# Message test — https://www.sans.org/

After reading your page, only 0 of 15 personas could name what kind of product this is, unprompted.

- **Page tested:** https://www.sans.org/
- **Audience tested against:** Information security managers and directors
- **Personas:** 15 simulated
- **Report:** https://grader.wynter.com/r/cybersecurity-training-degrees-and-resources-s-xaWo9G8

> These answers are generated by AI, scored on Wynter's B2B Message
> Layers framework using behaviorally-diverse simulated personas. The
> methodology is real and the critique is directional. What a simulated
> persona cannot have is a live budget, a renewal coming up, or a boss
> asking about this quarter.

---

## 01 · The scores

Every persona answered all four questions. These are four independent
proportions of the same panel, not stages of a funnel.

| Layer | Question | Cleared the bar | Strength | Of those who passed |
| --- | --- | --- | --- | --- |
| 1. Clarity | Do they understand what you do? | 0/15 | 41% | — |
| 2. Relevance | Can they tell what it solves, and who it's for? | 0/15 | 0% | — |
| 3. Value | Do they actually want it? | 0/15 | 3% | — |
| 4. Differentiation | Is there a reason to pick you over the alternatives? | 1/15 | 8% | without hesitation |

**Brand alignment** (a side metric, not one of the four layers) — 0/15, 33% strength. Does the page read like the company you actually are?

**Fix first: Clarity.** Earliest failing layer, walking the sequence in order — not simply the lowest score.

### What they thought you sell

11 of the personas who named a category got it wrong:

- 5× “Unknown / error page”
- 2× “Unknown / page error”
- 1× “Unknown - error page, no content”
- 1× “Unknown - page failed to load”
- 1× “Unknown — page did not load”
- 1× “Unknown / page not loaded (error page)”

---

## 02 · What to change, layer by layer

Ordered worst-first. Specific edits, not a restatement of the score.

### Clarity

**Replace the 500 error page with the live product page before any further testing.**

The page returns "We are currently experiencing technical difficulties" and a 500 code, so no product content exists to read. Restore the page so buyers see what the product is.

*effort high · impact high · tested against Show the product early*

**Add a maintained error page naming the product and linking to a working overview.**

The current error screen shows only skip links and the number 500, giving a visitor nothing to identify the company or where to go next. Say what the site is and offer one link back to a working page.

*effort low · impact medium · tested against One clear next action*

**Add a status page link and expected return time to the error message.**

"Please try again later" tells a visitor nothing about how long later means or where to check. Give a status URL and a time estimate so the reader has a next step.

*effort low · impact medium · tested against Concrete over abstract*

### Relevance

**Open the restored page with the specific job the buyer is hiring you for.**

Nothing on the page names a problem, a role, or a use case, so no reader can tell whether it is for them. Lead with the task a security or operations buyer would say out loud.

*effort medium · impact high · tested against Lead with the use case*

**State the problem in the buyer's words above any description of the product.**

The page presents no problem statement at all, so even a restored page risks opening on capabilities. Start with the failure the buyer already lives with before naming the answer.

*effort medium · impact high · tested against Problem before solution*

**Name the buyer role and company size in the first screen of the restored page.**

Readers arrived mid-renewal with no way to see whether the page addressed their situation. Write a line that names the team and the environment, so the right reader stops and the wrong one leaves.

*effort low · impact high · tested against Name the audience*

### Value

**Add a quantified outcome with its timeframe directly under the main headline.**

There is no claim, number, or outcome anywhere for a buyer to weigh. Put one measurable result, such as reduction in analyst hours or incidents, where the eye lands first.

*effort medium · impact high · tested against Specifics beat superlatives*

**Place a named customer and their result beside the main claim on the restored page.**

Buyers said they needed a reference customer at their own scale before spending time. Put the company name, size, and measured change next to the claim it supports, not on a separate page.

*effort medium · impact high · tested against Proof next to the claim*

**Pair each capability on the restored page with the task it removes from the buyer.**

Feature lists without outcomes leave the reader to guess the payoff. Write each line as what the buyer stops doing or finishes faster.

