Case Study
An Industrial Cybersecurity Company
Three acquisitions in four years had left one company running five websites' worth of story on a single domain. I rebuilt the message architecture, the information architecture, and the conversion path around the person who actually starts the search — and demo requests from organic went up 2.4x.
Role
UX Strategy Lead
Timeline
7 months
Team
9 across agency and client
Client
An Industrial Cybersecurity Company
Outcomes
2.4x
Demo requests from organic
Two quarters post-launch against the two before it
340 → 96
Pages in the library
The audit retired everything that could not name its job
−44%
Time to the first product answer
Median seconds from landing to a page that says what the product does
01 — Problem
The company sold operational technology security — the software that watches the industrial control systems inside power plants, refineries, and factory floors. It had grown by buying three companies in four years, and every acquisition arrived with its own product, its own website, and its own vocabulary. All of it had been migrated onto one domain without anyone merging the story. The result was 340 pages, four different names for the same capability, and three incompatible definitions of "asset visibility."
Sales felt it first. Every discovery call opened with twenty minutes of un-confusing the customer before anyone could talk about a problem. Analytics agreed: 61% of organic sessions landed on a legacy product page and left from it. The site had traffic. It had no path.
The brief that came to us said redesign. What the engagement actually had to produce was a decision — the company had never said out loud, in one sentence, what it sells.
02 — Research & Discovery
I started with the content audit, because it is the cheapest way to turn an argument into a fact. Every one of the 340 pages got tagged two ways: which legacy company wrote it, and which job it does — inform, prove, convert, or nothing. 214 pages came back as nothing. That spreadsheet ended a debate that three meetings of opinion had not.
Behavioural data filled in the shape of the failure. GA4 showed entrances scattered across legacy product pages with no onward journey. Clarity showed rage clicks concentrated in a primary navigation whose labels were acquisition names, and scroll maps where visitors bailed above the one sentence that explained what the product did. Search Console showed the company ranking for questions its pages did not answer.
Then the interviews, and the finding that reframed the whole engagement. The buying committee has six roles, and the company had built its entire site for the last one — the CISO who signs. But the search does not start there. It starts with a plant OT engineer who has been told to do something about it, and whose first question is not "what is your architecture" but "will this break my line?" Downtime is the fear that governs everything downstream. The site answered the last question first and never answered the first one at all.
The win/loss read of 41 deals confirmed it from the commercial side: deals were won on operational trust — references from plants that looked like theirs, honest deployment detail — and lost on perceived risk to production. Meanwhile the SERP analysis showed six competitors using the same three abstractions. Nobody in the category was describing an actual plant.
Research activities
03 — Design Process
Project phases — select one
Discovery & audit. 340-page content audit, GA4 and Clarity review, SERP landscape, and 14 stakeholder interviews across three legacy product orgs.
Message architecture came before any layout. I ran a FigJam workshop with the review board and opened it with a silent exercise: everyone writes the company's one-sentence description alone, before anyone speaks. Seven people described six different companies. That artifact did more work than the deck it was buried in, because the problem stopped being a website problem in front of the people who had to fix it.
What came out was a five-beat story spine: the plant is a network now — here is what that costs you — here is what we see that you do not — here is what happens the week it is installed — here is who has already done it. Each top-level page owns exactly one beat, and no two pages compete for the same job. That rule is the whole information architecture in one line.
The IA itself was settled by evidence rather than preference. A card sort with 60 OT and security practitioners produced groupings by environment and by problem — never once by product name. A tree test on two candidate structures put the product-led navigation 22 points behind on findability. That killed a navigation the company had carried for six years, and it killed it with a number, which is the only way that particular decision was ever going to die.
Lo-fi is where I got the homepage wrong in a useful way. My first instinct was a persona selector at the top of the page — "I'm an OT engineer" / "I'm a CISO" — because it looked like it solved the multi-audience problem. It solves nothing. People do not self-identify at speed, and a chooser is a tax you charge a visitor before you have earned anything from them. Testing killed it in an afternoon. What replaced it was a single narrative where each beat carries a side door, so the engineer and the CISO travel the same road and get off at different exits.
