to manually translate it into a detection rule, a block list, or a hunt hypothesis. Sellers who demo the portal are demoing the weakest link. Sellers who demo an enriched alert appearing inside the customer's existing console are demoing the actual product.

Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training — figure 2

Mechanism three: the incumbent's contract shapes the deal more than the incumbent's features. In enterprise security, most accounts already have a threat-intelligence subscription bundled into something else — an EDR platform, an MDR contract, an ISAC membership, or a bundled tier from a cloud provider. The competitive question is rarely "is our intel better." It's "what does this customer already have, what does it not cover, and does the gap justify a separate line item?" Reps who treat every deal as a rip-and-replace burn cycles on displacement math that procurement will never approve mid-term. Reps who scope complementary coverage — brand and executive impersonation monitoring, third-party/supply-chain exposure, sector-specific actor tracking, dark web credential leakage — land smaller initial deals that expand at the incumbent's renewal.

Mechanism four: renewals are decided by usage telemetry, not by relationship. If the CTI Lead who championed the purchase leaves — and security staff turnover is high — the renewal defends itself only if usage data shows the platform embedded in daily workflow. Login counts are a weak proxy. Strong proxies are API call volume, number of automated enrichment actions, detections created from vendor-supplied intelligence, and reports cited in internal incident write-ups.

Benchmarks and realistic ranges

Be careful here — this is the section where sellers most often invent numbers, and a CTI Lead will fact-check you. Use ranges you can source or hedge honestly.

Deal size. Commercial threat-intelligence contracts span an enormous range, from low five figures for a narrow feed or brand-monitoring module to mid-six figures for a multi-module enterprise subscription with dedicated analyst support. Published list pricing is rare in this category; most vendors quote per-environment. Do not state a competitor's price as fact unless you're reading it off a customer-provided quote — if you're wrong, you've handed the incumbent a credibility win.

Cycle length. Expect enterprise threat-intelligence cycles to run one to two quarters when the budget already exists and considerably longer when you're creating a new line item. Cycles that close faster than a quarter almost always mean one of two things: a renewal event forced a decision, or a recent incident created urgency. Both are real; neither is repeatable at scale.

Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training — figure 3

Evaluation length. A meaningful proof of concept needs enough time for the customer to see intelligence they didn't already have, which means covering at least one reporting cycle and ideally one real detection. Two to four weeks is often too short to demonstrate value on anything except brand monitoring and credential leakage, which produce hits quickly. Sixty to ninety days is more honest for finished-intelligence and actor-tracking evaluations, and it lets you deliver multiple finished reports mapped to the customer's PIRs rather than one generic sample.

Operationalization as a scoring metric. Rather than quoting a percentage you can't defend, teach reps to establish the customer's *own* baseline in discovery: "Of the intelligence you receive in a given week, roughly what fraction ends up in an automated enrichment, a detection rule, or a block action — versus read and filed?" Whatever number they give becomes the scoreboard. Improving a customer's self-reported baseline is a far stronger commercial argument than benchmarking against an industry figure they may dispute.

Report cadence and relevance. Volume of finished reports is a vanity metric. The metric that matters is what fraction of delivered reports map to the customer's declared PIRs. A vendor delivering eight highly targeted reports a month beats one delivering forty generic ones, and the CTI Lead knows it. Coach reps to ask the incumbent-comparison question in relevance terms, not count terms.

Multi-year discounting. Multi-year discounts in enterprise security software are common and typically escalate with term length, but the exact tiers are yours to set with your own finance team, not a category constant. What is generalizable: trade term length for something beyond price — reference rights, a case study, a joint webinar, early access to a beta module. A discount given for nothing trains procurement to ask again at renewal.

Where the numbers come from. Point reps at primary sources: Gartner's market guides for security threat intelligence, Forrester's Wave evaluations of external threat intelligence services, the SANS annual CTI survey, and the vendors' own published threat reports. The SANS survey in particular is useful in discovery because it reports on how practitioners actually use CTI — team sizes, tooling, and satisfaction — which makes it a neutral conversation opener rather than vendor marketing.

Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training — figure 4

Risks, edge cases, and failure modes

The analyst ambush. The CTI Lead asks a sourcing question — how collection works, how confidence ratings are assigned, whether attribution is original or aggregated from public reporting. A rep who bluffs here loses the technical champion permanently. The trained answer is a clean handoff: name the boundary of your own knowledge, commit to a specific answer by a specific time, and bring the SE or an in-house analyst to the follow-up. Security buyers respect a rep who says "I don't know, and I'm not going to guess about intelligence sourcing."

The bundled-incumbent wall. The customer already gets intelligence bundled with their EDR or MDR contract at what feels like zero marginal cost. Arguing that the bundled intel is bad rarely works — it's usually decent for its purpose. The productive move is scope: bundled intelligence tends to be strong on commodity malware and endpoint-relevant indicators, and thinner on sector-specific actor tracking, brand and executive impersonation, third-party exposure, and geopolitical context for non-endpoint decisions. Sell the gap, not the replacement.

Incident-driven urgency that evaporates. A breach or a peer's breach creates a fast-moving deal with emergency budget. These close quickly and churn quickly, because the operational work to embed the platform never happened — the customer bought reassurance. If you take one of these deals, over-invest in onboarding immediately, while attention is still high. Six weeks later the urgency is gone and you'll never get the integration meeting.

Procurement-only routing. Security procurement teams frequently try to run late-stage negotiation without technical stakeholders present, which reduces the deal to a price comparison against whatever the incumbent quoted. The counter isn't refusing to meet procurement — that reads as arrogant and can genuinely stall a deal. It's insisting that any scope change discussed in a procurement meeting gets validated by the CTI Lead before you re-quote, because scope and price are coupled.

Data handling and legal friction. Threat intelligence platforms often ingest customer telemetry or require customer domains, executive names, and brand assets for monitoring. That triggers privacy review, data-residency questions, and sometimes works council consultation in European deployments. Reps who surface these requirements in discovery — rather than at contract — avoid a four-week legal stall right before quarter end. This is the single most common preventable slip in the category.

Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training — figure 5

Dark web and takedown expectations. Buyers sometimes expect capabilities the platform doesn't have — active takedowns, engagement with threat actors, or law-enforcement-grade attribution. Set the boundary explicitly and early. Overselling access to closed sources is both a commercial risk and, depending on jurisdiction, a compliance one.

Champion turnover. Security team churn is significant enough that a single-champion deal is fragile by default. Multi-thread deliberately: the SOC shift leads who use the product daily, the detection engineer who writes rules from your intelligence, and the GRC contact who values third-party risk reporting are all secondary champions worth ten minutes each.

The pilot that proves nothing. A POC with no defined success criteria always ends the same way — the customer says "it was interesting" and the deal stalls. Write the criteria down before the POC starts, in the customer's language, with a named owner for each criterion.

A practical rollout plan for the 60 minutes

Here's the run-of-show. Keep it tight; the temptation is to over-lecture and under-drill.

Minutes 0–5: the three-buyer frame. Whiteboard the three roles and their three questions. Ask the room who they've actually been selling to. The honest answer is usually "whoever replies," and naming that out loud is what makes the rest of the hour land.

Minutes 5–20: discovery drill. Not a lecture — a live drill. Reps pair up, one plays the CTI Lead, one runs discovery. Give the seller a fixed question set: current PIR list, where intelligence lands today, what fraction gets auto-actioned, what the last useful report changed, what's bundled from existing vendors, when the incumbent contract renews, and who signs. Fifteen minutes, then a two-minute debrief on which question produced the most information. It's almost always "what did the last useful report actually change?"

Threat Intelligence Selling to the SOC Manager and CTI Lead — 60-Min Training — figure 6

Minutes 20–35: POC design. Take a real open opportunity from someone in the room and scope its POC live. Define the break point you're proving against, the success criteria in the customer's words, the integration required, who installs it, and the review cadence. Reps should leave with a reusable one-page POC scope template.

Minutes 35–48: incumbent and objection handling. Run the bundled-incumbent scenario, the "our intel team already reads the public reports for free" objection, and the analyst ambush. Coach the gap-scoping move and the honest-handoff move. Role-play, don't narrate.

Minutes 48–57: pricing and renewal traps. Cover the pricing model options, the trade-term-for-value rule, and the four telemetry metrics that defend a renewal. Have each rep write down the specific metric they'll define at kickoff for their largest open deal.