*effort medium · impact medium · tested against Tie the feature to the outcome*

### Differentiation

**Add a short section explaining how your approach differs from the alternatives buyers compare you against.**

With the page down, buyers dropped the vendor for competitors whose sites load, and nothing on the restored page should leave that comparison unanswered. Name the specific difference: scope, speed, pricing model, or who it is built for.

*effort medium · impact high · tested against Give a reason to choose you*

**Add the reliability objection and your answer to it near the top of the restored page.**

Buyers evaluating a renewal now hold a live doubt about your uptime. Name the concern and answer it with your published availability record and status page.

*effort medium · impact high · tested against Answer the live objection*

### Brand alignment (side metric)

**Add a public status page and uptime history, linked from the header.**

An unhandled 500 from a vendor selling reliability reads as evidence against the pitch. A linked uptime record and incident history turn the claim into something checkable.

*effort medium · impact high · tested against Proof next to the claim*

**Rewrite the error text to acknowledge the incident and point to incident updates.**

"We are currently experiencing technical difficulties" is generic and unowned, which compounds the damage for a reliability vendor. Acknowledge the outage plainly and link to where updates are posted.

*effort low · impact medium · tested against Plain language*

---

## 03 · What the personas said

### The page served a 500 error, so no product content was visible

All respondents hit a 500 error page with no product copy, claims, or mechanism to read. Evaluation of the message itself was impossible for every participant.

> the page just showed an error: "We are currently experiencing technical difficulties. Please try again later. 500". There was no actual product content to assess
> 
> — Senior Information Security Manager, Healthcare, 5000+

> Honestly, I can't tell you what this company does — the page just threw a 500 error page at me: "We are currently experiencing technical difficulties. Please try again later."
> 
> — Information Security Manager, Technology, 1001-5000

> No idea — the page just threw a "500, technical difficulties" error. There's literally no product copy to go on, so I can't tell you what this company does.
> 
> — Director of Information Security, Telecommunications, 201-500

> the page didn't load any actual content, just a generic error message: "We are currently experiencing technical difficulties. Please try again later." and a stray "500" error code with an "Edit" link, which looks like a broken CMS page
> 
> — Information Security Director, Retail, 501-1000

> the page just threw up a "500 — technical difficulties" error page, not actual product copy
> 
> — Information Security Manager, Financial Services, 1001-5000

> the page just threw a "500 - technical difficulties, please try again later" error at me. There's no product description, no claims, nothing to evaluate.
> 
> — Senior Information Security Manager, Technology, 5000+

> the page didn't load anything but an error: "We are currently experiencing technical difficulties. Please try again later. 500." There's no product description, no claims, nothing to evaluate.
> 
> — Director of Information Security, Healthcare, 201-500

> the page didn't load any actual content, it just returned a 500 error page: "We are currently experiencing technical difficulties. Please try again later." There's no product description, no mechanism, no claims to evaluate at all.
> 
> — Information Security Director, Telecommunications, 501-1000

### No problem statement, audience, or product name was present to judge relevance

Respondents reported no stated problem, named role, use case, or product identity. Several specified what was missing: healthcare-specific problems with quantified metrics, and an explicitly named security role and use case.

> No problem statement, no audience, no product copy at all.
> 
> — Senior Information Security Manager, Healthcare, 5000+

> There's nothing here to find — the page just shows a "500" error and "We are currently experiencing technical difficulties. Please try again later." No problem statement, no audience, nothing to even hunt through.
> 
> — Director of Information Security, Telecommunications, 201-500

> There's nothing here to find — no problem statement, no audience, no product description. The entire page is just an error
> 
> — Information Security Director, Retail, 501-1000

> the page is literally just a 500 error, "We are currently experiencing technical difficulties. Please try again later," plus a stray "Edit" link that looks like leftover CMS debris. No problem statement, no audience, no product name, nothing.
> 
> — Senior Information Security Manager, Technology, 5000+

> I'd need it to name my problem in healthcare-specific terms — think incident response times, audit/compliance burden (HIPAA, SOC 2), or breach exposure for a company our size — plus a concrete metric or case study showing a peer org got measurable results
> 
> — Director of Information Security, Healthcare, 201-500

> I'd need to see it called out for a security role at my scale directly — something like 'built for infosec teams at multi-location retailers' plus a concrete use case (fraud, PCI compliance, incident response) that mirrors what I deal with daily.
> 
> — Information Security Manager, Retail, 1001-5000

### Timing during an active renewal cycle amplified the damage

Two respondents flagged that the downtime occurred while they were evaluating a renewal, making it a live reliability signal rather than an abstract inconvenience.

