# Message test — https://upguard-pages.web.app/roc/

After reading your page, 11 of 15 personas could name a reason to pick you over a similar option.

- **Page tested:** https://upguard-pages.web.app/roc/
- **Audience tested against:** Information Security Directors, Information Security leadership

Sizes with 200 or more employees in the US and UK
- **Personas:** 15 simulated
- **Report:** https://grader.wynter.com/r/upguard-pages-web-app-roc-nFPpyBs

> These answers are generated by AI, scored on Wynter's B2B Message
> Layers framework using behaviorally-diverse simulated personas. The
> methodology is real and the critique is directional. What a simulated
> persona cannot have is a live budget, a renewal coming up, or a boss
> asking about this quarter.

---

## 01 · The scores

Every persona answered all four questions. These are four independent
proportions of the same panel, not stages of a funnel.

| Layer | Question | Cleared the bar | Strength | Of those who passed |
| --- | --- | --- | --- | --- |
| 1. Clarity | Do they understand what you do? | 15/15 | 78% | all with reservations |
| 2. Relevance | Can they tell what it solves, and who it's for? | 15/15 | 78% | all with reservations |
| 3. Value | Do they actually want it? | 13/15 | 70% | all with reservations |
| 4. Differentiation | Is there a reason to pick you over the alternatives? | 11/15 | 63% | all with reservations |

**Brand alignment** (a side metric, not one of the four layers) — 15/15, 78% strength (all with reservations). Does the page read like the company you actually are?

**Fix first: Differentiation.** Earliest failing layer, walking the sequence in order — not simply the lowest score.

---

## 02 · What to change, layer by layer

Ordered worst-first. Specific edits, not a restatement of the score.

### Differentiation

**Source the SOC-analyst-days and questionnaire figures with method and sample.**

The Proof block asks readers to accept "300+ SOC-analyst days saved per customer, per year" and "95% faster security questionnaires with AI Autofill" with nothing beside them — no customer count, no baseline, no time period. Readers flagged these as marketing aggregates rather than evidence, and one said the unsourced round numbers made them doubt the tighter claims elsewhere. Add a one-line footnote under the stat row naming how it was measured: how many customers, what period, measured…

*effort medium · impact high · tested against Proof next to the claim*

**Add a regulated-industry customer alongside Chemist Warehouse and Anglo-Eastern.**

The only named customers are retail pharmacy and ship management, so a security leader in financial services, healthcare or manufacturing reads the evidence as belonging to someone else's industry. The DORA and CPS 230 references in the PROVE pillar imply financial-services customers exist — name one, with the same kind of concrete outcome the Chemist Warehouse quote carries. If a logo cannot be named, use "Head of Information Security, [sector] firm" the way the payments-company quote already…

*effort medium · impact high · tested against Proof next to the claim*

**Rewrite "Compounding Intelligence" line to say what connecting actually produces.**

"Point tools add up. UpGuard compounds… We call it Compounding Intelligence" invents a term instead of demonstrating the mechanism, which is why readers concluded the product is TPRM, ASM and identity risk bundled rather than genuinely connected. Replace the coined name with one concrete cross-domain example: a leaked credential at a vendor matched to an exposed asset and an employee account, and what the platform does with that link. Show the join, and the bundling objection answers itself.

*effort medium · impact high · tested against Concrete over abstract*

**Attach the G2 ranking to review count and category.**

"Ranked #1 on G2 for third-party risk management, 12 consecutive quarters" is read as an unverifiable badge, not a differentiator — five badge images with no numbers behind them make it worse. Either state what sits behind the ranking (number of reviews, average rating, the specific G2 grid and segment) and link it, or demote it below the customer quotes so it is not carrying the proof section. A ranking with a review count and a link is checkable; a badge row is decoration.

*effort low · impact medium · tested against Proof next to the claim*

### Value

**Offer a demo against the reader's own vendor questionnaires.**

The numbers create interest but stop short of conviction — readers want to see 220 questions answered against their questionnaires, verify the 68% dismissal rate on their own attack surface, or talk to a peer. The page's next action should say so explicitly: a demo run on your own questionnaire set and your own domains, not a generic "book a demo". Naming what the demo will use makes the testable claims testable.

*effort low · impact high · tested against One clear next action*

---

## 03 · What is working

### The consolidation story — three risk domains, one platform — is what everyone reads back

Nine respondents described the offering in near-identical terms: vendor/third-party risk, attack surface, and workforce/insider risk pulled into a single platform or dashboard. This is the one message that transmitted intact without prompting. It is the page's most reliable asset.

