Skip to content
Viewing: all (23)
  1. David Lowbridge From fixed values to behaviours Brand automationUX & UIDigital strategy
  2. Mike Leonard The web is fun Motion designUX & UITechnical validation
  3. Jara Santamaria Martinez Every year is a new brief PlatformsContent strategyTechnical validation
  4. Kristina Radonjic The work between the work Digital strategyMarketing
  5. Guanglun Wu Choosing the right tech stack Technical validationPlatformsDigital strategy
  6. Barry Cumberlidge Security deep dive Technical validationContent strategyDigital strategy
  7. David Lowbridge Startups are prototypes Digital strategyBrand automation
  8. Tara Heal Shapeshifting the Future UX & UIMarketing
  9. Tom Small The theme is the guardrail Brand automationPlatforms
  10. Barry Cumberlidge Your biggest asset in an RFP, your website SEOContent strategyDigital strategyMarketing
  11. Michael Gunner Cache Components: the right content at the right time PlatformsTechnical validationContent strategy
  12. David Lowbridge From static frames to a creative operating system Brand automationUX & UI
  13. Tom Small We build by leaving things out PlatformsDigital strategyUX & UI
  14. Michael Gunner Standardise the foundations, not the brand experience PlatformsBrand automation
  15. Charlie Clarke Letting type move Motion designUX & UI
  16. Andy Purbrick Putting video back where it belongs PlatformsTechnical validation
  17. Mike Leonard The cache that doubled as a coordinator PlatformsTechnical validation
  18. Andy Purbrick We test the revenue path Technical validationDigital strategy
  19. Mike Leonard Two months in Three.js, we started over Motion designTechnical validation
  20. Rhona Mackay The form we actually trust PlatformsTechnical validation
  21. Andy Purbrick The testbed nobody will see PlatformsTechnical validation
  22. Andy Purbrick Twenty-four modules, one wrapper PlatformsContent strategy
  23. Andy Purbrick We haven’t missed a Thursday in 33 weeks Content strategyMarketing

Security deep dive

Barry Cumberlidge 6 min read Technical validation Content strategy Digital strategy

Security questionnaires now arrive before, during and after the pitch. Your website needs to answer the questions buyers and machines already ask.

Security deep dive

A few weeks ago I wrote about your website being your biggest asset in an RFP. That piece ended on the unglamorous tier: security posture, certifications, compliance, and the information nobody in marketing owns.

Since then, it has sparked conversations inside Made by ON about how security shows up in RFPs and in other purchasing scenarios.

Those conversations kept returning to three core questions. They come from our collective experience across procurement processes in aviation, banking, retail, telecoms, medical technology and more.

What has changed is the variation and stage at which those questions arrive:

  • inside the RFP as scored sections
  • after the pitch as onboarding
  • mid-relationship, when your client’s own customers push due diligence down the chain

Forrester found that 94% of B2B buyers used AI in their most recent purchase1, which means the research that used to arrive as a questionnaire increasingly starts with a machine reading whatever your site says.

This image shows a webpage with a dark background featuring a prominent heading that reads "How we keep your accounts protected."
Start with the questions procurement will ask first: who has access, where data lives, and how protection is handled

So what are the three big questions your site should cover? Who can access it, what you stand behind, and what happens when it breaks.

Who can access our data, and where does it live?

84% of organisations use security questionnaires2 to get answers that give them comfort in the companies they buy from. This is not just for use inside the buyer’s procurement department. It is increasingly required by regulators across the globe.

Rules like DORA, the EU’s Digital Operational Resilience Act3, now force enterprise buyers to prove due diligence across their whole supply chain. That touches data access and hosting, which is why the ask increasingly comes from your customer’s customer.

The right answer depends on what you are.

  • SaaS answers in architecture: tenancy, residency, encryption, and a subprocessor list that is published and current.
  • An AI company answers the training question: where inference happens, which providers sit underneath, and whether customer data trains anything. That last one is now the crucial point for enterprise buyers.
  • A services business answers in people: who touches client material, how access is granted and revoked, and what contractors see.

What certifications do you hold?

