Every year is a new brief

Every year is a new brief

The London Design Festival gets a new identity every year. The website has to keep up with it, and with everything else the festival becomes. The London Design Festival website wasn’t broken. It was doing exactly what it had been built to do, which was to let partners publish most of the site...

Engineering
Strategy
15h ago
The work between the work

The work between the work

Process can be standardised. Judgement cannot. I’ve spent most of my career around client and project management, both in-house and agency-side, and lately I’ve been noticing how much of doing it well comes down to knowing when a process needs to change. Timelines, budgets and resources still...

Studio
9d ago
Security deep dive

Security deep dive

Security questionnaires now arrive before, during and after the pitch. Your website needs to answer the questions buyers and machines already ask. A few weeks ago I wrote about your website being your biggest asset in an RFP. That piece ended on the unglamorous tier: security posture,...

Studio
22d ago
Shapeshifting the Future

Shapeshifting the Future

Every year we open our doors for a week to a student trying to find their way into the industry. Not work experience in the shadowing-only sense but a real placement, with a real brief. We do the same for a roomful of UCL students, in the studio for an afternoon. From the outside, a career in this...

Studio
1mo ago

Your biggest asset in an RFP, your website

Your biggest asset in an RFP, your website. I’ve spent most of my career in B2B, and at Made by ON I spend my weeks talking to leaders of the world’s most exciting B2B businesses. Lately those conversations keep circling one question, which I put to our strategists and UX team: what happens when...

Studio
2mo ago
From static frames to a creative operating system

From static frames to a creative operating system

Looking beyond the flashy generative UI, shader effects and animation features at Figma Config signaled a deeper, more structural shift: the transition from a static repository of files and rules into a behavioural operating system. I left San Francisco with a camera roll of screenshots and pages...

Design
Engineering
2mo ago
Choosing the right tech stack

Choosing the right tech stack

Here at ON, we intentionally cast a wide net on the technologies that we work with. Across websites, web apps, native apps, installations, and platforms, we don’t tie ourselves to just one, because we recognise that there’s no such thing as “best”, but rather matching the right choices to the...

Engineering
Strategy
15d ago
Startups are prototypes

Startups are prototypes

A startup isn’t just an early-stage company. It’s a mechanism to reduce uncertainty. Every early customer, product release and funding round exists to answer one question: have we learned enough to justify the next investment? A startup is essentially a super complex prototype designed to validate...

Strategy
30d ago
The theme is the guardrail

The theme is the guardrail

WordPress can now describe itself to machines. WordPress 7.0 landed back in May with AI infrastructure in core. There’s an AI Client, a Connectors screen where the provider keys live, and the Abilities API, which actually arrived back in 6.9. Abilities are how core, plugins and themes describe what...

Engineering
1mo ago
Cache Components: the right content at the right time

Cache Components: the right content at the right time

Cast your mind back to the earlier days of the world wide web. A website was essentially a digital document, the web a library, and the internet the mechanism of delivery. Updating a document meant editing HTML on your computer and uploading it to a server by hand, usually over FTP. In 1995 PHP...

Engineering
2mo ago

Security deep dive

Barry CumberlidgeBarry Cumberlidge Studio
20 August 2026
6 min
Security deep dive

Security questionnaires now arrive before, during and after the pitch. Your website needs to answer the questions buyers and machines already ask.

A few weeks ago I wrote about your website being your biggest asset in an RFP. That piece ended on the unglamorous tier: security posture, certifications, compliance, and the information nobody in marketing owns.

Since then, it has sparked conversations inside Made by ON about how security shows up in RFPs and in other purchasing scenarios.

Those conversations kept returning to three core questions. They come from our collective experience across procurement processes in aviation, banking, retail, telecoms, medical technology and more.

What has changed is the variation and stage at which those questions arrive:

  • inside the RFP as scored sections
  • after the pitch as onboarding
  • mid-relationship, when your client’s own customers push due diligence down the chain

Forrester found that 94% of B2B buyers used AI in their most recent purchase1, which means the research that used to arrive as a questionnaire increasingly starts with a machine reading whatever your site says.

This image shows a webpage with a dark background featuring a prominent heading that reads "How we keep your accounts protected." Start with the questions procurement will ask first: who has access, where data lives, and how protection is handled.

So what are the three big questions your site should cover? Who can access it, what you stand behind, and what happens when it breaks.

Who can access our data, and where does it live?

84% of organisations use security questionnaires2 to get answers that give them comfort in the companies they buy from. This is not just for use inside the buyer’s procurement department. It is increasingly required by regulators across the globe.

Rules like DORA, the EU’s Digital Operational Resilience Act3, now force enterprise buyers to prove due diligence across their whole supply chain. That touches data access and hosting, which is why the ask increasingly comes from your customer’s customer.

The right answer depends on what you are.

  • SaaS answers in architecture: tenancy, residency, encryption, and a subprocessor list that is published and current.
  • An AI company answers the training question: where inference happens, which providers sit underneath, and whether customer data trains anything. That last one is now the crucial point for enterprise buyers.
  • A services business answers in people: who touches client material, how access is granted and revoked, and what contractors see.

What certifications do you hold?

This image shows a split-screen with two distinct sections. "Overview" section provides a welcome message and explains the purpose of the Trust Center, emphasizing transparency and trust in security practices. The "Certificates" section displays various certifications, including ISO and SOC compliance badges. Certification pages need to do more than display badges; they should make the claim, scope and evidence easy to verify.

Sales teams often treat certifications as tick-box essentials, but there is depth to earning them and to highlighting them on your website in a meaningful way.

