# Message test — https://quantumnetwork.ch/

After reading your page, only 4 of 15 personas could name a reason to pick you over a similar option.

- **Page tested:** https://quantumnetwork.ch/
- **Audience tested against:** ICP: the person inside the company who carries the responsibility. Because of NIS-2 that is the board / management, not the IT department.
They are NOT technical. They do understand the pain.
They are not the ones who will operate the box; their IT people are.
- **Personas:** 15 simulated
- **Report:** https://grader.wynter.com/r/quantum-network-VPMkXfY

> These answers are generated by AI, scored on Wynter's B2B Message
> Layers framework using behaviorally-diverse simulated personas. The
> methodology is real and the critique is directional. What a simulated
> persona cannot have is a live budget, a renewal coming up, or a boss
> asking about this quarter.

---

## 01 · The scores

Every persona answered all four questions. These are four independent
proportions of the same panel, not stages of a funnel.

| Layer | Question | Cleared the bar | Strength | Of those who passed |
| --- | --- | --- | --- | --- |
| 1. Clarity | Do they understand what you do? | 15/15 | 84% | 4 without hesitation, 11 with reservations |
| 2. Relevance | Can they tell what it solves, and who it's for? | 15/15 | 79% | 1 without hesitation, 14 with reservations |
| 3. Value | Do they actually want it? | 14/15 | 74% | all with reservations |
| 4. Differentiation | Is there a reason to pick you over the alternatives? | 4/15 | 40% | all with reservations |

**Brand alignment** (a side metric, not one of the four layers) — 13/15, 72% strength (all with reservations). Does the page read like the company you actually are?

**Fix first: Differentiation.** Earliest failing layer, walking the sequence in order — not simply the lowest score.

---

## 02 · What to change, layer by layer

Ordered worst-first. Specific edits, not a restatement of the score.

### Differentiation

**Add one named customer deployment with sector and site count.**

Partner logos — Red Hat, Advantech, OnLogic, NIST — stand in for customers, so the page proves suppliers, not users. A single named utility, port or airport deployment would move readers from reading to evaluating.

*effort medium · impact high · tested against Proof next to the claim*

**State why QPN over a standard VPN or competing PQC gateway.**

'One protection layer. Wherever your network needs to connect.' could headline any VPN vendor. Name the specific reason to choose — DIN-rail OT hardware, no telemetry, no cloud dependency — as a comparison, not a feature list.

*effort medium · impact high · tested against Give a reason to choose you*

**Replace 'typical latency of one millisecond' with tested conditions.**

The latency line is read as a vendor assertion because no throughput, packet size or link type is given. State the measured figure with the test setup beside it, or drop the number.

*effort low · impact high · tested against Specifics beat superlatives*

### Value

**Publish a spec block: throughput, failover time, MTBF, failure mode.**

Readers could not complete a purchase decision without numbers, particularly what happens to traffic when a gateway fails. Put a short spec table on the page, with failover behaviour stated in plain terms.

*effort medium · impact high · tested against Answer the live objection*

**Say exactly where the gateway sits relative to the firewall.**

'In front of or behind your existing firewall, and your IT team connects it by adjusting a few network routes' is too vague to plan a change window. Name the routing changes and the two supported placements.

*effort low · impact medium · tested against Concrete over abstract*

### Relevance

**Name the buyer in the subheading, not just the imagery.**

SCADA, PLCs and control rooms signal the audience but nobody is addressed directly. Add a line naming OT and network security teams at utilities, ports and water operators.

*effort low · impact medium · tested against Name the audience*

### Brand alignment (side metric)

**Add maturity signals: founding year, deployed sites, certifications.**

Logos without customers and mechanism-heavy copy read as an early-stage engineering shop. A single line of company facts near the CTA changes the inferred size of the vendor.

*effort low · impact medium · tested against Proof next to the claim*

---

## 03 · What is working

### The core offer — a post-quantum encryption gateway that protects OT links without…

Ten respondents restated the product and its purpose accurately: hardware/software gateways encrypting site-to-site OT traffic with post-quantum crypto, no rip-and-replace. This was the most consistently reproduced message on the page.