This image shows a split-screen with two distinct sections. "Overview" section provides a welcome message and explains the purpose of the Trust Center, emphasizing transparency and trust in security practices. The "Certificates" section displays various certifications, including ISO and SOC compliance badges.
Certification pages need to do more than display badges; they should make the claim, scope and evidence easy to verify

Sales teams often treat certifications as tick-box essentials, but there is depth to earning them and to highlighting them on your website in a meaningful way.

For SaaS, past a certain deal size, System and Organisation Controls 2 (SOC 2)4 is table stakes. It is a voluntary auditing framework created by the American Institute of Certified Public Accountants (AICPA) that evaluates how well a service provider protects customer data. The key information to surface through your website is how easily a buyer can access the report.

For AI companies, the ground is shifting underneath them. The International Organisation for Standardisation has created the first international standard for Artificial Intelligence Management Systems, ISO 420015. In around two years, it has moved from novelty to a procurement requirement in regulated sectors6, providing a formal framework for organisations to responsibly develop, provide or use AI systems.

Our advice: publishing the certification logo is good practice, but the information architecture needs to give space to a dedicated certifications page that explains your position and why these certifications matter to you.

The watch-out, as our Chief Digital Officer Guanglun Wu puts it, is that “certified”, “audited” and “working to the standard of” are three different claims. The one person guaranteed to know the difference is the security reviewer reading your answer. State what you hold, what you do not, and what stands behind the gap. The honesty is itself the signal.

What happens when something goes wrong?

This image shows two screenshots of a website, likely a promotional or informational page for the company Air.
Incident response is part of the trust story: buyers want to know what happens, who acts, and how quickly they hear

Safety engineers have a name for how bad days happen: the Swiss cheese model7. Every defence is a slice of cheese with holes in it, and disaster is the day the holes line up.

The three questions are really asking about your slices. The first measures how big the holes are: who has access. The second asks whether a badge is a whole slice or just the label on one. The third asks what happens on the day the holes align.

A good answer has four parts:

  1. How you would know: detection, because uptime monitoring is not compromise detection. A hacked site can still be up.
  2. Who acts: named by role, not “the team”.
  3. How fast the client hears: and what they see while it is in progress.
  4. What recovery covers: agreed before anything happens, not negotiated mid-incident.

Following the theme of the first two questions, celebrate your incident response approach. Incidents happen. Buyers want to know that you have handled them before and managed them effectively.

The quiet advantage

Industry research suggests up to 75% of vendors8 either do not respond to security questionnaires or fail to do so on time. Most competitors are still deprioritising what is becoming a crucial area of concern for buyers.

A published answer on your website gets ahead of the race before it starts, regardless of the stage those questions now arrive: scored in the RFP, checked at onboarding, or scanned mid-relationship.

Do not underestimate the internal benefit either. When the sales team asks, “What’s our position on this?”, you can educate through the content already published on your website.

Security is arguably the crucial question procurement asks, but it is not the only one. Accessibility has quietly moved from a feature request to a warranty clause in client contracts, and will be the next topic of conversation in an upcoming Field Note.

Footnotes

  1. Forrester, The State of Business Buying, 2026 (Buyers’ Journey Survey, 2025; ~18,000 global buyers). ↩

  2. RiskRecon/Ponemon Institute research, as compiled in Secureframe’s third-party risk statistics roundup, which reports security questionnaires as the most popular method of assessing third-party risk at 84% of respondents. ↩

  3. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. ↩

  4. AICPA, SOC 2 - SOC for Service Organizations: Trust Services Criteria. ↩

  5. ISO/IEC 42001:2023, Information technology - Artificial intelligence - Management system. ↩

  6. Supported by certification announcements through 2025-26, including Microsoft, AWS, Anthropic and CrowdStrike, and reported procurement adoption in financial services and healthcare. ↩

  7. Reason, J. (2000), “Human error: models and management”, BMJ 320:768-770. ↩

  8. Secureframe, 100+ Essential Third-Party Risk Statistics and Trends, which reports that up to 75% of vendors either do not answer security questionnaires or fail to do so in a timely manner. ↩