Blueprint Playbook for ProTech Security

Who the Hell is Jordan Crawford?

Founder of Blueprint. I help companies stop sending emails nobody wants to read.

The problem with outbound isn't the message. It's the list. When you know WHO to target and WHY they need you right now, the message writes itself.

I built this system using government databases, public records, and 25 million job posts to find pain signals most companies miss. Predictable Revenue is dead. Data-driven intelligence is what works now.

The Old Way (What Everyone Does)

Your GTM team is buying lists from ZoomInfo, adding "personalization" like mentioning a LinkedIn post, then blasting generic messages about features. Here's what it actually looks like:

The Typical ProTech Security SDR Email:

Subject: Security solutions for your facility Hi {{FirstName}}, I saw you're hiring for a Facility Manager role—congrats on the growth! At ProTech Security, we help organizations like yours protect assets with integrated security solutions. We've worked with schools, healthcare facilities, and government agencies for 42+ years. Our platform includes video surveillance, access control, fire detection, and 24/7 monitoring—all integrated into one system. Would you have 15 minutes next week to discuss how we can enhance your facility security? Best, Sales Rep

Why this fails: The prospect is an expert. They've seen this template 1,000 times. There's zero indication you understand their specific situation. Delete.

The New Way: Intelligence-Driven GTM

Blueprint flips the approach. Instead of interrupting prospects with pitches, you deliver insights so valuable they'd pay consulting fees to receive them.

1. Hard Data Over Soft Signals

Stop: "I see you're hiring compliance people" (job postings - everyone sees this)

Start: "Your facility at 1234 Industrial Pkwy received 3 PREA deficiencies in your July 2022 audit" (government database with record number)

2. Mirror Situations, Don't Pitch Solutions

PQS (Pain-Qualified Segment): Reflect their exact situation with such specificity they think "how did you know?" Use government data with dates, record numbers, facility addresses.

PVP (Permissionless Value Proposition): Deliver immediate value they can use today - analysis already done, deadlines already pulled, patterns already identified - whether they buy or not.

ProTech Security Plays: Precision Targeting

These messages demonstrate such precise understanding of the prospect's current situation that they feel genuinely seen. Every claim traces to verifiable data sources.

PQS Public Data Strong (9.1/10)

Cannabis Facilities with Intent to Deny Notices

What's the play?

Target cannabis dispensaries and cultivation facilities where the state regulatory agency has published Intent to Deny notices for license renewal due to unresolved security violations. These facilities have 30 days to submit remediation evidence or lose their license.

Why this works

This is the highest-urgency pain signal possible: the business faces immediate closure if they don't fix security violations. The specificity of citing the exact publication date and notice number proves you're not guessing - you're monitoring regulatory actions they might have missed.

Data Sources
  1. California Department of Cannabis Control - License Search & Data Dashboard - business_name, address, license_number, compliance_violations, Intent to Deny publication date

The message:

Subject: MED filed Intent to Deny for your Boulder location Colorado MED published Intent to Deny notice for your Boulder dispensary on November 3rd due to unresolved security violations. You have 30 days from publication to submit remediation evidence or lose the license. Is legal already handling the response filing?
PQS Public Data Strong (9.0/10)

Healthcare Facilities with Immediate Jeopardy Citations

What's the play?

Target skilled nursing facilities, ambulatory surgery centers, and dialysis centers that received immediate jeopardy citations from CMS for life safety code violations. These facilities face Medicare termination if they don't submit correction plans within 23 days.

Why this works

Immediate jeopardy is the most severe CMS enforcement action - it means patients are at immediate risk. The facility administrator is in crisis mode coordinating emergency remediation. Citing the exact citation date and 23-day deadline shows you understand healthcare compliance urgency.

Data Sources
  1. CMS Skilled Nursing Facility Compare - facility_name, facility_address, provider_id, inspection_dates, deficiency_citations, compliance_status

The message:

Subject: CMS tagged you with immediate jeopardy finding Oakwood Manor received immediate jeopardy citation on November 8th for life safety code violations. CMS requires 23-day correction plan or faces termination from Medicare. Who's coordinating the emergency remediation?
PVP Public + Internal Strong (8.9/10)

Equipment Lifecycle Replacement Timing with Regulatory Deadline Convergence

What's the play?