> They sell a hardware/software gateway you bolt onto each site of your network to encrypt the traffic between them with post-quantum crypto, so nothing readable crosses the public internet even once quantum computers can break today's encryption.
> 
> — Chief Risk Officer, Government and Public Sector, 201-500

> They make hardware/software gateways you drop into an existing network — at each site, in front of or behind your firewall — that set up an encrypted tunnel between locations using post-quantum cryptography
> 
> — Board Member - Risk/Security Committee, Critical Infrastructure, 501-1000

> They sell hardware gateways you bolt onto each end of a network link to encrypt site-to-site traffic with post-quantum crypto (ML-KEM/FIPS-203)
> 
> — Director of Cybersecurity, Utilities and Energy, 1001-5000

> the H1 and subhead do the work: "Add quantum-safe protection to your network, without replacing your existing infrastructure" and "A gateway at each location encrypts everything your sites send to each other."
> 
> — VP of Information Security, Transportation and Logistics, 5000+

> They sell hardware/software gateways that bolt onto existing network links to add post-quantum encryption to the traffic between sites — site-to-site, edge-to-cloud, or remote client access — without touching your firewalls, servers or applications.
> 
> — Chief Information Security Officer, Manufacturing, 201-500

> the real change is closing the harvest-now-decrypt-later gap on our SCADA links without a rip-and-replace project - "1ms latency" and "servers, clients and applications are not touched" means I'm not asking the OT team to re-cert half the plant
> 
> — Chief Risk Officer, Government and Public Sector, 201-500

> If it worked as described, I'd get harvest-now-decrypt-later protection on our inter-site OT links without ripping out SCADA gear or re-architecting the firewall stack — "your infrastructure stays, the connection becomes secure" is the actual value, since any change I make to an OT environment has to clear a very high bar with our engineers and auditors.
> 
> — CISO, Government and Public Sector, 501-1000

> The tone is written for someone like me in terms of concerns addressed — "nothing removed," "your firewall keeps its job," "typical latency of one millisecond"
> 
> — CISO, Critical Infrastructure, 5000+

> The tone is written for someone technical and risk-averse like me: it leads with "without replacing your existing infrastructure" and keeps hammering "nothing touched, firewall keeps its job" which is exactly the objection I'd raise first.
> 
> — Chief Risk Officer, Utilities and Energy, 201-500

### SCADA, PLC and control-room references make the critical-infrastructure focus land…

Six respondents said the OT/critical-infrastructure audience and problem were obvious from the hero line, subheading, imagery and domain terminology. Several named SCADA, PLCs and control rooms as the signals that did the work.

> It was clear within seconds - the hero line "Add quantum-safe protection to your network, without replacing your existing infrastructure" plus the SCADA/control-room diagram (control room, PLCs, sensors, water treatment plant, airport tower) told me exactly who this is for
> 
> — Chief Risk Officer, Government and Public Sector, 201-500

> the clues are heavy-handed: SCADA, PLCs, control rooms, water treatment plants, OT environments — this is aimed at industrial/critical-infrastructure security people like me, not a generic office IT buyer.
> 
> — Chief Information Security Officer, Manufacturing, 201-500

> the subhead "Add quantum-safe protection to your network, without replacing your existing infrastructure" and the diagram with control room, SCADA, PLCs, solar park, water treatment plant tells you immediately this is for OT/critical infrastructure operators
> 
> — Chief Risk Officer, Critical Infrastructure, 1001-5000

> The reader isn't named explicitly as "utilities" or "energy operators," but the imagery and phrases like "Field side," "your machines PLCs, sensors, cameras and barriers," and "critical OT environments" make it obvious enough
> 
> — Director of Cybersecurity, Utilities and Energy, 1001-5000

> the imagery and phrase "SCADA and dispatch" made the intended buyer obvious by inference rather than hunting — I didn't have to dig for it
> 
> — Board Member - Risk/Security Committee, Critical Infrastructure, 501-1000

> The intended reader isn't named in so many words like "utilities" or "critical infrastructure operator," but the diagrams do that work for you - control room, SCADA, dispatch, PLCs, sensors, cameras, barriers, water treatment plant, airport control tower, solar park
> 
> — Board Member - Risk/Security Committee, Utilities and Energy, 5000+

---

## 04 · What the personas said

### The 1ms latency claim has no baseline, methodology or source and is not believed

Four respondents singled out the one-millisecond latency and telemetry claims as unsupported, citing missing test conditions, baselines and independent proof. Performance claims were read as vendor assertion rather than evidence.

