InsightsSalesHow to Find IT and Security Decision-Makers at UK Financial and Legal Firms

How to Find IT and Security Decision-Makers at UK Financial and Legal Firms

August 24, 2026

Written by The Apollo Team

How to Find IT and Security Decision-Makers at UK Financial and Legal Firms

UK financial and legal firms with 150-300 employees sit right on top of an awkward statistical fault line. The government defines medium businesses as 50-249 employees and large businesses as 250+, so any list built on a single "150-300" filter mixes two different regulatory categories, two different buying committees, and two different budget approval chains.

If you're building a security decision-maker list for this segment, sizing accuracy matters as much as email accuracy.

This guide shows GTM teams, RevOps, and SDRs how to define the ICP correctly, map the real buying committee, verify company size before outreach, and build an auditable, compliant contact list. For teams that need to move fast, Apollo's advanced prospecting filters let you segment by employee count, SIC code, and job title in one search.

find it and security decision-makers at uk financial and legal services companies with 150-300 employees and get their verified work emails infographic, key steps and actionable takeaways
find it and security decision-makers at uk financial and legal services companies with 150-300 employees and get their verified work emails infographic, key steps and actionable takeaways
Apollo
VERIFIED CONTACT DATA

Ditch The Manual Research Grind

Spending hours chasing down accurate emails and phone numbers instead of selling. Apollo hands you verified contact data instantly, with 98% email accuracy built in. Stop researching. Start closing.

Start Free with Apollo

Key Takeaways

  • Split your "150-300 employee" target into two cohorts (150-249 medium, 250-300 large) because titles, budget authority, and procurement steps change at the 250-employee line.
  • Security buying committees at finance and legal firms now extend beyond the CISO to Heads of IT, Compliance, Data Protection, and Vendor Risk, so single-threaded outreach under-covers the deal.
  • Use Apollo MCP when you need to pull a verified list of IT and security titles at UK finance and legal firms directly inside ChatGPT, Claude, or Perplexity without switching tabs.
  • Every record in a compliant list needs an evidence trail: source, size verification, role confirmation, verification date, and opt-out status.
  • Use Apollo MCP when you need to enrich a spreadsheet of company names with verified work emails and firmographic data in a single conversational workflow.

A qualifying company is a UK-registered financial services or legal services business whose verified headcount falls between 150 and 300 employees, confirmed through at least one independent size signal beyond a single database field. Because this range crosses the official medium/large boundary, treat it as two sub-segments rather than one bucket.

CriteriaQualifying DefinitionExclusion
Sector (SIC code)64-66 (Financial services, insurance) or 69 (Legal activities)Fintech infrastructure vendors, legal tech SaaS companies (different buying motion)
UK statusRegistered UK entity, Companies House number, UK head office or major UK officeUK sales office only, HQ and decision-making offshore
Employee count150-249 (medium) or 250-300 (large), verified via 2+ sourcesSingle-source headcount estimate with no cross-check
Size evidenceCompanies House filing employee count, job board listings, funding/press dataSelf-reported headcount with no corroboration

According to FSB, there were 38,435 medium-sized businesses (50-249 employees) in the UK as of early 2025, a figure also confirmed by gov.uk. That's the entire medium-business universe across all sectors, which is why filtering to finance and legal SIC codes at the 150-300 range requires company-level verification rather than published aggregate tables.

Why Does The 150-300 Employee Range Split Into Two Different Buying Motions?

The 150-300 range splits into two buying motions because UK statistical classification treats 249 employees as the ceiling for "medium" and 250 as the floor for "large," and that boundary tracks real differences in governance structure. Firms just under 250 employees often still route security purchases through an IT Director with informal sign-off.

Firms just over 250 typically have a named CISO or Head of Information Security, a documented procurement process, and board-level reporting.

This split shows up directly in the data. The UK government's Cyber Security Breaches Survey 2025 found that board-level cyber responsibility was 57% in finance and insurance but only 36% in professional services (the category covering legal firms), meaning your legal-sector messaging needs to work even when the board isn't directly engaged.