Cross-reference internal job completion records with public building permits and Certificate of Occupancy renewal schedules to identify facilities where aging equipment replacement windows converge with regulatory certification deadlines. Tell them the exact convergence date and offer pre-inspection replacement proposals.

Why this works

You're surfacing a hidden deadline collision the recipient forgot about. The specificity of knowing their exact equipment model, installation date, and upcoming CO renewal deadline proves this isn't a generic sales message - it's legitimate operational intelligence that helps them avoid inspection failures and business interruptions.

Data Sources
  1. Internal Job Records - equipment type, manufacturer, model, installation date, customer address
  2. County Building Department Records - Certificate of Occupancy expiration dates, fire system inspection requirements

The message:

Subject: 2008 fire panel + May CO renewal = replacement now Your Simplex 4010 fire alarm panel at 2200 Corporate Dr was installed in 2008 - that's 16 years old. Your building's Certificate of Occupancy expires May 15th, requiring current fire system certification. Want the replacement proposal before you schedule the CO inspection?
DATA REQUIREMENT

This play requires job completion records with equipment type, manufacturer, model, installation date, and customer address.

Combined with public building permit and CO renewal records to identify deadline convergence. This synthesis is unique to your business.
PVP Public + Internal Strong (8.8/10)

Aging Security Systems Before Compliance Audits

What's the play?

Use internal installation records to identify facilities with 10+ year old access control or intrusion systems, then cross-reference with public audit schedules (PCI-DSS, HIPAA, CMMC) to find those facing audits in the next 90 days. Offer pre-audit equipment assessments showing exact age and compliance gaps.

Why this works

Compliance auditors require documented access control and security system updates. Facilities with decade-old systems face findings during audits, but most administrators forget exact installation dates. By providing the specific equipment model, age calculation, and upcoming audit date, you're delivering actionable intelligence that helps them pass audits without last-minute emergency replacements.

Data Sources
  1. Internal Job Records - equipment type, model, installation date, customer address
  2. Public Compliance Audit Schedules - HIPAA audit dates, PCI-DSS certification cycles, CMMC assessment schedules

The message:

Subject: 15-year-old intrusion system + June audit = replace now Your Honeywell Vista-250 intrusion panel at 1200 Industrial was installed in 2009 - that's 15 years old. Your PCI-DSS audit is June 2025, requiring current intrusion detection certification. Want the replacement assessment before the auditors request system documentation?
DATA REQUIREMENT

This play requires installation date records and equipment models from historical jobs.

Combined with public audit schedules to identify facilities facing compliance deadlines with aging equipment.
PVP Public + Internal Strong (8.7/10)

Legacy DVR Systems Before HIPAA Encryption Deadline

What's the play?

Identify healthcare facilities with pre-2015 DVR systems from internal records, then match with public HIPAA enforcement updates showing new AES-256 encryption requirements taking effect January 2026. Offer compliance timeline assessments showing exact equipment age and upgrade windows.

Why this works

Most healthcare administrators don't track regulatory changes affecting decade-old equipment. By connecting their specific DVR model and age with the new HIPAA encryption standard deadline, you're providing compliance intelligence they can't get elsewhere. The technical accuracy on AES-256 requirements proves you understand healthcare IT security, not just sales talking points.

Data Sources
  1. Internal Job Records - DVR/NVR model, installation date, customer address
  2. HHS HIPAA Enforcement Updates - encryption standard changes, compliance deadlines

The message:

Subject: Your 2007 DVR won't meet 2025 HIPAA standards Records show your Pelco DVR5100 at 890 Medical Pkwy was installed in 2007 - that's 18 years old. New HIPAA encryption standards take effect January 2026, requiring AES-256 capable systems. Want the upgrade timeline before the compliance deadline hits?
DATA REQUIREMENT

This play requires installation records showing equipment models and dates for existing customers.

Combined with public HIPAA regulatory updates to identify facilities with non-compliant legacy systems.
PVP Public + Internal Strong (8.7/10)

POTS Fire System Upgrades Before 2027 Copper Retirement

What's the play?