Minutes 57–60: commitments. Each rep names one account where they'll rebook discovery as a joint three-buyer call this week. Manager writes them down. Follow up in the next pipeline review — a training with no follow-up inspection decays within two weeks.

After the session. Two things sustain it: a shared PIR-capture template in the CRM so discovery output is structured rather than free-text, and a monthly deal review where one lost deal gets dissected against the three-buyer frame. Adjacent teams — the MDR sellers, the attack-surface-management team, the vulnerability-management crew — benefit from the same frame, so run the abbreviated version for them rather than building separate content.

Related questions

Who should own the CTI relationship after the sale?

Customer success or a technical account manager, paired with an in-house analyst who can speak to sourcing and tradecraft. A purely commercial CSM cannot sustain credibility with a CTI Lead, and the relationship decays into a renewal transaction.

How long should a threat intelligence POC run?

Long enough to cover a full reporting cycle and ideally one real detection. Brand monitoring and credential leakage produce hits fast; finished-intelligence and actor-tracking evaluations need meaningfully longer to demonstrate anything a customer couldn't get free.

Is bundled intelligence from an EDR vendor a real competitor?

Yes, and pretending otherwise loses deals. Bundled intelligence is generally solid on endpoint-relevant, commodity threats. Compete on the coverage it doesn't provide — sector actor tracking, brand impersonation, third-party exposure — rather than on quality claims.

What's the fastest way to disqualify a threat intelligence deal?

Ask what the last intelligence report they received actually changed. If nobody can name a decision, detection, or block that resulted, the account has no operationalization capacity and any purchase becomes shelf-ware regardless of vendor.

Should sales engineers run the discovery call instead of the AE?

No — but the SE should be in the room from the first call. The AE owns the commercial thread and the buying committee; the SE owns technical credibility with the CTI Lead. Splitting these across separate calls slows the cycle.

FAQ

How technical does the AE actually need to be?

Fluent enough to use the vocabulary correctly — PIR, IOC, TTP, finished intelligence, confidence rating, attribution — and to know which questions matter. Not fluent enough to debate tradecraft. The failure mode isn't insufficient depth; it's an AE performing depth they don't have in front of a former government analyst who spots it immediately.

What if the customer says their intel team already reads public reporting for free?

That's a fair point and a good sign — it means they have analyst capacity. Reframe around time: how many analyst hours per week go to collection and triage rather than analysis? Commercial intelligence's honest value proposition is usually redirected analyst time and earlier access, not information that's otherwise unobtainable.

Should we lead with the CISO or the practitioners?

Practitioners first, CISO to fund. The SOC Manager and CTI Lead can kill a deal the CISO likes; the reverse is less common. But a deal with practitioner enthusiasm and no executive sponsor stalls at budget. Get technical validation first, then bring the sponsor in with the practitioners' own words.

How do we handle an account mid-contract with an incumbent?

Scope a complementary deployment against coverage the incumbent doesn't provide, prove value on that narrow surface, and be present with usage data when the incumbent's renewal comes up. Attempting mid-term displacement usually fails on procurement grounds regardless of product merit.

What metrics should we write into the kickoff?

Pick metrics tied to workflow, not access: automated enrichment volume, detections created from vendor intelligence, reports cited in internal incident write-ups, and API call trends. Define them in week one with the SOC Manager, and review them monthly. Login counts prove nothing at renewal.

Does this training transfer to adjacent security categories?

Largely yes. Attack surface management, digital risk protection, and vulnerability management share the split-committee structure and the operationalization problem. The transferable core is joint discovery, proving value inside the customer's existing console, and defining renewal telemetry at kickoff rather than at renewal.

Sources

flowchart TD S["Threat Intelligence Selling to the SOC"] S --> N0["The outcome you should expect from thi"] N0 --> N1["What actually drives the outcome"] N1 --> N2["Benchmarks and realistic ranges"] N2 --> N3["Risks, edge cases, and failure modes"]
flowchart LR C["Threat Intelligence Selling to the SOC"] C --> H0["What actually drives the outcome"] C --> H1["Benchmarks and realistic ranges"] C --> H2["Risks, edge cases, and failure modes"] C --> H3["A practical rollout plan for the 60 mi"]

Related on PULSE

Download:
Was this helpful?