Two professionals discussing business over a laptop in a bright, modern office with large windows.
Two professionals discussing business over a laptop in a bright, modern office with large windows.
  • 150-249 employees (medium): IT Director or Head of IT often owns security budget; fewer named security specialists; faster but less formal procurement.
  • 250-300 employees (large): Dedicated CISO or Head of Information Security more likely; procurement, compliance, and vendor risk teams get involved; longer, multi-stakeholder cycles.

The IT and security decision-makers at UK finance and legal firms of this size typically include a core technical owner plus an expanding circle of governance and risk stakeholders. Regulatory pressure from bodies like the FCA is pushing this buying committee wider than "just the CISO."

SectorCore Technical TitlesGovernance/Risk Titles
Financial servicesCISO, Head of IT, IT Director, Head of Information SecurityHead of Operational Resilience, Technology Risk Manager, Compliance Director, Vendor Risk Manager
Legal servicesIT Director, Head of IT, Information Security ManagerData Protection Officer, Risk & Compliance Partner, COO, Practice Manager

On March 18, 2026, the FCA confirmed new incident and third-party reporting rules taking effect March 18, 2027, with more than 40% of cyber incidents reported to the FCA in 2025 involving a third party. That regulatory deadline is a live trigger event for CIOs, risk leaders, and vendor managers at qualifying firms right now, and it's a reason to multi-thread rather than target a single title.

Legal firms show a parallel pattern. Armstrong Watson reports the UK legal sector saw reported data breaches rise from 1,633 to 2,284 incidents (a 39% increase) in the year to September 2024, reinforcing why Data Protection Officers and Risk Partners belong in the same sequence as IT Directors.

Apollo
LEAD-TO-OPPORTUNITY GAP

Turn Weak Leads Into Sales-Ready Deals

Filling the top of funnel with leads that never convert. Apollo's buyer intent signals surface prospects actually ready to talk, so your pipeline stops leaking at the handoff. Built-In saw a 10% lift in win rate using Apollo's scoring.

Start Free with Apollo

How Do You Verify Company Size Before Adding A Record To Your List?

You verify company size by cross-checking at least two independent sources before treating a headcount figure as reliable, since a single database field is frequently stale or estimated. Relying on one number is the most common reason lists mis-segment 150-300 employee targets.

  • Companies House filings: Confirms UK registration status and, for some entities, average employee numbers in annual accounts.
  • Professional network employee count: Cross-reference against a second data provider's count.
  • Job board activity: Active security or IT job postings can confirm a company is scaling into the 250+ band.
  • Verification date field: Record when each data point was last checked, since headcounts shift quickly at growth-stage firms.

Struggling to confirm headcount and role at scale? Apollo's data enrichment pulls firmographic and role data from Apollo's B2B data network so RevOps teams aren't manually stitching together three sources per record.

How Can SDRs And RevOps Build A Record-Quality Scorecard For This List?

A record-quality scorecard works by scoring every contact on five evidence fields instead of accepting a name and email at face value. This gives RevOps leaders an auditable trail and gives SDRs confidence before they send a single message.

FieldWhat To Capture
SourceWhich data provider or method surfaced the contact
Size proofTwo-source headcount confirmation, with date
Role checkTitle confirmed against company website, network profile, or press mention
Verification dateLast date the email was checked for deliverability
Objection statusAny prior opt-out, bounce, or do-not-contact flag

For SDRs and BDRs working this segment, a scorecard like this also speeds up personalization; you already know the role is confirmed, so your first line can reference the actual regulatory pressure (FCA reporting rules for finance, breach trends for legal) instead of a generic opener. Account Executives inherit cleaner records too, which shortens the discovery call needed to confirm fit.

You test a data vendor by running a small, representative sample against your scorecard fields before buying or licensing a full list. Ask every vendor the same five questions and score the answers side by side.