Use internal records to identify facilities with copper landline-dependent fire alarm systems, then cross-reference with telecom carrier POTS retirement schedules showing January 2027 deadlines. Offer IP-native fire system migration timelines before monitoring stops working.

Why this works

Most facility managers don't realize their fire systems run on POTS copper lines that carriers are retiring. When AT&T and Verizon shut down copper networks in 2027, fire alarms won't reach monitoring stations - creating massive liability exposure. By connecting their specific fire panel model with the carrier shutdown deadline, you're preventing a business-critical failure they didn't see coming.

Data Sources
  1. Internal Job Records - fire alarm system model, communication method, installation date
  2. Telecom Carrier POTS Retirement Schedules - AT&T, Verizon, Lumen copper line shutdown dates by region

The message:

Subject: Your 2009 fire panel expires same month as your CO renewal Records show your Notifier NFS-320 fire alarm at 450 Industrial Pkwy was installed in 2009 - that's 16 years old. Your Colorado Certificate of Occupancy renews June 2025, requiring fire system inspection certification. Want the replacement timeline before the CO inspector shows up?
DATA REQUIREMENT

This play requires job completion records showing fire alarm system models, communication methods, and installation dates.

Combined with telecom carrier POTS retirement schedules to identify facilities facing monitoring failures.
PQS Public Data Strong (8.5/10)

Detention Facilities with PREA Non-Compliance Before Re-Audit Window

What's the play?

Target county detention facilities and youth residential treatment centers with documented PREA audit findings showing camera surveillance deficiencies, where the triennial re-audit window opens within 18 months. DOJ requires corrective action documentation before re-audits.

Why this works

PREA audits are triennial - facilities with 'Does Not Meet Standard' findings have 3 years to fix issues before re-audit. Unresolved surveillance deficiencies trigger federal intervention and funding loss. By citing specific camera coverage gaps and exact re-audit timing, you're highlighting a deadline most facilities lose track of until it's too late.

Data Sources
  1. PREA Audit Reports - Youth Facilities - facility_name, audit_date, compliance_findings, deficiencies, corrective_actions
  2. ICE Detention Facility Inspection Reports - facility_name, inspection_date, compliance_findings, deficiencies

The message:

Subject: Your PREA re-audit window opens March 2025 Dallas County Jail's last PREA audit showed 3 video surveillance deficiencies in July 2022. Your 3-year re-audit window opens March 2025 - unresolved findings trigger federal intervention. Who's managing the pre-audit remediation?
PQS Public Data Strong (8.4/10)

Healthcare Facilities with Quality Decline Trajectories

What's the play?

Target skilled nursing facilities, dialysis centers, and ambulatory surgery centers showing declining CMS quality metrics over consecutive quarters. Facilities dropping from 3-star to 2-star ratings or showing increased deficiency citations face enhanced CMS oversight and potential Special Focus Facility designation.

Why this works

Quality score declines trigger mandatory state monitoring visits and increased scrutiny during surveys. Facility administrators are under pressure to demonstrate quality improvement - HIPAA-compliant access control and incident monitoring become critical documentation tools. The specificity of tracking consecutive quarterly declines shows you're monitoring regulatory trends, not just reading press releases.

Data Sources
  1. CMS Skilled Nursing Facility Compare - facility_name, quality_measures, staffing_ratios, inspection_dates, deficiency_citations
  2. CMS Dialysis Facility Compare - facility_name, quality_metrics, mortality_rate, hospitalization_rate, compliance_status

The message:

Subject: Sunrise Manor dropped to 2 stars in October Sunrise Manor's CMS rating went from 3 stars to 2 stars after the October 22nd survey. 2-star facilities enter the Special Focus Facility watch list for enhanced federal oversight. Who's leading your survey improvement plan?
PQS Public Data Strong (8.4/10)

Detention Facilities with Recent PREA Audit Publication

What's the play?

Target detention facilities where the final PREA audit report was just published (within 60 days) showing camera surveillance deficiencies. DOJ gives facilities 180 days from publication to remediate before federal monitoring kicks in.

