Channels · Outbound

How should a security company run account-based marketing and outbound email in Canada?

Security purchases involve several people at each account, and Canada's anti-spam law limits who you can email and when. This page shows how to pick accounts, map the roles inside them, stay inside CASL and build a touch plan that gives each person something useful.

By the ShoutEx Team · Updated October 2026 · Facts checked October 7, 2026
In security ABM, the list is the strategy. Fewer accounts, more roles per account, and consent before every commercial email.Marketing for Cybersecurity Companies · Updated October 2026
$10M
Maximum CASL administrative penalty per violation for a business
10 days
Business days to process an unsubscribe request, at most
6 months
Implied consent period after an inquiry or application under CASL

How should a security company run ABM and outbound email in Canada?

How should a security company run account-based marketing and outbound email in Canada?

Agree a short list of accounts with sales, map the buying roles inside each, reach those roles through paid social, events, direct mail and content, and send commercial email only where you have consent or a clear CASL exemption. Measure progress by account, not by lead.

In practice, consent-safe email comes after other touches have created a reason to talk, such as an event conversation, a downloaded report or a form submission.

The general ABM method is in account-based marketing. The security version differs because the committee is technical, sceptical and wary of unsolicited contact, which is unsurprising for people who triage phishing all day.

How do you choose target accounts and map the roles inside them?

Choose accounts by fit and by trigger. Fit covers size, sector, technology stack and region. Triggers are events that make a purchase likely now: a new security leader, a compliance deadline, an acquisition, a public incident in their sector or a move to a new cloud platform.

Account map: who to reach at each target account
1Security lead or CISO
Worries aboutRisk reduced per dollar and per analyst hour
Needs from youShort business case, peer references
2Security engineer
Worries aboutDeployment effort, detection quality, false positives
Needs from youDocs, test access, technical session
3IT director
Worries aboutAgents, performance, change windows
Needs from youDeployment guide, rollout plan
4Privacy or legal
Worries aboutData handling, contracts, cross-border transfer
Needs from youDPA, subprocessor list, trust centre
5Procurement
Worries aboutVendor risk review, terms, payment route
Needs from youCompleted questionnaire, standard terms
6Finance
Worries aboutTotal cost and how it grows
Needs from youPricing logic, multi-year options

The committee shape and the evidence each role needs is covered in how security buyers buy. Six roles is a planning template, not a verified average.

What does CASL allow for B2B cold email?

Less than many sales teams assume. The CRTC's CASL guidance sets out the consent types and exemptions that matter for B2B security outreach.

BasisWhat the CRTC saysPractical meaning
Express consentDoes not expire, but can be withdrawnBest basis; record when and how it was given
Implied: purchaseTwo years after a purchaseCustomers can be emailed about relevant offers
Implied: inquirySix months after an inquiry or applicationFollow up promptly, then ask for express consent
Conspicuous publicationA higher standard than simple public availability; message must relate to the person's business roleA CISO's published address can support a relevant message, not any message
B2B exemptionBetween employees of two organizations that have a relationship, about the recipient's activitiesA personal connection between two employees is not enough
  • Unsubscribe requests must be processed without delay and within 10 business days.
  • The unsubscribe mechanism must work for at least 60 days after sending.
  • Maximum administrative penalties per violation are $1 million for individuals and $10 million for businesses.

This is general information, not legal advice; check with counsel.

ShoutEx rule

Every touch must be useful to the role that receives it.

The security engineer gets the detection write-up, the CISO the board-level summary, procurement the trust centre link. Sending everyone the same demo request is how accounts go cold.

What does a role-based touch plan look like?

A sequence across channels where each step gives a specific role something useful, and email starts only once there is consent or a valid exemption.

Eight-week touch plan for one target accountSignalpine, a fictional email security vendor
WeekRoleTouchChannelConsent basis
1Security engineerDetection write-upLinkedIn Thought Leader AdNot needed (ad)
2CISOFindings summaryLinkedIn Document AdNot needed (ad)
3CISOIncident checklist cardAddressed mailNot CASL (paper)
4Security engineerInvite to technical briefingConversation Ad with Lead Gen FormExpress opt-in on form
5Engineer who opted inBriefing recording and docsEmailExpress consent
6 to 8IT director, procurementRollout plan, trust centre linkSales outreach via championConsent or a valid exemption
Source: Illustrative example written by ShoutEx for this guide, not a benchmark.

How to run the paid steps is on LinkedIn Ads for security companies.

What should a security company measure in ABM?

Measure accounts, not leads. A single engaged account with three roles involved is worth more than forty form fills from people who will never buy.

ABM metrics for security companiesReview monthly with sales
MetricWhat it shows
Target accounts with two or more roles engagedCommittee coverage
Accounts with a meeting heldSales conversations started
Opportunities created from target accountsPipeline from the list
Email contacts with a recorded consent basisCASL hygiene
Unsubscribes processed within 10 business daysCASL compliance
Source: ShoutEx ABM measurement set.
  • Mistake: a list too long to personalize. If sales cannot name why an account is on it, remove it.
  • Mistake: one contact per account. Single-threaded deals stall when that person is busy or leaves.
  • Mistake: treating consent as a one-off. Implied consent from an inquiry lapses after six months; ask for express consent before then.

Frequently asked questions

Can we cold email CISOs in Canada?

Only with consent or a valid CASL exemption. A published business address can support a message relevant to the person's role, but a scraped list alone does not make cold email compliant. This is general information, not legal advice.

Do LinkedIn sponsored posts need CASL consent?

Feed ads shown on a platform are not emails to an address you hold. Direct messages are a different question, so check with counsel before running cold message campaigns on any platform.

How long does implied consent last under CASL?

The CRTC lists two years after a purchase and six months after an inquiry or application. Express consent does not expire but can be withdrawn.

What is the B2B exemption under CASL?

It covers messages between employees of two organizations that have a relationship, about the recipient organization's activities. A personal link between two employees is not enough.

How many accounts should a security ABM program target?

As many as sales can work with personal attention. For many smaller security companies that is dozens, not thousands.

How fast must we process an unsubscribe?

Without delay and within 10 business days, and the unsubscribe mechanism must keep working for at least 60 days after the message is sent.

Do LinkedIn Lead Gen Forms give us consent to email?

Not automatically. The form collects profile data; add clear consent wording for the emails you plan to send and record it.

Which roles should ABM reach at a security buyer?

Usually the security lead, security engineers, IT operations, privacy or legal, procurement and finance. Each needs different material.

Sources & further reading

Regulations, platform policies and market data change. These sources let you check the facts on this page, last checked October 7, 2026.