For SaaS, past a certain deal size, System and Organisation Controls 2 (SOC 2)4 is table stakes. It is a voluntary auditing framework created by the American Institute of Certified Public Accountants (AICPA) that evaluates how well a service provider protects customer data. The key information to surface through your website is how easily a buyer can access the report.

For AI companies, the ground is shifting underneath them. The International Organisation for Standardisation has created the first international standard for Artificial Intelligence Management Systems, ISO 420015. In around two years, it has moved from novelty to a procurement requirement in regulated sectors6, providing a formal framework for organisations to responsibly develop, provide or use AI systems.

Our advice: publishing the certification logo is good practice, but the information architecture needs to give space to a dedicated certifications page that explains your position and why these certifications matter to you.

The watch-out, as our Chief Digital Officer Guanglun Wu puts it, is that “certified”, “audited” and “working to the standard of” are three different claims. The one person guaranteed to know the difference is the security reviewer reading your answer. State what you hold, what you do not, and what stands behind the gap. The honesty is itself the signal.

What happens when something goes wrong?

This image shows two screenshots of a website, likely a promotional or informational page for the company Air. Incident response is part of the trust story: buyers want to know what happens, who acts, and how quickly they hear.

Safety engineers have a name for how bad days happen: the Swiss cheese model7. Every defence is a slice of cheese with holes in it, and disaster is the day the holes line up.

The three questions are really asking about your slices. The first measures how big the holes are: who has access. The second asks whether a badge is a whole slice or just the label on one. The third asks what happens on the day the holes align.

A good answer has four parts:

  1. How you would know: detection, because uptime monitoring is not compromise detection. A hacked site can still be up.
  2. Who acts: named by role, not “the team”.
  3. How fast the client hears: and what they see while it is in progress.
  4. What recovery covers: agreed before anything happens, not negotiated mid-incident.

Following the theme of the first two questions, celebrate your incident response approach. Incidents happen. Buyers want to know that you have handled them before and managed them effectively.

The quiet advantage

Industry research suggests up to 75% of vendors8 either do not respond to security questionnaires or fail to do so on time. Most competitors are still deprioritising what is becoming a crucial area of concern for buyers.

A published answer on your website gets ahead of the race before it starts, regardless of the stage those questions now arrive: scored in the RFP, checked at onboarding, or scanned mid-relationship.

Do not underestimate the internal benefit either. When the sales team asks, “What’s our position on this?”, you can educate through the content already published on your website.

Security is arguably the crucial question procurement asks, but it is not the only one. Accessibility has quietly moved from a feature request to a warranty clause in client contracts, and will be the next topic of conversation in an upcoming Field Note.

Footnotes

  1. Forrester, The State of Business Buying, 2026 (Buyers’ Journey Survey, 2025; ~18,000 global buyers).

  2. RiskRecon/Ponemon Institute research, as compiled in Secureframe’s third-party risk statistics roundup, which reports security questionnaires as the most popular method of assessing third-party risk at 84% of respondents.

  3. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector.

  4. AICPA, SOC 2 - SOC for Service Organizations: Trust Services Criteria.

  5. ISO/IEC 42001:2023, Information technology - Artificial intelligence - Management system.

  6. Supported by certification announcements through 2025-26, including Microsoft, AWS, Anthropic and CrowdStrike, and reported procurement adoption in financial services and healthcare.

  7. Reason, J. (2000), “Human error: models and management”, BMJ 320:768-770.

  8. Secureframe, 100+ Essential Third-Party Risk Statistics and Trends, which reports that up to 75% of vendors either do not answer security questionnaires or fail to do so in a timely manner.

Aug 2026

A black-and-white ship on ice beside a portrait of Alfred Wegener seated at a desk

Drift

In 1912 Alfred Wegener told a room of geologists that the continents move. He was right. The one thing he couldn’t explain was how, and it took half a century of sonar and magnetometers, instruments that read the magnetism in rock, to prove it.

Jul 2026

One of the 214 hand-drawn sheets of Inō’s map of Japan, and his team surveying Mitarai in 1806

Measure

In 1800 a retired sake brewer named Inō Tadataka set out to walk Japan’s coast. He spent 17 years and 35,000 km on foot, and died before the work was done. His team finished the first accurate map of Japan in 1821, and it stayed in use for a century.

Jun 2026

William Badcock, A Touch-stone for Gold and Silver Wares (1677)

Hallmark

The word hallmark comes from an actual hall, Goldsmiths’ Hall in London, where since 1300 silver has been tested against the sterling standard and struck with the hall’s mark, so you could trust it without knowing the maker.

May 2026

Alan Kay: His Sketches, Piano, and Computer

Notes

A note can be a written record, a struck key, or the act of noticing, and each sharpens how we understand the world. A piano is an instrument, but also a technology built on the notes it makes possible.

Apr 2026

Photographs of a red cloth bound travel handbook from 1894. The book is open to show pages with maps and illustrations.

Change

A red cloth spine caught my eye in a Tokyo bookshop last week. A handbook for travellers in Japan, fourth edition, 1894. I was 132 years late, yet most of what it describes still stands.

Mar 2026

Screenshots from the development process of the new ON release notes page

Taking the temperature

You walk into a room and you can feel it. Whether there is energy or not. We describe someone as warm. We talk about things cooling down. Temperature is something we sense before we have words for it.

Feb 2026

Pixelised image of a horse running

Rethinking video, prototyping faster, and encoding brand logic

In Japanese, the character for hand is 手. Joined with the character for craft, it becomes 手仕事 (teshigoto), or handwork.

Want to know more?

On the last Sunday of every month, we share insights on creative thinking, emerging tools, technology.