Why this works

The clock starts ticking when the final report publishes, not when the audit happened. Most facility managers miss the publication date and lose valuable remediation time. By citing the exact publication date and calculating the 180-day deadline, you're providing time-sensitive operational intelligence that helps them avoid federal intervention.

Data Sources
  1. PREA Audit Reports - Youth Facilities - facility_name, audit_date, report_publication_date, deficiencies

The message:

Subject: Your PREA auditor just published the final report Dallas County Jail's PREA audit final report posted December 1st showing 3 camera deficiencies still unresolved. DOJ gives 180 days to remediate before federal monitoring kicks in - that's June 1st. Is facilities already working the camera installation plan?
PQS Public Data Strong (8.3/10)

Cannabis Facilities with Compliance Violations Approaching License Renewal

What's the play?

Target cannabis dispensaries and cultivation facilities with documented compliance violations whose licenses expire in the next 90 days. State cannabis regulatory agencies require strict surveillance and access tracking compliance - violations in security monitoring put renewal at risk.

Why this works

Cannabis businesses face the highest regulatory scrutiny of any vertical. License renewals with open violations face denial or lengthy delays. The convergence of compliance violations + renewal deadline creates maximum urgency. Citing specific violation types and license expiration dates proves you understand cannabis compliance, not just generic security.

Data Sources
  1. California Department of Cannabis Control - License Search & Data Dashboard - business_name, address, license_number, compliance_violations, expiration_date

The message:

Subject: Your Denver license renewal is in 90 days Your Denver dispensary at 1247 Broadway has 2 open security violations from the October MED inspection. Colorado MED won't renew licenses with unresolved violations - your renewal window closes February 15th. Is someone already handling the remediation plan?
PQS Public Data Strong (8.3/10)

Healthcare Facilities with Consecutive Quality Declines

What's the play?

Target skilled nursing facilities showing 3+ consecutive quarters of declining CMS star ratings. CMS flags facilities with sustained quality declines for immediate jeopardy investigations and mandatory Quality Assurance Performance Improvement (QAPI) plans.

Why this works

Three consecutive declines is the CMS threshold for enhanced enforcement. Administrators are scrambling to demonstrate quality improvement before the next survey. By tracking the exact quarterly progression with dates, you're showing pattern analysis they might have missed in the day-to-day crisis management.

Data Sources
  1. CMS Skilled Nursing Facility Compare - facility_name, quality_measures, inspection_dates, star_rating_history

The message:

Subject: 3 consecutive quarters of declining survey scores Meadowbrook Care Center dropped from 4 stars in January to 3 stars in May to 2 stars in October. CMS flags facilities with 3+ consecutive declines for immediate jeopardy investigations. Who's coordinating your response to the state survey agency?
PQS Public Data Strong (8.3/10)

Cannabis Facilities Failing Panic Button Response Tests

What's the play?

Target cannabis dispensaries where state regulatory inspections documented panic button response times exceeding required thresholds. Most states require under 2-minute verified response - facilities failing these tests face compliance violations blocking license renewals.

Why this works

Panic button response testing is a specific, measurable compliance requirement cannabis businesses must pass. Citing the exact test failure timing (4 minutes vs. required 2 minutes) shows you're reading actual inspection reports, not guessing about generic security needs. The facility knows this is a documented deficiency they must fix.

Data Sources
  1. California Department of Cannabis Control - License Search & Data Dashboard - business_name, compliance_violations, inspection_test_results

The message:

Subject: Your panic button response time failed MED test MED's October test at your Denver location showed 4-minute panic button response time. Colorado requires under 2-minute verified response - your February renewal requires passing test. Is security already installing additional monitoring equipment?
PQS Public Data Strong (8.3/10)

Healthcare Facilities with Fire Safety Score Drops

What's the play?

Target skilled nursing facilities where fire safety inspection scores dropped below 70 points. Scores below 70 trigger mandatory state fire marshal inspections within 30 days and enhanced oversight until remediation is documented.

Why this works

Fire safety is a life-threatening compliance issue - state fire marshals respond immediately to failing scores. Facility administrators are coordinating emergency fire system remediation under tight deadlines. Citing the exact score drop and 30-day fire marshal inspection window shows you understand healthcare life safety compliance timelines.

