How should a security company run account-based marketing and outbound email in Canada?
Security purchases involve several people at each account, and Canada's anti-spam law limits who you can email and when. This page shows how to pick accounts, map the roles inside them, stay inside CASL and build a touch plan that gives each person something useful.
How should a security company run ABM and outbound email in Canada?
Agree a short list of accounts with sales, map the buying roles inside each, reach those roles through paid social, events, direct mail and content, and send commercial email only where you have consent or a clear CASL exemption. Measure progress by account, not by lead.
In practice, consent-safe email comes after other touches have created a reason to talk, such as an event conversation, a downloaded report or a form submission.
The general ABM method is in account-based marketing. The security version differs because the committee is technical, sceptical and wary of unsolicited contact, which is unsurprising for people who triage phishing all day.
How do you choose target accounts and map the roles inside them?
Choose accounts by fit and by trigger. Fit covers size, sector, technology stack and region. Triggers are events that make a purchase likely now: a new security leader, a compliance deadline, an acquisition, a public incident in their sector or a move to a new cloud platform.
The committee shape and the evidence each role needs is covered in how security buyers buy. Six roles is a planning template, not a verified average.
What does CASL allow for B2B cold email?
Less than many sales teams assume. The CRTC's CASL guidance sets out the consent types and exemptions that matter for B2B security outreach.
| Basis | What the CRTC says | Practical meaning |
|---|---|---|
| Express consent | Does not expire, but can be withdrawn | Best basis; record when and how it was given |
| Implied: purchase | Two years after a purchase | Customers can be emailed about relevant offers |
| Implied: inquiry | Six months after an inquiry or application | Follow up promptly, then ask for express consent |
| Conspicuous publication | A higher standard than simple public availability; message must relate to the person's business role | A CISO's published address can support a relevant message, not any message |
| B2B exemption | Between employees of two organizations that have a relationship, about the recipient's activities | A personal connection between two employees is not enough |
- Unsubscribe requests must be processed without delay and within 10 business days.
- The unsubscribe mechanism must work for at least 60 days after sending.
- Maximum administrative penalties per violation are $1 million for individuals and $10 million for businesses.
This is general information, not legal advice; check with counsel.
How do you collect consent without slowing the program?
Build consent into every useful offer. Event registrations, research downloads, briefing requests and assessment sign-ups can each include a clear, unticked opt-in for related emails.
LinkedIn's Lead Gen Forms open inside LinkedIn and are pre-filled from the member's profile with details such as name, contact information, company, seniority, job title and location. They are available for Sponsored Content and Message Ads, and leads can be downloaded from Campaign Manager or synced to a CRM. LinkedIn says 90% of its pilot customers beat their cost-per-lead goals, a vendor claim from an early pilot. Add your own consent wording to the form; pre-filled data is not the same as consent to email.
Physical channels do not fall under CASL in the same way. Addressed mail to named accounts is covered in direct mail for security companies, and in-person conversations in security events. Both create a natural moment to ask whether someone would like follow-up by email.
Every touch must be useful to the role that receives it.
The security engineer gets the detection write-up, the CISO the board-level summary, procurement the trust centre link. Sending everyone the same demo request is how accounts go cold.
What does a role-based touch plan look like?
A sequence across channels where each step gives a specific role something useful, and email starts only once there is consent or a valid exemption.
| Week | Role | Touch | Channel | Consent basis |
|---|---|---|---|---|
| 1 | Security engineer | Detection write-up | LinkedIn Thought Leader Ad | Not needed (ad) |
| 2 | CISO | Findings summary | LinkedIn Document Ad | Not needed (ad) |
| 3 | CISO | Incident checklist card | Addressed mail | Not CASL (paper) |
| 4 | Security engineer | Invite to technical briefing | Conversation Ad with Lead Gen Form | Express opt-in on form |
| 5 | Engineer who opted in | Briefing recording and docs | Express consent | |
| 6 to 8 | IT director, procurement | Rollout plan, trust centre link | Sales outreach via champion | Consent or a valid exemption |
How to run the paid steps is on LinkedIn Ads for security companies.
What should a security company measure in ABM?
Measure accounts, not leads. A single engaged account with three roles involved is worth more than forty form fills from people who will never buy.
| Metric | What it shows |
|---|---|
| Target accounts with two or more roles engaged | Committee coverage |
| Accounts with a meeting held | Sales conversations started |
| Opportunities created from target accounts | Pipeline from the list |
| Email contacts with a recorded consent basis | CASL hygiene |
| Unsubscribes processed within 10 business days | CASL compliance |
- Mistake: a list too long to personalize. If sales cannot name why an account is on it, remove it.
- Mistake: one contact per account. Single-threaded deals stall when that person is busy or leaves.
- Mistake: treating consent as a one-off. Implied consent from an inquiry lapses after six months; ask for express consent before then.
Frequently asked questions
Can we cold email CISOs in Canada?
Only with consent or a valid CASL exemption. A published business address can support a message relevant to the person's role, but a scraped list alone does not make cold email compliant. This is general information, not legal advice.
Do LinkedIn sponsored posts need CASL consent?
Feed ads shown on a platform are not emails to an address you hold. Direct messages are a different question, so check with counsel before running cold message campaigns on any platform.
How long does implied consent last under CASL?
The CRTC lists two years after a purchase and six months after an inquiry or application. Express consent does not expire but can be withdrawn.
What is the B2B exemption under CASL?
It covers messages between employees of two organizations that have a relationship, about the recipient organization's activities. A personal link between two employees is not enough.
How many accounts should a security ABM program target?
As many as sales can work with personal attention. For many smaller security companies that is dozens, not thousands.
How fast must we process an unsubscribe?
Without delay and within 10 business days, and the unsubscribe mechanism must keep working for at least 60 days after the message is sent.
Do LinkedIn Lead Gen Forms give us consent to email?
Not automatically. The form collects profile data; add clear consent wording for the emails you plan to send and record it.
Which roles should ABM reach at a security buyer?
Usually the security lead, security engineers, IT operations, privacy or legal, procurement and finance. Each needs different material.
Sources & further reading
Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.