> words like "no telemetry," "typical latency of one millisecond," and "encrypted tunnel established" are asserted flatly with no source, no test conditions, and no named environment
> 
> — VP of Information Security, Transportation and Logistics, 5000+

> The phrase "typical latency of one millisecond" is the culprit — "typical" has no defined baseline (typical of what topology, what packet size, what distance between sites?), and there's no test report or methodology attached, so it reads like a marketing number rather than an engineering spec I could hold them to.
> 
> — CISO, Government and Public Sector, 501-1000

> 1ms and "no telemetry" are just claims until I see independent test numbers on our actual link speeds, a real FIPS-203 conformance cert, and a reference customer running this in a similarly regulated multi-site OT environment.
> 
> — Chief Information Security Officer, Manufacturing, 201-500

> But "worth a meeting" hinges on things this page doesn't give me: what's the actual latency and failover behaviour under load beyond the throwaway "typical latency of one millisecond," what happens if a gateway fails in a control loop, and is FIPS-203/ML-KEM compliance independently certified or just a standards namedrop.
> 
> — Director of Cybersecurity, Utilities and Energy, 1001-5000

### Firewall placement and network routing impact are described too vaguely to plan a…

One respondent could not determine where the gateway sits in firewall topology or how it affects network routing.

> 'in front of or behind your existing firewall' is a bit hand-wavy about which topology actually applies to a given site, and 'preconfigured and easy to connect' glosses over what 'a few network routes' really means
> 
> — Board Member - Risk/Security Committee, Critical Infrastructure, 501-1000

### No named customer appears anywhere, and respondents said one reference would move them…

Eight respondents flagged the absence of named customers or case studies. Three stated specifically that a single reference from a utility, port, airport or regulated OT operator would convert them to a full evaluation.

> I'd need a named reference site — a utility, port, or airport operator by name, with a quote from their OT or network lead
> 
> — Board Member - Risk/Security Committee, Critical Infrastructure, 501-1000

> One outcome: a named reference customer in transportation, logistics or utilities who put this in front of an actual NIS-2 auditor and passed the "encryption in transit" control — that single data point converts this from a 30-minute call into a real evaluation.
> 
> — VP of Information Security, Transportation and Logistics, 5000+

> no named customers, no case study showing this actually got someone through a NIS-2 audit
> 
> — VP of Information Security, Transportation and Logistics, 5000+

> I'd walk in wanting a reference customer in critical infrastructure and a failure-mode conversation, not a demo of the happy path
> 
> — Board Member - Risk/Security Committee, Utilities and Energy, 5000+

> The FIPS-203/ML-KEM standardisation line is the one thing that would tip me toward this over a competitor with vaguer "quantum-ready" language - it's a concrete, checkable claim rather than marketing fluff. Against that, "no rip and replace, no touching servers or PLCs" plus "1ms latency" is exactly the pitch every OT security vendor makes, and this page gives me zero customer names
> 
> — Chief Risk Officer, Government and Public Sector, 201-500

> The partner logos — Red Hat, Advantech, OnLogic, NIST — read like a startup borrowing credibility through integration partners and standards bodies rather than its own track record, which is a pattern I've seen before from newer entrants trying to look bigger than they are.
> 
> — CISO, Government and Public Sector, 501-1000

> 1ms and "no telemetry" are just claims until I see independent test numbers on our actual link speeds, a real FIPS-203 conformance cert, and a reference customer running this in a similarly regulated multi-site OT environment.
> 
> — Chief Information Security Officer, Manufacturing, 201-500

> no independent benchmark for that latency number, no named reference customer running this in a multi-site OT/SCADA environment, no failure-mode explanation for what happens to control traffic when a gateway drops or loses sync.
> 
> — Chief Information Security Officer, Manufacturing, 201-500

### There is no spec sheet, so the buying decision cannot be made from the page

Four respondents said missing throughput, latency-under-load, MTBF, failover time and failure-mode documentation blocked a purchase decision. Two tied real value specifically to demonstrated failover survivability without dropped traffic.