### There were no claims, metrics, or proof points to evaluate

Respondents found no value proposition, mechanism, customer evidence, or numbers on the page. Nothing was available to test against their own reality.

> I can't answer that because there's literally nothing to evaluate — the page is just a 500 error page, "We are currently experiencing technical difficulties. Please try again later."
> 
> — Information Security Manager, Retail, 1001-5000

> no problem statement, no claimed outcome, no named customers, nothing I could hold against reality even hypothetically
> 
> — Senior Information Security Manager, Retail, 5000+

> I can't answer that in any meaningful way because there's nothing here to evaluate — the page is just a 500 error, "We are currently experiencing technical difficulties. Please try again later." There's no claim about what would change, no mechanism, no proof points, nothing to even hypothesize "if this worked as promised."
> 
> — Information Security Manager, Technology, 1001-5000

> The page is just a 500 error, so I have no claims, no mechanism, no numbers to judge "if it worked as promised."
> 
> — Director of Information Security, Telecommunications, 201-500

### The broken page disqualified the vendor outright against working competitors

Respondents did not treat the error as neutral. They described it as a concrete negative data point for renewal, grounds for removal from shortlist comparison, and automatic disqualification against competitors whose pages load.

> If a competitor's shortlisted page actually loads and shows me a problem statement, customers, or even basic product detail, they win by default. A broken page at evaluation time tells me something about reliability
> 
> — Senior Information Security Manager, Healthcare, 5000+

> for a vendor up for renewal, a broken page during evaluation is an actual data point against them, not neutral.
> 
> — Information Security Director, Telecommunications, 501-1000

> This one rules itself out immediately — there's nothing on the page but "We are currently experiencing technical difficulties. Please try again later." That's an automatic disqualifier against any competitor that actually loads
> 
> — Information Security Manager, Retail, 1001-5000

> if a vendor can't even keep a landing page up while I'm evaluating them, that's a data point about reliability in itself, and I'd need someone to send me working materials before I'd reconsider.
> 
> — Senior Information Security Manager, Financial Services, 5000+

> If a vendor can't keep their own page up for a shortlist review, that's a reason to drop them, not a tiebreaker.
> 
> — Director of Information Security, Telecommunications, 201-500

> against any competitor who actually shows up with a claim and proof points, this one loses by default
> 
> — Information Security Manager, Financial Services, 1001-5000

> one of them not even having a working page to show me isn't a weak signal, it's disqualifying on its own - it tells me nothing about the product but quite a bit about whether this vendor has their basics sorted.
> 
> — Senior Information Security Manager, Technology, 5000+

### The outage itself read as evidence of poor reliability from a vendor selling reliability

Respondents treated the unhandled 500 error as a signal about the company, not just the page: weak engineering maturity, immature operations, and damaged infrastructure credibility. Two noted the irony of a security or reliability vendor whose own site is…

> a vendor whose site throws an unhandled 500 rather than a graceful maintenance page feels under-resourced on basic engineering hygiene — not a confidence builder going into a renewal conversation.
> 
> — Information Security Director, Healthcare, 501-1000

> there's no copy, no tone, no claims, nothing to size up a company from. All I've got is "We are currently experiencing technical difficulties. Please try again later. 500."
> 
> — Senior Information Security Manager, Healthcare, 5000+

> the lack of a custom error page or even basic branding on the failure screen makes me guess smaller or less mature outfit
> 
> — Director of Information Security, Technology, 201-500

### Respondents named reference customers and quantified risk reduction as the bar for a…

Absent any content, several respondents volunteered what would have earned their time: a named reference customer at 5000+ employees, documented risk reduction or analyst workload improvement, and a credible mechanism backed by references.

