Industries we've worked with

Outbound for IT services, MSPs and cybersecurity firms.

Companies switch IT providers when something breaks, when they grow past their current one or when a compliance deadline forces the issue. Outbound reaches them at those moments with a reason that's specific to their stack and their situation.

The problem

Why MSPs stall once referrals run out

Most MSPs get their first fifty clients from the owner's network, a few vendor referrals and the accountant down the hall who knew someone whose server died. After that the growth comes from add-ons and per-seat creep at existing accounts, which looks like revenue growth on the P&L but is not new logos. The owner is still the escalation point, the sales engineer and the person who writes the proposals, and the calendar shows it: quarterly business reviews yes, prospecting no.

MSP outbound is the most crowded inbox category there is. Every operations director has seen the email about 24/7 monitoring, the free network assessment and the cyber insurance scare, most of them from a vendor-supplied template with the logo swapped. When outbound is done properly the list is built from the company's actual situation: the IT manager role they cannot fill, the second office they opened, the SOC 2 report a customer has asked for, and the email is about that and nothing else.

Who we reach

The people who say yes.

  • Owners and operations directors at companies with 20 to 500 staff
  • IT managers running a one-person department
  • CFOs and COOs who own the IT budget
  • Compliance and risk leads facing an audit or certification
What we write about

The signals that make it timely.

  • Hiring for an internal IT role
  • New offices, mergers and headcount growth
  • Compliance deadlines such as SOC 2, HIPAA and cyber insurance renewals
  • Public incidents and outages in the sector

MSP outbound is crowded and most of it is generic. Ours names the company's actual situation, the role they're hiring, the office they've opened, the certification they need, which is what gets past an operations director's delete key.

How it works for it services

Five steps, and you're only in the last one.

  1. 1

    List

    We build the list from IT moments, not headcount bands. Open IT postings on job boards, new office announcements, mergers, and the compliance deadlines that show up in public procurement, customer lists and industry press. We take the owner, COO or operations director at companies with 20 to 500 staff, or the lone IT manager for co-managed offers, and exclude anything in your PSA or a partner's account list.

  2. 2

    Research

    Our copywriters read the IT posting line by line, because it lists the stack: Microsoft 365 or Google, Meraki or Fortinet, the line-of-business application, how many sites, whether 'on call' appears. They check how long the role has been open and whether it was reposted, look for a new address on the website, and note whether the company sells into a sector that asks for SOC 2 or CMMC.

  3. 3

    Copy

    The email never mentions 24/7 monitoring, proactive support or a free assessment, because every MSP email says those. It names the role, the stack it describes and what one person covering all of it costs the company, then states plainly what you would take off their plate and what a comparable client pays. Under 120 words, no vendor logos, no ransomware scare, a short call at the end.

  4. 4

    Sending

    We send Tuesday to Thursday mornings in the prospect's time zone. We skip quarter-end, when budgets are locked, and the fortnight around Christmas when the only IT person is on holiday. Lists built on cyber insurance or compliance deadlines go out 60 to 90 days ahead. Every send uses dedicated domains we warm for three to four weeks, never yours, and follow-ups stop on reply.

  5. 5

    Replies

    Operations directors reply with a question: what does this cost for 80 users, or can you look at what we have. Have a per-user range ready. Replies land in the portal as interested, not now and out of office; a not now says after the migration or when the contract ends in March, and we schedule the return. Every two weeks we tilt the list towards the signals converting.

Why that email works

"Your systems administrator posting"

The reposting history is the signal: a role open since May and reposted twice means the company has already tried to hire and failed, so an alternative is welcome rather than insulting. The proof is two comparable clients in the same trade and region, with a concrete service shape. It leaves out monitoring, security acronyms and the MSP's certifications, none of which are what Renata is stuck on.

Who this is for

IT and security firms we write for

Managed service providersOwners and operations directors at companies with 20 to 300 staff, no IT department and an IT posting that has been open for weeks.
Managed security and MDRCompliance and risk leads facing a SOC 2, HIPAA or CMMC deadline, or a cyber insurance renewal that now asks about MFA and EDR.
Cloud and Microsoft 365 specialistsIT managers at companies still on an on-premises Exchange server or a file server, timed to end-of-support dates.
Co-managed ITIn-house IT managers running a one-person department who need help desk cover and escalation, not replacement.
Vertical MSPsHealthcare, legal, financial services, manufacturing and construction, where the email has to speak to the regulator, the line-of-business software and the site.
VoIP, connectivity and infrastructureFacilities and operations leads at companies opening, moving or fitting out a location, written to the go-live date.
Questions we get from this industry

Asked on almost every call.

Every MSP in our area is already cold emailing. Does it still work?

It works because most of that email is the same vendor template about proactive monitoring and a free assessment, sent to every business in the county. An operations director who has been trying to fill a systems administrator role for four months will read an email about that role. Ours are only sent where there is a situation like that to write about.

We are a Microsoft partner and we sell through vendor referrals too. Will this interfere?

No. We exclude your existing accounts and any company your distributor or vendor partner has registered to you or to another partner, if you share that list. The emails are signed by you and mention no vendor by name unless the prospect's own posting does, so co-marketing rules and deal registration stay clean.

Can you time emails to cyber insurance renewals or a compliance deadline?

Yes. Compliance deadlines are visible from outside: a company that announces a defence contract will need CMMC, one selling to SaaS buyers will be asked for a SOC 2, and healthcare clients carry HIPAA already. Cyber insurance renewals are harder to see, so we write to what carriers now require, MFA, EDR and tested backups, and time the sends 60 to 90 days ahead of the January 1 renewal peak.

General questions about pricing, contracts and warm-up →

Other industries

Also built for

See all 15 industries →