Heads of Threat Intelligence -- including Director of Threat Intelligence, VP of Threat Research, and Head of CTI (Cyber Threat Intelligence) -- are among the hardest B2B buyer personas to reach with cold outreach. They operate in a specialized community with strong peer networks, attend specific industry events (ISACs, FIRST, CISA briefings), and have finely tuned vendor-pitch radar. The vendors who get meetings with them do so through the community -- not through cold email.
Who Is the Head of Threat Intelligence?
The Head of Threat Intelligence typically:
- Manages a team of threat analysts, malware researchers, and CTI specialists
- Consumes threat intelligence from ISACs, government feeds (CISA, FBI), and commercial platforms (Recorded Future, Mandiant, CrowdStrike)
- Evaluates vendors based on intelligence quality and analyst workflow fit, not marketing claims
- Has a very specific skill set and tends to interact primarily within the threat intelligence professional community
- Attends FIRST Conference, ISACs sector meetings, DEF CON, and Black Hat -- but usually the technical tracks, not the vendor expo
Company profile: primarily enterprise (5,000+ employees), financial services, critical infrastructure, defense contractors, large technology companies, and government contractors. Mid-market companies rarely have a dedicated Head of Threat Intelligence -- the function rolls up to the CISO or VP Security.
What Does the Head of Threat Intelligence Care About?
The three things that drive a CTI leader's attention and budget:
- Intelligence coverage and fidelity: Is your data covering the threat actors, campaigns, and TTPs most relevant to their vertical? Generic "threat data" does not move this buyer; vertical-specific intelligence quality does.
- Analyst workflow integration: CTI teams run SOAR platforms, TIP (Threat Intelligence Platforms), and SIEM. A new vendor needs to integrate cleanly into existing workflows -- or have a compelling reason to replace them.
- Speed of production: Time from observed threat to actionable intelligence. CTI leaders measure how fast a platform surfaces indicators they have not already seen through other channels.
What Channels Work for Reaching Threat Intelligence Leaders?
What does not work:
- Generic cold email (ignored)
- LinkedIn automated sequences (blocked or ignored)
- Gated white papers (downloaded by analysts, not leaders)
- Conference sponsor booths (CTI leaders attend technical sessions, not expo floors)
What works:
- Live technical events with real threat researchers presenting: A webinar where a Mandiant, CrowdStrike, or respected independent researcher presents specific campaign analysis is the kind of content a CTI leader will attend. The event host gets brand proximity.
- ISAC participation and sponsorship: CTI leaders actively participate in sector ISACs (FS-ISAC, H-ISAC, E-ISAC). Sponsorship or speaker placement in ISAC-adjacent events reaches this community authentically.
- Peer referral from a known researcher: One warm introduction from a respected threat researcher is worth 100 cold emails. Building relationships with recognized community members (who then introduce you) is a long-term investment that pays out in CISO and CTI meetings.
- Event-led outbound with technical speaker: LinkedOtter runs live events with technical cybersecurity practitioners as speakers. For threat intelligence audiences, the speaker must be a recognized researcher -- not a vendor representative. This is non-negotiable.
How to Build the Target List for Threat Intelligence Outreach
Use Apollo or LinkedIn Sales Navigator with these filters:
- Job title: "Head of Threat Intelligence," "Director of CTI," "VP Threat Intelligence," "Threat Intelligence Lead"
- Company: 1,000+ employees, industries: financial services, critical infrastructure, defense, large tech
- Geography: US-headquartered (for US-focused programs)
- Additional signal: company member of sector ISAC
Expect 200-500 named contacts in the US enterprise segment. This is a small, high-value list. Treat each contact as an account, not just a name.
For personalization, use Claude in Clay to research each contact's public threat intelligence work (conference presentations, blog posts, LinkedIn activity) and tailor your event invite to their specific focus area (ransomware, nation-state, supply chain). See how LinkedOtter structures this.