  • Can you filter by SIC code (64-66, 69) and UK registration status in the same query?
  • Do you provide two independent employee-count signals, or one estimate?
  • How recently was each work email verified, and what happens on bounce?
  • Can you segment the list into 150-249 and 250-300 cohorts automatically?
  • What lawful basis and privacy-notice support do you provide for UK GDPR compliance?

On the compliance question: named business contacts are personal data under UK GDPR, and even though PECR generally doesn't require consent to email corporate subscribers, you still need a lawful basis (commonly legitimate interests) and must generally provide privacy information within one month when the data comes from a third party. Build this check into your vendor scorecard, not as an afterthought.

How Do You Run This Whole Workflow Without Switching Between Five Tools?

You run this workflow in one place by connecting Apollo to the AI tool you already use for research, so the ICP search, size verification, role check, and email enrichment happen inside a single conversation instead of six separate tabs. Apollo MCP connects Apollo directly into ChatGPT, Claude, Perplexity, and Codex, so a RevOps lead can type a prompt like "find IT and security decision-makers at UK financial and legal firms with 150-300 employees" and get back a segmented, enriched list without leaving the chat window.

Setup is no-code: connect Apollo through the AI tool's connectors or integrations panel via OAuth, on any Apollo plan including free. From there you can search for matching people and companies, enrich records with verified work emails and phone numbers, push qualified contacts into sequences, and ask follow-up questions about campaign performance, all without opening a new tab.

Collin Stewart of Predictable Revenue put it simply: "We reduced the complexity of three tools into one." That's the toggle-tax problem this workflow solves. Instead of exporting a list, cleaning it, importing to a verifier, re-enriching, and building a sequence, GTM teams handle discovery, verification, and outreach setup as one motion. Spending hours stitching together spreadsheets and verification tools? Apollo's sales engagement platform lets you move from verified contact to multi-channel sequence in the same workspace.

What Should You Put In The First Outreach Message To This Audience?

Your first message should reference a specific, verifiable trigger relevant to the recipient's sector and role rather than a generic security pitch. Buyers are actively filtering out irrelevant outreach: Gartner's survey of 632 B2B buyers found 73% actively avoid suppliers sending irrelevant outreach, and 61% prefer a rep-free buying experience where possible.

  • Finance sector: Reference the FCA's March 2026 third-party reporting rules and the 2027 deadline.
  • Legal sector: Reference sector-specific breach trends and the shift toward dedicated cyber specialists at mid-market firms.
  • Both sectors: Confirm you've verified their company falls in the correct size band; specificity signals you did the work.

Need help writing messages that reflect this level of specificity? See this guide to sales emails that get responses for structure and tone guidance that pairs well with a verified, segmented list.

Three diverse professionals collaborate at a desk with laptops in a modern office overlooking a city skyline.
Three diverse professionals collaborate at a desk with laptops in a modern office overlooking a city skyline.

Conclusion: Build The List Right, Then Let The Workflow Scale

Getting this segment right isn't about finding more names, it's about splitting the 150-300 range into medium and large cohorts, mapping the wider security buying committee, and attaching evidence to every record before you send a single email. That discipline is what separates a compliant, high-response list from a bounce-heavy spreadsheet.

Once your ICP definition and scorecard are in place, the execution layer should be just as tight. Apollo brings B2B data, sales intelligence, and multi-channel engagement into one workspace, so RevOps and SDR teams don't have to stitch together a data vendor, a verifier, and a sequencing tool for this one segment. Get Leads Now and start building your verified UK finance and legal security decision-maker list today.

Apollo
ROI AND BUDGET JUSTIFICATION

Prove ROI Fast, Scale Outreach With Apollo

Struggling to justify tool spend before the pilot even shows results? Apollo consolidates prospecting and outreach into one platform, so teams see pipeline impact fast instead of waiting quarters to prove value. Start free and show leadership the numbers this month.

Start Free with Apollo
Don't miss these
See Apollo in action

We'd love to show how Apollo can help you sell better.

By submitting this form, you will receive information, tips, and promotions from Apollo. To learn more, see our Privacy Statement.

4.7/5 based on 9,690 reviews