Objections Security won't approve it

Security and Compliance Objection: The Script for 'Security Won't Approve It'

How to answer the prospect who expects their security review to kill the deal, with a five-beat script, three openers, the smokescreen test, and a Claude prompt.

The security and compliance objection sounds like a verdict and is almost always a prediction. When a prospect says 'security won't approve it,' they are usually remembering the last vendor review: a 300-question spreadsheet, a six-week wait, and an InfoSec lead who found one missing control and killed the whole thing. They are protecting themselves from repeating that, and protecting you from a process they assume you will fail. Reps respond by reciting certifications, which answers a question nobody asked. The security team is a buyer with a checklist, and the fastest way through is to know what is on it before you get there: the data you touch, where it lives, who at your company can see it, and what happens when they ask you to delete it. The script below turns the prediction into a conversation with the person who will actually run the review. The openers and the smokescreen test tell you when security is the objection and when it is the excuse.

What they usually mean

What "Security won't approve it" is really telling you

Under 'security won't approve it' there are usually two things. The first is process fatigue: the prospect has watched a review take six weeks and does not want to sponsor another one, so the objection is about their calendar and political capital rather than your controls. The second is a specific known blocker: a policy such as no third-party access to the CRM, no data outside a region, or no vendors without a particular attestation, and the prospect knows your product trips it. The mistake reps make is to answer both with a certification list. Attestations do not shorten a review the prospect does not want to run, and they do not fix a policy conflict. The work is to find out which it is, get the review owner in early, and either scope the data footprint down to clear the policy or find out fast that it cannot.

THE SCRIPT

Security and compliance objection script: five beats, spoken

Have your data-flow one-pager ready before this call: what you access, where it is stored, who can see it, retention, and deletion. The ASK depends on being able to send it within the hour.

The script
ACKNOWLEDGE: That is fair, and I would rather hear it now than in week six of a review.

CLARIFY: Can I ask what you expect them to flag? Is it a specific policy, like third-party access to the CRM or data leaving a region, or is it more that the review process itself is a long road you do not want to walk again?

REFRAME: If it is a policy, I want to know today whether we clear it, because if we do not, neither of us should spend another hour on this. If it is the process, the thing that shortens it is going to your security lead with the data-flow answered before they ask: what we read, where it lives, who at our company can see it, how long we keep it, how you delete it.

PROOF: Acme Observe's security lead told our champion the same thing. We sent the one-page data-flow document and our completed questionnaire before the first security call, and the review took nine business days instead of the six weeks their last vendor needed.

ASK: Would you introduce me to whoever runs vendor reviews, and let me send them the one-pager first? If they come back with a hard no, you have your answer in a week instead of a quarter.
Three alternate openers
Direct: 'They might not. What do you think they will flag? If it is a hard policy I want to know now, not in week six.'

Curious: 'What did the last vendor review look like from your seat? I ask because I would rather design around it than repeat it.'

Dry: 'Security teams approve things every week. What they turn down is vendors who show up without the data-flow answered, and that part is on me.'
If it is a smokescreen
The test: ask 'Who runs vendor security reviews here, and can I send them our data-flow document this week?' A real security concern gets you a name and a yes, because the prospect wants the answer too. A smokescreen gets 'let me think about it' or 'I would not want to waste their time,' which means the prospect is the one saying no.

If it is not real, name it gently: 'It sounds like security is one concern and there is another underneath it. What would need to be true for you to want to bring this to them?' Then handle what comes back, and stop talking about controls.

Open with the data you touch and where it lives, never with your certifications; that is the first question on every reviewer's list and the one most vendors cannot answer in a sentence.

Do it with Claude

Rewrite the script for your product and this account

The script assumes you know your own data footprint cold and know nothing about their policy. Usually you can infer a lot about the second from their industry, region, and public security pages. Paste that with the prompt below and let Claude tailor CLARIFY to the policies most likely at this account and draft the data-flow one-pager you promise to send.

Claude prompt
I am handling 'security won't approve it' from {{prospect title}} at {{company}} ({{company URL}}), in {{industry}}, based in {{region}}. My product: {{one-line description}}. Our data footprint: {{what we read, where it is stored, who at our company can access it, retention period, deletion process, attestations we hold}}.

Read their site, security or trust page, and careers page for signals about their security posture and any policies that might conflict with our footprint.

Rewrite the five-beat script below so CLARIFY names the two policies most likely to be the blocker at {{company}}, REFRAME addresses the process-fatigue case in their terms, and PROOF uses: {{customer, review length, what shortened it}}. Under 200 words, spoken. Then draft the one-page data-flow document as a plain list a security reviewer can scan in two minutes. Mark anything inferred, and do not invent attestations I did not list.

SCRIPT:
{{paste the script above}}
Related

Handle any objection with Claude

FAQ

Frequently asked questions

How do you handle the security and compliance objection?

Find out whether it is a policy or a process. Ask what they expect security to flag: a specific rule, such as no third-party CRM access or no data outside a region, or the memory of a six-week review they do not want to sponsor again. A policy conflict needs an answer today, and sometimes the answer is that you do not clear it. Process fatigue is solved by going to the reviewer first with the data-flow answered: what you read, where it lives, who sees it, retention, and deletion. Ask for the introduction and send the one-pager within the hour.

Should you lead with your SOC 2 or ISO certification?

Mention it once, in the data-flow document, and stop. Attestations answer 'has someone audited you,' and the reviewer's first question is 'what do you touch and where does it go,' which most vendors cannot answer in a sentence. A rep who opens with certifications sounds like every other vendor and signals they do not know their own footprint. Lead with the data flow, attach the attestation and the completed questionnaire, and let the reviewer see that you have done their job for them. That is what shortens a review; the badge alone does not.

What if the security team really will not approve it?

Then you want to know in a week, and the script is built to get you there. If the blocker is a hard policy your product cannot clear, say so, ask whether a reduced data scope would change the answer, and if it would not, leave cleanly with a note on what would need to change on your side. A rep who pushes a doomed deal through a six-week review burns the champion who sponsored it. A rep who takes a fast no and leaves a clear document gets called when the policy changes, and policies change more often than people expect.

Want the response drafted for the deal you are in?

The objection handling prompt writes it in your voice with your proof, in one paste.

Get the prompt →