The start: the right content for the wrong reader
Cyber Data Services delivers cyber security, data protection and compliance as a division of Stiperstone Group. Its content problem is the one almost every security business has.
Security content gets written by people who understand security. That produces pages that are accurate, thorough and completely wrong for the person holding the budget, because that person is usually not technical. They are an operations director with a client security questionnaire due on Friday, or a finance director whose insurer has just added a condition to the renewal.
They are not evaluating your methodology. They are trying to work out whether you can make a specific problem go away before a specific date.
The reader we actually wrote for
The signatory. The person who will put their name to the statement that the business is compliant, and who has to be able to explain the decision to somebody else.
That changes almost every content decision. It means leading with the framework name, because that is the word on their paperwork. It means answering what it requires and what you do about it before explaining how. And it means every page has to survive being forwarded to a colleague without a covering explanation.
The middle: what we actually built
1. Organise by framework, not by capability
Cyber Essentials. ISO 27001. Data protection. These are the words on the questionnaire the buyer is holding, so these are the entry points. A page titled after your service offering asks the reader to translate. A page titled after their obligation does not.
2. Answer first, explain second
Each key page opens with the question in the words somebody would actually type and answers it in the first two sentences. The supporting detail follows for the reader who wants it.
This is partly a readability decision and increasingly a visibility one. Answer engines lift direct answers, and they lift them from the top of a page. Content that spends three paragraphs clearing its throat does not get quoted.
3. Build the fullest machine layer in the estate
This is the most thoroughly marked-up of the four sites: eleven structured data types on the homepage alone, including geo coordinates and speakable markup. Speakable exists specifically to tell an answer engine which passage is the quotable answer.
For a security firm this matters disproportionately. Compliance questions are exactly the sort of thing people now put to an assistant rather than a search box, and the firms that get named in those answers are the ones whose machine layer makes them easy to name.
4. Give the person in trouble their own route
Not everyone arriving is researching. Some are mid-incident, and that visitor is the highest intent person who will land on the site all week. They get a visible emergency route from every page rather than being funnelled through a services journey written for somebody calm.
5. Keep every claim verifiable
Accreditations are named and current, and nothing is implied that is not held. In most sectors an overstated credential is a risk. In security it is close to a certainty of being caught, because verifying credentials is exactly what the buyer does for a living.
6. Ship it static
All 42 pages are server-rendered. Nothing that matters waits on JavaScript. A security business whose own site is slow or fragile is making an argument against itself, and in this sector prospects do look.
The end: what it left them with
42 pages aimed at the person who signs rather than the person who implements, with the strongest structured data and answer-engine coverage of the four sites we built for the group, and an honest accreditation story that holds up to the checking this sector guarantees.