Sales · cybersec · NordicsJul 20269 min read342 words

Discovery calls for startups under 20 people for cybersecurity in the Nordics

How under-20-person startups get discovery calls live without hiring — the specific version of the playbook designed for constraint. Written for CISOs, VPs of security, and heads of GRC in the Nordics.

This edition of the Growth Broker playbook is written for CISOs, VPs of security, and heads of GRC operating in the Nordics. In this market, Nordic buyers reward directness, small buying committees, and a track record over a pitch, so the way you install discovery calls has to be shaped to that reality from day one.

The under-20-person version of discovery calls is not a diluted enterprise playbook. It is the 30 minutes that decide whether a deal exists at all with different constraints: no headcount, no politics, and no time to be wrong for long.

Own it personally as a founder or lean-in operator for the first quarter. Hiring a specialist too early replaces context with process.

Pick one channel, one trigger, one message. Two of anything at this stage is too many and none of them will work.

Inside cybersecurity, the binding constraint is almost always credibility and trust, not tooling, and in the Nordics it is compounded by the fact that reputation compounding, not campaign spend is what actually gates growth. Discovery calls is only useful here when it is pointed at both constraints at once.

Instrument discovery-to-opportunity conversion in a spreadsheet if you have to. Legibility beats sophistication under 20 people.

The startup-specific trap is reading a script instead of running a diagnosis, usually because a well-meaning advisor points at what worked at their $50m company. Ignore.

Budget rules: whatever you spend on tools, spend the same on the person operating them. Under-tooling is fine; under-humaning is not.

A working discovery calls function at 15 people is a genuine moat — most competitors of that size do not have one, and the discipline carries forward as the company grows.

Concretely for cybersecurity in the Nordics: the difference between a real security opportunity and a wasted quarter is one credible sentence, and the Nordic teams that install this compound reputation faster than any paid channel could. That is the reason it is worth installing discovery calls deliberately for this market rather than importing a playbook designed for somewhere else.

discovery callssales discoveryMEDDICstartup discovery callsdiscovery calls for early stagediscovery calls for cybersecuritydiscovery calls in the Nordicscybersecurity growth in the Nordics

Frequently asked questions

Sales · cybersec · Nordics — answered

Does discovery calls work for cybersecurity in the Nordics?
Yes — provided it is pointed at credibility and trust, not tooling and adapted to the fact that in the Nordics, Nordic buyers reward directness, small buying committees, and a track record over a pitch. The difference between a real security opportunity and a wasted quarter is one credible sentence.
Can a five-person team run discovery calls?
Yes, if the founder owns it. The lower headcount, the more concentrated the ownership.
What is the smallest useful discovery calls setup?
One channel, one trigger, one message, and a spreadsheet tracking discovery-to-opportunity conversion.
Should we hire a specialist for discovery calls?
Not in the first quarter. Own it personally until the model is proven.
What common advice should startups ignore?
Anything derived from a company more than 10x larger. Constraints differ.
What is the Nordics-specific pitfall when running discovery calls for cybersec?
Importing a playbook that was built for another market. In the Nordics, Nordic buyers reward directness, small buying committees, and a track record over a pitch — the install has to reflect that.

Growth Broker editorial

Filed under sales · cybersec · nordics

Up next

AI for Growth: the complete 2026 guide for B2B companies

Read piece

Ready to broker your growth?

Book a Growth Call