← All articles

How to Book Meetings With Heads of Threat Intelligence in B2B (2026)

By Asaf Katz · July 25, 2026

QUICK ANSWER

Heads of Threat Intelligence are among the most difficult senior security buyers to reach in B2B. They are deeply skeptical of vendor outreach, highly networked in the threat intel community, and will only engage with vendors who demonstrate genuine understanding of their operational reality. Cold email does not work. Live events where they learn something specific and peer-validated do.

Heads of Threat Intelligence -- including Director of Threat Intelligence, VP of Threat Research, and Head of CTI (Cyber Threat Intelligence) -- are among the hardest B2B buyer personas to reach with cold outreach. They operate in a specialized community with strong peer networks, attend specific industry events (ISACs, FIRST, CISA briefings), and have finely tuned vendor-pitch radar. The vendors who get meetings with them do so through the community -- not through cold email.

Who Is the Head of Threat Intelligence?

The Head of Threat Intelligence typically:

Company profile: primarily enterprise (5,000+ employees), financial services, critical infrastructure, defense contractors, large technology companies, and government contractors. Mid-market companies rarely have a dedicated Head of Threat Intelligence -- the function rolls up to the CISO or VP Security.

What Does the Head of Threat Intelligence Care About?

The three things that drive a CTI leader's attention and budget:

  1. Intelligence coverage and fidelity: Is your data covering the threat actors, campaigns, and TTPs most relevant to their vertical? Generic "threat data" does not move this buyer; vertical-specific intelligence quality does.
  2. Analyst workflow integration: CTI teams run SOAR platforms, TIP (Threat Intelligence Platforms), and SIEM. A new vendor needs to integrate cleanly into existing workflows -- or have a compelling reason to replace them.
  3. Speed of production: Time from observed threat to actionable intelligence. CTI leaders measure how fast a platform surfaces indicators they have not already seen through other channels.

What Channels Work for Reaching Threat Intelligence Leaders?

What does not work:

What works:

How to Build the Target List for Threat Intelligence Outreach

Use Apollo or LinkedIn Sales Navigator with these filters:

Expect 200-500 named contacts in the US enterprise segment. This is a small, high-value list. Treat each contact as an account, not just a name.

For personalization, use Claude in Clay to research each contact's public threat intelligence work (conference presentations, blog posts, LinkedIn activity) and tailor your event invite to their specific focus area (ransomware, nation-state, supply chain). See how LinkedOtter structures this.

Frequently asked questions

Why is it so hard to book meetings with Heads of Threat Intelligence?

CTI leaders operate within a tight-knit professional community with strong vendor-pitch radar. They are heavily targeted by vendors and have learned to ignore cold outreach. They engage only through their community -- via peer referral, ISAC events, and technical presentations by credible researchers.

What event topics attract Heads of Threat Intelligence to a webinar?

Specific threat actor campaign analysis, TTPs for relevant sectors (financial services, critical infrastructure), threat intelligence platform integration case studies, and ISAC coordination frameworks. Technical content delivered by recognized threat researchers, not vendor representatives.

How do you personalize outreach to a Head of Threat Intelligence?

Research their public work -- conference presentations, blog posts, LinkedIn activity. Reference their specific focus area (ransomware, nation-state actors, supply chain) in the invite. Use Clay and Claude to scale this research across your target list.

Which companies have Heads of Threat Intelligence?

Primarily enterprise companies (5,000+ employees) in financial services, critical infrastructure, defense contracting, large technology companies, and government contractors. Mid-market companies rarely have a dedicated CTI function.

What is the realistic meeting booking rate for Heads of Threat Intelligence through events?

For a well-targeted live event with a credible technical speaker, expect 5-15% of live attendees to take a follow-up meeting. The base rate is lower than other personas, but meeting quality is exceptionally high when it happens.

Should cybersecurity vendors sponsor ISACs to reach CTI leaders?

ISAC participation is one of the most effective channels for reaching CTI leaders authentically. It signals commitment to the community rather than transactional vendor interest. Combined with event-led outbound, it accelerates the trust-building that leads to meetings.

Related

Take the free 60-second check