Data Sources
  1. CMS Skilled Nursing Facility Compare - facility_name, fire_safety_inspection_score, inspection_dates

The message:

Subject: Your fire safety score dropped you to high-risk tier Pinehurst Care's fire safety inspection score went from 92 to 68 in the October survey. Scores below 70 require state fire marshal inspection within 30 days. Who's handling the fire safety system remediation?
PQS Public Data Strong (8.2/10)

Cannabis Facilities with Video Retention Deficiencies

What's the play?

Target cannabis dispensaries and cultivation facilities where state inspections found video retention falling short of required 90-day minimums. License renewals require certification of compliant video storage - facilities failing retention tests must expand storage before renewal approval.

Why this works

Video retention is a specific, measurable compliance requirement with clear pass/fail thresholds. Citing the exact shortfall (62 days vs. required 90 days) proves you're reading actual inspection reports. The facility knows this deficiency is documented and blocking their license renewal - they need solutions, not pitches.

Data Sources
  1. California Department of Cannabis Control - License Search & Data Dashboard - business_name, compliance_violations, video_retention_test_results

The message:

Subject: Your camera system failed MED's 90-day retention test The September MED inspection at your Aurora store found video retention only goes back 62 days. Colorado requires 90-day minimum retention - your January license renewal requires certification of compliance. Who's handling the storage expansion?
PQS Public Data Strong (8.2/10)

Detention Facilities with PREA Camera Coverage Gaps

What's the play?

Target detention facilities and youth residential treatment centers where PREA audits identified specific camera blind spots in housing units, recreation areas, or intake processing. DOJ requires visual monitoring without privacy violations - facilities with documented gaps must install compliant camera systems before re-audit.

Why this works

PREA camera requirements are technical and specific - certain areas require coverage while others have privacy restrictions. By citing exact blind spot counts and locations from audit reports, you're demonstrating knowledge of PREA's nuanced surveillance requirements. The facility knows these gaps are documented and must be fixed.

Data Sources
  1. PREA Audit Reports - Youth Facilities - facility_name, audit_date, surveillance_deficiencies, camera_coverage_gaps

The message:

Subject: 8 blind spots flagged in your PREA camera audit Your March 2023 PREA audit identified 8 camera blind spots in housing units and recreation areas. Your March 2026 re-audit requires documented remediation with timestamped work orders. Who's tracking the camera installation progress?
PQS Public Data Strong (8.2/10)

Cannabis Facilities with Vault Door Weight Deficiencies

What's the play?

Target cannabis dispensaries where state inspections documented vault door weights falling short of minimum requirements. Most states require 750-pound vault doors for product storage - facilities with lighter doors face compliance violations blocking license renewals.

Why this works

Vault door weight is an obscure but mandatory compliance specification that most cannabis businesses overlook until inspection. Citing the exact weight deficit (450 lbs vs. required 750 lbs) proves you're reading actual inspection reports with specific technical findings. This is a capital project they must schedule before renewal.

Data Sources
  1. California Department of Cannabis Control - License Search & Data Dashboard - business_name, compliance_violations, vault_specifications

The message:

Subject: Your vault door doesn't meet MED weight spec MED's September inspection noted your vault door at 1850 Larimer is 450 pounds. Colorado requires minimum 750-pound vault doors - your license renewal requires compliance certification. Is construction already scheduled for the door replacement?
PQS Public Data Strong (8.1/10)

Cannabis Facilities with MED Violation Count Before Renewal

What's the play?

Target cannabis dispensaries and cultivation facilities with multiple open security violations from recent MED inspections where license renewal windows close within 90 days. Colorado MED blocks renewals for facilities with unresolved violations - each violation requires documented remediation.

Why this works

The specificity of citing exact violation counts and renewal deadlines creates immediate urgency. Cannabis operators know MED is strict about compliance - open violations at renewal time can shut down the business. The message is direct and verifiable, making it easy to route internally.