> It's a consolidated cyber risk platform covering third-party/vendor risk, attack surface monitoring, and workforce/identity risk in one place
> 
> — Vice President of Information Security, Technology, 201-500

> consolidated cyber risk management platform that pulls together third-party/vendor risk, attack surface monitoring, and workforce/identity risk into one place so you're not juggling separate point tools
> 
> — Information Security Director, Retail, 501-1000

> It's a third-party/cyber risk platform that bolts together vendor risk assessment, attack surface monitoring, and workforce/identity risk into one dashboard, with AI doing the questionnaire and triage grunt work.
> 
> — Senior Information Security Director, Manufacturing, 1001-5000

> basically an attempt to replace three separate point tools (ratings tool, dark web feed, TPRM software) with one fused signal source
> 
> — Director of Information Security, Financial Services, 5000+

> the real change would be consolidating three separate workstreams — vendor assessments, attack surface monitoring, and workforce/identity risk — into one place
> 
> — Head of Information Security, Healthcare, 201-500

> It's a consolidated cyber risk platform stitching together third-party/vendor risk management, attack surface monitoring, and workforce/identity risk (shadow AI, leaked credentials) into one "Risk Operations Center" — plus a questionnaire/trust-exchange piece for compliance evidence.
> 
> — Information Security Leader, Technology, 501-1000

> one dashboard that replaces your vendor questionnaires, attack surface scans, and dark web credential alerts, and stitches them together so you're not chasing three separate tools.
> 
> — Vice President of Information Security, Retail, 1001-5000

### The problem statement and intended audience land within the first screen

Six respondents said the pain point, the three risk areas, and the implied buyer — security leaders with board accountability and tool-consolidation pressure — were clear immediately, several citing the column breakdown on the first screen. Nobody reported confusion about who the page is for.

> the "Your risk is in three places at once. Your tools aren't." line up top plus the three-column split into Supply chain/Attack surface/Workforce told me exactly what pain this addresses within seconds
> 
> — Information Security Director, Retail, 501-1000

> the "Your risk is in three places at once. Your tools aren't." line and the three-column breakdown (supply chain / attack surface / workforce) told me the problem within the first few seconds
> 
> — Director of Information Security, Financial Services, 5000+

> "Your risk is in three places at once. Your tools aren't" — that's the second line on the page, and it immediately frames the pain as fragmented tooling across supply chain, attack surface, and workforce risk.
> 
> — Information Security Leader, Healthcare, 5000+

> between "your board, auditors, and customers accept" and the security-leader quotes, it's obviously someone like me - a security leader juggling vendor risk, attack surface, and workforce risk
> 
> — Vice President of Information Security, Retail, 1001-5000

> the "Your risk is in three places at once" line and the three buckets (supply chain, attack surface, workforce) tell you the problem in the first screen
> 
> — Information Security Director, Manufacturing, 5000+

### The 220-question / 85%-in-4-minutes stat is the number respondents singled out and want…

Four respondents named the questionnaire automation metric specifically, calling it the key decision metric and a testable claim. Two others pointed to the 68% noise reduction figure the same way. These quantified claims are doing the persuasive work, and respondents treated them as verifiable rather than as marketing.

> the specific numbers like "220 questions, 85% answered in 4 minutes" and "<60s to generate an instant vendor risk assessment" are the kind of concrete claim that would actually change my Friday.
> 
> — Senior Information Security Director, Manufacturing, 1001-5000

> Honestly, it's the questionnaire number holding up under our own vendor list — if a real trial gets anywhere near that 85%-in-4-minutes result on our actual backlog, that's the outcome that justifies pulling my team off three tools
> 
> — Director of Information Security, Financial Services, 5000+

> The "220 questions, 85% answered in 4 minutes" line is the one thing that would pull me toward shortlisting it over a straight ratings tool, because it's a concrete, checkable number rather than a marketing adjective
> 
> — Head of Information Security, Healthcare, 201-500

---

## 04 · What the personas said

### Unsourced stats, especially the G2 ranking and SOC-days-saved figures, actively cost the…

Four respondents flagged aggregate marketing statistics as lacking transparent methodology, and one said the unsourced numbers undermine trust in the concrete claims elsewhere on the page. Only one respondent treated the G2 ranking across 12 quarters as a credible differentiator; the rest read it as unverifiable.