> But "worth a meeting" hinges on things this page doesn't give me: what's the actual latency and failover behaviour under load beyond the throwaway "typical latency of one millisecond," what happens if a gateway fails in a control loop, and is FIPS-203/ML-KEM compliance independently certified or just a standards namedrop.
> 
> — Director of Cybersecurity, Utilities and Energy, 1001-5000

> the page gives me no side-by-side numbers — no throughput under load, no MTBF or failover time, no pricing tier, no named reference customer
> 
> — Board Member - Risk/Security Committee, Critical Infrastructure, 501-1000

> no independent benchmark for that latency number, no named reference customer running this in a multi-site OT/SCADA environment, no failure-mode explanation for what happens to control traffic when a gateway drops or loses sync.
> 
> — Chief Information Security Officer, Manufacturing, 201-500

> The one outcome that matters is watching the tunnel survive a gateway failure or firmware update without dropping SCADA/dispatch traffic or requiring a control-room outage window
> 
> — Board Member - Risk/Security Committee, Critical Infrastructure, 501-1000

> I'd walk in wanting a reference customer in critical infrastructure and a failure-mode conversation, not a demo of the happy path
> 
> — Board Member - Risk/Security Committee, Utilities and Energy, 5000+

### The page reads as an early-stage, engineering-led vendor with no maturity signals

Four respondents inferred a small, unproven or niche vendor from partner logos without customers, absent founding date, team page and customer count, and mechanism-heavy copy that assumes insider knowledge.

> The partner logos — Red Hat, Advantech, OnLogic, NIST — read like a startup borrowing credibility through integration partners and standards bodies rather than its own track record, which is a pattern I've seen before from newer entrants trying to look bigger than they are.
> 
> — CISO, Government and Public Sector, 501-1000

> I'd picture a smallish, engineering-led vendor - maybe 20-100 people, a few years old, probably spun out of crypto or industrial networking rather than a big platform company. The Advantech/OnLogic hardware partnerships and Red Hat/Ubuntu/SuSE/Debian client list read like a niche OT security shop, not an enterprise giant with a polished sales machine - there's no pricing, no case studies, no named customers, just "Talk to an expert."
> 
> — VP of Information Security, Manufacturing, 501-1000

> what's missing for full credibility is any sense of company maturity — no "founded in," no team page, no customer count
> 
> — CISO, Critical Infrastructure, 5000+

> The tone is written for someone like me: it doesn't waste time explaining what SCADA or a firewall is, it goes straight to "your infrastructure stays, the connection becomes secure," which assumes I already own the pain of rip-and-replace fights.
> 
> — Chief Information Security Officer, Government and Public Sector, 1001-5000

### The audience is shown, never stated, so buyers have to infer whether the page is for them

Four respondents noted the target buyer was inferred from visuals and examples rather than named explicitly, and one flagged that the page assumes prior familiarity with SCADA pain.

> the imagery and phrase "SCADA and dispatch" made the intended buyer obvious by inference rather than hunting — I didn't have to dig for it
> 
> — Board Member - Risk/Security Committee, Critical Infrastructure, 501-1000

> The reader isn't named explicitly as "utilities" or "energy operators," but the imagery and phrases like "Field side," "your machines PLCs, sensors, cameras and barriers," and "critical OT environments" make it obvious enough
> 
> — Director of Cybersecurity, Utilities and Energy, 1001-5000

> The intended reader isn't named in so many words like "utilities" or "critical infrastructure operator," but the diagrams do that work for you - control room, SCADA, dispatch, PLCs, sensors, cameras, barriers, water treatment plant, airport control tower, solar park
> 
> — Board Member - Risk/Security Committee, Utilities and Energy, 5000+

> The tone is written for someone like me: it doesn't waste time explaining what SCADA or a firewall is, it goes straight to "your infrastructure stays, the connection becomes secure," which assumes I already own the pain of rip-and-replace fights.
> 
> — Chief Information Security Officer, Government and Public Sector, 1001-5000

---

## 05 · The hardest read

An adversarial pass over the findings. Every claim below was checked
against the panel's own answers; unsupported ones were dropped.

