September 3, 2026
A quick reminder to enterprise sales and BDR teams: A whitepaper is not an NDA.
Lately, there is a recurring pattern in the IT and cybersecurity space:
By Hemant Bothra
1 min read
- A cold call comes in offering a "valuable industry whitepaper."
- Before sending the document, the representative begins probing:
- "What firewall or endpoint solution are you currently running?"
- "How is your hybrid cloud environment structured?"
- "What are your primary pain points with your existing SIEM?"
- When met with hesitation, the pushback is: "We just need these details to ensure we share the most relevant report with your team."
In cybersecurity, this tactic has a well-known name: Pretexting.
Internal architectural configurations, active vendor stacks, and operational workflows are proprietary, confidential assets. Posing discovery questions under the guise of content distribution is not value-added consulting โ it is aggressive elicitation.
A whitepaper should educate, build trust, and showcase thought leadership on its own merits. If content delivery requires an enterprise to map out its internal security posture over an unsolicited phone call, the transaction is misaligned from the start.
To vendors and OEM representatives: share knowledge openly to earn a conversation. Respect operational boundaries.
To fellow IT and security leaders: keep the guardrails high. Legitimate research never demands your infrastructure blueprints as an entry fee.