> A credible, named reference customer - ideally another EU tech company at 5000+ employees - saying this tool cut a specific pain point like alert fatigue or audit hours, with a number attached.
> 
> — Senior Information Security Manager, Technology, 5000+

> A credible, quantified reduction in risk or analyst workload — something like fewer hours spent on manual triage or a documented drop in incident response time at a similar-sized healthcare org — backed by a reference I can call
> 
> — Director of Information Security, Healthcare, 201-500

> The one outcome worth my time would be a credible, evidenced mechanism showing how the product reduces a specific risk I already track — paired with a reference customer of comparable size and sector I could actually call.
> 
> — Information Security Director, Telecommunications, 501-1000

---

## 04 · The hardest read

An adversarial pass over the findings. Every claim below was checked
against the panel's own answers; unsupported ones were dropped.

- **This test produced zero data on the messaging and must be rerun from scratch.** *(high)*
  All 15 respondents hit a 500 error with no copy, claims, or mechanism visible (theme 0), and 6 confirmed no problem statement, audience, or product name existed to judge (theme 1). Every downstream score measures an outage, not words.
- **The page actively destroyed brand equity rather than merely failing to build it.** *(high)*
  7 respondents read the unhandled 500 as weak engineering maturity and immature operations, with two naming the irony of a reliability vendor (theme 5), and 7 more treated it as grounds for disqualification (theme 4). Silence would have scored better.
- **The failure cost live pipeline, not just a test cycle.** *(high)*
  Two respondents were mid-renewal evaluation when the page died and logged it as a concrete negative data point (theme 2), while 7 described removal from shortlist comparison against competitors whose pages load (theme 4).
- **Respondents wrote the brief the page should have delivered, and it is specific enough that there is no excuse for missing it.** *(medium)*
  3 volunteered the exact bar unprompted: a named reference customer at 5000+ employees, documented risk reduction or analyst workload improvement, and a credible mechanism (theme 6); 6 named healthcare-quantified problems and an explicit security role (theme…
- **No differentiation claim survives, because the comparison respondents ran was availability versus competitors, not capability.** *(medium)*
  7 respondents framed the vendor against competitors purely on whose page loads (theme 4), and 4 found no value proposition, mechanism, or customer evidence to compare on (theme 3).

---

## 05 · Who answered

| # | Role | Industry | Company size |
| --- | --- | --- | --- |
| 1 | Information Security Manager | Technology | 1001-5000 |
| 2 | Senior Information Security Manager | Healthcare | 5000+ |
| 3 | Director of Information Security | Telecommunications | 201-500 |
| 4 | Information Security Director | Retail | 501-1000 |
| 5 | Information Security Manager | Financial Services | 1001-5000 |
| 6 | Senior Information Security Manager | Technology | 5000+ |
| 7 | Director of Information Security | Healthcare | 201-500 |
| 8 | Information Security Director | Telecommunications | 501-1000 |
| 9 | Information Security Manager | Retail | 1001-5000 |
| 10 | Senior Information Security Manager | Financial Services | 5000+ |
| 11 | Director of Information Security | Technology | 201-500 |
| 12 | Information Security Director | Healthcare | 501-1000 |
| 13 | Information Security Manager | Telecommunications | 1001-5000 |
| 14 | Senior Information Security Manager | Retail | 5000+ |
| 15 | Director of Information Security | Financial Services | 201-500 |

---

## 06 · Before you act on this

The methodology is real, and the critique is directional. What a
simulated persona cannot have is a live budget, a renewal coming up, or
a boss asking about this quarter. **Validate anything you're betting on
with real ICPs who are actually in-market.** Being wrong is more
expensive than you think. Finding out is cheaper than you'd guess.

Wynter runs message testing with verified B2B professionals — trusted
by HubSpot, RingCentral, Shopify, Cognism, Paddle, Veeam, Rippling and
Miro. <https://wynter.com>

This report is kept for 60 days from 2026-10-05, then deleted along with the personas and their answers.