Mid-fi is where the wireframes stopped being layouts and became content specifications. Every module carried three things: the question it answers, a word count, and the type of proof required to close it. That is what made real copy possible on an agency schedule — our content strategist wrote to a brief instead of pouring words into a shape.
The last piece was the conversion path. Every page on the old site ended in the same button: Request a demo. That is one rung on a ladder that needs three. I designed the ladder to match intent — read a brief written for your kind of plant, assess your own environment in four minutes, then talk to someone with that context already attached. The middle rung is the one that mattered; it gives a first-time visitor something to do that is not a sales call, and it hands sales a qualified conversation instead of a name.
Sketches and wireframes from the work — click any of them to look closer:
Lo-fi · discovery workshop
The silent one-sentence exercise, then the spine that came out of it. Five product stories became five beats of one story — and the persona selector I sketched at the top of the homepage got crossed out the same week.
Lo-fi · committee journey
The reframe on paper. The old site was built for the person who signs; the search starts with the engineer who has to live with it. Same road, different exits.
Mid-fi · homepage as content spec
Wireframes that stopped being layouts. Every module carries the question it answers, a word count, and the proof type required — which is what let real copy get written on an agency timeline.
Mid-fi · IA and tree test
Two candidate structures, 60 practitioners, one number. Product-led navigation lost findability by 22 points, which is how a six-year-old nav finally died.
From first sketch to shipped interface:
04 — Solution & Outcome
The site launched as one narrative with six top-level sections named for problems rather than products, and 96 pages instead of 340. Product names still exist — they matter to someone already in a deal — but they live one level down, where that person is.
Each capability page opens with a plain 40-to-60 word answer to the question the page is named for, then the evidence underneath it. That structure is doing double duty: it is how a skimming engineer decides whether to keep reading, and it is how an answer engine finds something quotable. Entity naming is consistent across the entire library, so the same capability is called the same thing everywhere, which the old site could not manage across four legacy vocabularies.
The Environment Fit Check is the middle rung of the ladder and the piece I would show first. Nine questions about control system vendor, network segmentation, patch posture, and regulatory regime produce a plain-language readout of where this would deploy cleanly and where it would not, including the cases where the honest answer is that it is a poor fit. It converts better than the demo button it replaced, and it converts better precisely because it is willing to say no.
Key design decisions
The shipped product, view by view:
Hi-fi · Environment Fit Check
The middle rung of the ladder. Nine questions produce a readout that is willing to tell you this is a poor fit — which is exactly why it converts better than the demo button it replaced.
“You didn't redesign our website. You made us decide what we sell.”
— VP of Marketing
05 — Team & Collaboration
The team
9 across agency and client
An agency engagement, so the job had two halves. Half was owning the UX artifacts. The other half was being the person in the room who could defend a recommendation to a VP with something other than taste. I wrote the message architecture alongside our content strategist rather than handing her a wireframe with lorem in it — by the time visual design started, every module on the page had a word count and a question it was responsible for answering.
06 — Reflection
The hardest deliverable on this project was not a wireframe. It was a sentence. Everything downstream — navigation labels, page count, what the homepage does in its first screen — fell out of the company finally agreeing on what it sells, and no amount of layout craft would have produced that agreement on its own.
The persona selector is the mistake I keep. It was a genuinely reasonable-looking idea that failed for a reason worth internalising: any control that asks the visitor to do work before the page has given them anything is a toll booth. Multi-audience is a content problem wearing an interface costume.
The thing I would carry into any agency room: bring the least arguable artifact first. The audit spreadsheet, the silent one-sentence exercise, the 22-point tree test gap — those are not deliverables anyone gets excited about, but they are what let a strategy recommendation survive a six-person review board with three legacy loyalties in it. Opinion is expensive to defend. Evidence is cheap.
Tools Used
Working on something like this?