> everything unsourced sitting right next to those — "45,000+ companies," "300+ SOC-analyst days saved," "100B+ signals fused per day" — no methodology, no customer count behind the average
> 
> — Vice President of Information Security, Technology, 201-500

> "Ranked #1 on G2 for third-party risk management, 12 consecutive quarters" line is the one thing here that would actually move the needle
> 
> — Head of Information Security, Financial Services, 1001-5000

> "#1 on G2 for 12 consecutive quarters" and the "300+ SOC-analyst days saved per customer per year" stat do nothing for me — no baseline, no methodology, could mean anything
> 
> — Head of Information Security, Healthcare, 201-500

### Customer proof does not cover respondents' own industries

Respondents noted the named examples are retail and shipping only, with no financial services peers, no healthcare logos, and no manufacturing reference. Absent same-industry proof, several treated the customer evidence as not applicable to them.

> the only two customer quotes I get are Chemist Warehouse and Anglo-Eastern — retail and shipping, not a financial services peer my board would recognize
> 
> — Director of Information Security, Financial Services, 5000+

### The absence of healthcare and industry-specific compliance signals reads as poor fit for…

Four respondents pointed to missing HIPAA, HITRUST or DSPT certifications and absent healthcare focus, and one said the EU regulatory references feel bolted on rather than native. One also said the brand skews infrastructure and government with no retail-specific messaging. The compliance story is being read as generic rather than sector-credible.

> nothing here mentions HIPAA, DSPT, or CQC, which I'd want to see if they're serious about our sector
> 
> — Head of Information Security, Healthcare, 201-500

> the DORA/NIS2 nods feel like they were added for UK/EU credibility rather than being native to the pitch
> 
> — Senior Information Security Director, Financial Services, 201-500

> it's not written for retail specifically — no retail-specific risk (POS breaches, seasonal vendor surges, PCI) gets a mention, and the named logos skew infrastructure/tech/government
> 
> — Information Security Leader, Retail, 5000+

> A named healthcare logo my size — not just PagerDuty or NSW Government — plus a line on HIPAA/HITRUST alongside the SOC 2/DORA list, and a plain statement of what it replaces versus bolts onto so I'm not guessing at a scoping call.
> 
> — Information Security Leader, Healthcare, 5000+

### Respondents read the platform as bundling of existing tools, not a new category, and one…

Three respondents characterised the product as a bundle of TPRM, ASM and identity/insider risk rather than something new, and two framed the vendor as an established TPRM player repositioning upward. One said the page argues about category positioning instead of letting the product speak.

> strip the marketing language and it's TPRM plus attack surface management plus identity risk monitoring, unified
> 
> — Head of Information Security, Financial Services, 1001-5000

> mid-to-late-stage vendor that's grown past pure TPRM/ratings roots and is now repositioning as a broader platform
> 
> — Senior Information Security Director, Financial Services, 201-500

> the page itself half-admits that by spending a whole section arguing "isn't this just TPRM/a ratings tool/dark web feed"
> 
> — Head of Information Security, Financial Services, 1001-5000

> The "45,000+ companies" claim, the "decade of first-party risk signal," and the G2 "#1 for third-party risk management, 12 consecutive quarters" all point to a company maybe 10-15 years in, well past product-market fit, now trying to reposition from a point tool (probably started as vendor risk/ratings) into a broader platform play
> 
> — Information Security Leader, Healthcare, 5000+

### Nobody accepted the numbers on the page alone — value is contingent on a demo or peer…

Five respondents said they would need a live demo against their own vendor questionnaires, false-positive verification, an audit proof, or a peer reference call before acting. One added that the whole value case depends on whether the attack surface and workforce modules are actually good. The claims generate interest but not conviction.

> the marginal case rests entirely on the attack surface and workforce/shadow-AI pieces actually being good, not just bolted on
> 
> — Vice President of Information Security, Technology, 201-500

> I'd walk in asking for a live demo against our actual vendor list and attack surface, not a canned pitch — if they can't show the AI's sourcing and false-positive rate on our data, I'm out
> 
> — Head of Information Security, Financial Services, 1001-5000

> One reference call with a manufacturing peer our size who actually ripped out three tools for this and can show the AI's questionnaire answers held up under audit without them getting burned — that's the only thing that gets this onto my roadmap this quarter.
> 
> — Senior Information Security Director, Manufacturing, 1001-5000

> The "220 questions, 85% answered in 4 minutes" quote is the kind of specific I'd want replicated in a demo with our actual vendor questionnaires before I believe it.
> 
> — Information Security Leader, Technology, 501-1000

> the "220 questions, 85% answered, in 4 minutes" line is the one that would actually save headcount hours if it's real. That's a legitimate workload argument, not just a nice-to-have, so yes, it's worth a meeting.
> 
> — Information Security Leader, Healthcare, 5000+

---

## 05 · The hardest read

An adversarial pass over the findings. Every claim below was checked
against the panel's own answers; unsupported ones were dropped.

