Handling objections about security spend
For account managers, account executives, customer success managers and MSP service leads who propose security services to business owners and leaders. Complete 'Objections beyond price: status quo, risk, timing, authority and competitors' first; it covers the general routine for any objection. This course is about one hard case: the customer who says security costs too much, isn't needed, or can wait. You'll uncover what the customer actually depends on, tie each measure to the risk it reduces, make only claims you can support, offer a phased plan starting with baseline controls, and record an informed decision when the customer says no. It draws on the UK NCSC's Cyber Security Toolkit for Boards and the Cyber Governance Code of Practice, CISA's Cyber Essentials for leaders, and the US FTC's advertising substantiation policy. Your company's approved claims, pricing authority and proposal rules apply on the job.
- Level
- Intermediate
- Length
- About 92 minutes
- Contents
- 5 lessons · final exam
- Status
- Published · updated 10 Oct 2026
Skills you'll practise
- Identify what lies behind a security spend objection by asking about the customer's objectives, critical assets and risks
- Link each proposed security measure to the specific risk it reduces and the business asset it protects
- Choose honest, supportable claims and avoid fear-based or guaranteed-outcome language
- Offer a prioritised, phased plan that starts with baseline controls when budget is the constraint
- Record a customer's informed decision to accept a security risk, with who decided and when it will be reviewed
Course outline
- 1.Identifying what lies behind a security spend objectionLesson · 16 min
- 2.Linking each security measure to the risk it reduces and the asset it protectsLesson · 16 min
- 3.Choosing honest, supportable claims instead of fear or guaranteesLesson · 16 min
- 4.Offering a prioritised, phased plan that starts with baseline controlsLesson · 14 min
- 5.Recording a customer's informed decision to accept a security riskLesson · 14 min
- 6.Handling objections about security spend: knowledge checkKnowledge check · 14 questions
- 7.Handling objections about security spend: practical exerciseKnowledge check · 1 question
- 8.Final exam10 questions · passing it completes the course, so people who already know the material can test out
Sources it draws on
The lessons and questions are written from these references, so learners can go back to the original.
- NCSC Cyber Security Toolkit for Boards: Introducing the toolkit
- NCSC Cyber Security Toolkit for Boards: Risk management for cyber security
- NCSC Cyber Security Toolkit for Boards: Identifying the critical assets in your organisation
- NCSC Cyber Security Toolkit for Boards: Implementing effective cyber security measures
- GOV.UK: Cyber Governance Code of Practice (DSIT, NCSC)
- CISA: Cyber Essentials (guide for leaders of small businesses and small and local government agencies)
- FTC Policy Statement Regarding Advertising Substantiation
See it with your own jobs and topics
Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.