- **The page teaches the product but sells nothing, so comprehension converts into no evaluation step** *(high)*
  Ten respondents restated the offer accurately, yet eight flagged no named customer, four cited a missing spec sheet and four disbelieved the latency claim. Understanding without proof produces informed non-buyers.
- **The single hardest number on the page actively damages credibility** *(high)*
  Four respondents read the 1ms latency and telemetry claims as vendor assertion with no baseline, methodology or independent proof. An unsourced performance figure in front of engineers costs more trust than saying nothing.
- **The page fails the only test that matters to this buyer: surviving failure** *(high)*
  Four respondents blocked a purchase decision on missing throughput, MTBF, failover time and failure-mode documentation, and two tied real value specifically to demonstrated failover without dropped traffic. Nothing on the page addresses this.
- **Named customers are the cheapest fix available and their absence is costing full evaluations outright** *(high)*
  Eight respondents flagged the missing customer proof and three said a single reference from a utility, port or airport would move them to full evaluation. The conversion barrier is one logo, not a messaging rewrite.
- **Partner logos without customers signal weakness, not credibility** *(medium)*
  Four respondents inferred a small, unproven vendor precisely from partner logos appearing where customers should be, compounded by no founding date, team page or customer count. The trust asset is reading as a substitute for traction.
- **Mechanism-heavy copy filters out the buyers the page needs most** *(medium)*
  Four respondents said the target buyer was never stated and had to be inferred from visuals, and one flagged the page assumes prior SCADA familiarity — the same insider tone four others read as early-stage engineering-led.

---

## 06 · Who answered

| # | Role | Industry | Company size |
| --- | --- | --- | --- |
| 1 | Chief Risk Officer | Government and Public Sector | 201-500 |
| 2 | Board Member - Risk/Security Committee | Critical Infrastructure | 501-1000 |
| 3 | Director of Cybersecurity | Utilities and Energy | 1001-5000 |
| 4 | VP of Information Security | Transportation and Logistics | 5000+ |
| 5 | Chief Information Security Officer | Manufacturing | 201-500 |
| 6 | CISO | Government and Public Sector | 501-1000 |
| 7 | Chief Risk Officer | Critical Infrastructure | 1001-5000 |
| 8 | Board Member - Risk/Security Committee | Utilities and Energy | 5000+ |
| 9 | Director of Cybersecurity | Transportation and Logistics | 201-500 |
| 10 | VP of Information Security | Manufacturing | 501-1000 |
| 11 | Chief Information Security Officer | Government and Public Sector | 1001-5000 |
| 12 | CISO | Critical Infrastructure | 5000+ |
| 13 | Chief Risk Officer | Utilities and Energy | 201-500 |
| 14 | Board Member - Risk/Security Committee | Transportation and Logistics | 501-1000 |
| 15 | Director of Cybersecurity | Manufacturing | 1001-5000 |

---

## 07 · Before you act on this

The methodology is real, and the critique is directional. What a
simulated persona cannot have is a live budget, a renewal coming up, or
a boss asking about this quarter. **Validate anything you're betting on
with real ICPs who are actually in-market.** Being wrong is more
expensive than you think. Finding out is cheaper than you'd guess.

Wynter runs message testing with verified B2B professionals — trusted
by HubSpot, RingCentral, Shopify, Cognism, Paddle, Veeam, Rippling and
Miro. <https://wynter.com>

This report is kept for 60 days from 2026-08-28, then deleted along with the personas and their answers.