- **The page's own statistics are split into two classes and the bad ones are contaminating the good ones. ** *(high)*
  Four respondents flagged the G2 ranking and SOC-days-saved figures as unsourced, and one said those numbers undermine trust in the concrete claims elsewhere on the page — the same page where four respondents named the 220-question/85%-in-4-minutes metric and two named the 68% noise reduction as the persuasive, testable claims. The page is spending the credibility of its best numbers to prop up its weakest.
- **Nothing on the page converts. Every respondent who engaged with the value case deferred the decision offsite.** *(high)*
  Five respondents said they need a live demo against their own questionnaires, false-positive verification, an audit proof, or a peer reference call before acting; one said the entire value case hinges on whether the attack surface and workforce modules are actually good. Against that, one respondent found the G2 ranking credible. The page produces interest and zero conviction.
- **The proof section is a liability, not an asset: it names industries the reader isn't in and omits the certifications the reader needs.** *(high)*
  Named customers are retail and shipping only — no financial services, healthcare or manufacturing reference — and four respondents pointed to missing HIPAA, HITRUST or DSPT certifications, with one calling the EU regulatory references bolted on. One respondent also noted the brand skews infrastructure and government with no retail messaging, meaning even the retail logos aren't supported by the surrounding copy.
- **The one message that transmits intact is a message the page cannot defend.** *(high)*
  Nine respondents read back the consolidation story — three risk domains, one platform — but three respondents characterised that same platform as a bundle of TPRM, ASM and identity/insider risk rather than something new, two framed the vendor as an established TPRM player repositioning upward, and one said the whole value case depends on whether the attack surface and workforce modules are actually good. The page's most reliable asset lands as repackaging.
- **The page argues its positioning instead of proving it, and respondents noticed the substitution.** *(medium)*
  One respondent said the page argues about category positioning instead of letting the product speak, and three read the product as a bundle rather than a new category — while the numbers that actually persuaded four to six respondents were narrow operational metrics, not category claims. The category argument is consuming space the product proof needs.
- **Clarity on the first screen is being wasted because the rest of the page cannot support the buyer it attracts.** *(medium)*
  Six respondents said the pain point, three risk areas and implied buyer — security leaders with board accountability — landed immediately with no confusion. That same buyer then finds no same-industry customer proof, no HIPAA/HITRUST/DSPT signals, and unsourced aggregate stats. The page qualifies people efficiently and then fails them.

---

## 06 · Who answered

| # | Role | Industry | Company size |
| --- | --- | --- | --- |
| 1 | Head of Information Security | Financial Services | 1001-5000 |
| 2 | Information Security Leader | Healthcare | 5000+ |
| 3 | Vice President of Information Security | Technology | 201-500 |
| 4 | Information Security Director | Retail | 501-1000 |
| 5 | Senior Information Security Director | Manufacturing | 1001-5000 |
| 6 | Director of Information Security | Financial Services | 5000+ |
| 7 | Head of Information Security | Healthcare | 201-500 |
| 8 | Information Security Leader | Technology | 501-1000 |
| 9 | Vice President of Information Security | Retail | 1001-5000 |
| 10 | Information Security Director | Manufacturing | 5000+ |
| 11 | Senior Information Security Director | Financial Services | 201-500 |
| 12 | Director of Information Security | Healthcare | 501-1000 |
| 13 | Head of Information Security | Technology | 1001-5000 |
| 14 | Information Security Leader | Retail | 5000+ |
| 15 | Vice President of Information Security | Manufacturing | 201-500 |

---

## 07 · Before you act on this

The methodology is real, and the critique is directional. What a
simulated persona cannot have is a live budget, a renewal coming up, or
a boss asking about this quarter. **Validate anything you're betting on
with real ICPs who are actually in-market.** Being wrong is more
expensive than you think. Finding out is cheaper than you'd guess.

Wynter runs message testing with verified B2B professionals — trusted
by HubSpot, RingCentral, Shopify, Cognism, Paddle, Veeam, Rippling and
Miro. <https://wynter.com>

This report is kept for 60 days from 2026-08-21, then deleted along with the personas and their answers.