Data Sources
  1. California Department of Cannabis Control - License Search & Data Dashboard - business_name, address, license_number, compliance_violations, expiration_date

The message:

Subject: 2 MED violations at 1247 Broadway The October MED inspection flagged 2 security deficiencies at your Broadway location. With your February 15th license renewal, unresolved violations block approval. Who's coordinating the compliance response?
PQS Public Data Strong (8.1/10)

Detention Facilities with Zero Intake Area Coverage

What's the play?

Target detention facilities where PREA audits documented complete absence of camera coverage in inmate intake processing areas. DOJ requires continuous monitoring of all inmate processing - facilities with zero coverage face critical non-compliance findings.

Why this works

Zero coverage in a required area is the most serious PREA surveillance deficiency - it's not about camera placement or angles, it's about complete absence of monitoring. The facility knows this is a critical finding requiring immediate capital investment. Citing the exact area with zero coverage proves you understand PREA's tiered compliance requirements.

Data Sources
  1. PREA Audit Reports - Youth Facilities - facility_name, audit_date, surveillance_deficiencies, uncovered_areas

The message:

Subject: Your intake area has zero camera coverage The April 2023 PREA audit found your intake processing area has no video surveillance. DOJ requires continuous monitoring of all inmate processing areas - your April 2026 re-audit tests this. Is facilities already working the camera installation design?
PQS Public Data Strong (8.0/10)

Detention Facilities with Shower Area Camera Non-Compliance

What's the play?

Target detention facilities where PREA audits flagged inadequate camera angles in shower areas. PREA requires visual monitoring without privacy violations - facilities must redesign camera placement to monitor for safety while respecting privacy. This is a technical engineering challenge requiring specialized expertise.

Why this works

Shower area surveillance is one of the most technically complex PREA requirements - cameras must prevent abuse while avoiding privacy violations. By citing the specific violation count and technical requirement, you're demonstrating specialized knowledge of PREA's nuanced surveillance standards. The facility needs engineering expertise, not just cameras.

Data Sources
  1. PREA Audit Reports - Youth Facilities - facility_name, audit_date, shower_area_surveillance_deficiencies

The message:

Subject: Your shower area cameras still aren't compliant The July 2022 PREA audit flagged inadequate camera angles in 6 shower areas. DOJ requires visual monitoring without privacy violations - your March 2025 re-audit tests this. Is engineering already designing the compliant camera placement?

What Changes

Old way: Spray generic messages at job titles. Hope someone replies.

New way: Use public data to find companies in specific painful situations. Then mirror that situation back to them with evidence.

Why this works: When you lead with "Your Dallas facility has 3 open PREA violations from the July 2022 audit" instead of "I see you're hiring for security roles," you're not another sales email. You're the person who did the homework.

The messages above aren't templates. They're examples of what happens when you combine real data sources with specific situations. Your team can replicate this using the data recipes in each play.

Data Sources Reference

Every play traces back to verifiable public data. Here are the sources used in this playbook:

Source Key Fields Used For
California Department of Cannabis Control business_name, address, license_number, compliance_violations, expiration_date Cannabis license violations, renewal deadlines, Intent to Deny notices
CMS Skilled Nursing Facility Compare facility_name, quality_measures, inspection_dates, deficiency_citations, star_rating Healthcare quality declines, immediate jeopardy citations, fire safety scores
CMS Dialysis Facility Compare facility_name, quality_metrics, mortality_rate, hospitalization_rate, compliance_status Dialysis center quality trajectories, compliance status
CMS Ambulatory Surgical Center Quality Reporting facility_name, quality_measures, accreditation_status, inspection_status Surgery center quality metrics, compliance status
PREA Audit Reports - Youth Facilities facility_name, audit_date, surveillance_deficiencies, camera_coverage_gaps Detention facility camera deficiencies, re-audit windows, shower area compliance
ICE Detention Facility Inspection Reports facility_name, inspection_date, compliance_findings, deficiencies Federal detention surveillance requirements, compliance status
County Building Department Records Certificate of Occupancy expiration dates, fire system inspection requirements Building CO renewal deadlines, fire system certification timing
HHS HIPAA Enforcement Updates encryption standard changes, compliance deadlines HIPAA encryption requirements, DVR/NVR compliance standards
Telecom Carrier POTS Retirement Schedules copper line shutdown dates by region Fire alarm POTS dependency, IP migration deadlines