Your website reads like an academic paper

Phill Keaney-BollandPhill Keaney-Bolland· Co-founder and Designer, Yaya6 min read

Key takeaways

  • The majority of the 77 startup websites we scored require a post-graduate reading level, as hard to read as an academic paper.
  • Behavioral research shows visitors skim and scroll at speed, more like flies trying to find a way out of a room than PhD students in a library.
  • In our CISO research, concrete plain descriptions beat abstract clever ones in every live messaging test.
  • Your homepage must survive being forwarded to a CFO who is not your audience.
  • Plain language is not dumbing down; it is one idea per section, jargon translated on arrival, and headings that carry the argument.

Here is a test you can run on your own website in two minutes. Paste your homepage copy into any Flesch-Kincaid readability checker and look at the grade level it returns. If you are a cybersecurity startup, the odds are it will tell you that comfortably reading your marketing requires a post-graduate education.

We know, because we measured the category. For our Cult Products Awards report we scored the 77 startups exhibiting at RSA's Early Stage Expo and Next Stage, and as part of that work we ran Flesch-Kincaid grade-level analysis on the Home, About, Product, and Blog pages of 72 of them. The median site demands a postgraduate reading level. In plain terms, they are as hard to read as an academic paper.

That would be defensible if visitors read websites the way examiners read papers. They do not.

How people actually read your site#

Behavioral research on web reading, the accumulated evidence from screen recordings, eye tracking, and heatmaps, tells a consistent story. Visitors do not read. They skim. They scroll at speed, bounce between headings, sample the first words of a paragraph, and click through the moment something looks more promising.

The line we used in the report is worth repeating because it reframes the whole problem: users behave much more like flies trying to find a way out of a room than PhD students in a library.

Now put the two findings together. The category is writing for the PhD student. The visitor is the fly. A wall of dense, subordinate-clause prose does not slow a skimming reader down and make them concentrate. It bounces them to the next tab, where a competitor may have made understanding easier.

Complexity is not credibility#

The dense prose is not an accident. It is a choice, driven by a belief that runs deep in technical founders: sounding sophisticated builds trust with a sophisticated audience. Write simply, the fear goes, and CISOs will assume the product is simple too.

Our CISO research says the opposite. In the live messaging tests we have run with security buyers, concrete plain descriptions have beaten abstract clever ones every time. On the Aizome drafts, both reviewers independently preferred the concrete option and both bounced off the abstract one. The buyers doing the judging were exactly the audience the dense prose was written to impress: senior, technical, deeply experienced. They did not reward the complexity. They punished it.

The explanation is not that security buyers cannot handle difficult text. They are among the most educated buyers in software. The explanation is that they are time-poor. A CISO evaluating vendors is skimming dozens of sites in stolen minutes between meetings. Prose that takes effort to decode is not a signal of depth in that context. It is a tax, and the reader declines to pay it.

It is worth being honest about how the register happens, because nobody sets out to write an unreadable homepage. The copy starts closest to the product, drafted by the people who understand it best. Then it passes through review, and every reviewer who prizes precision adds a qualifier, a dependent clause, a term of art. Each edit is individually defensible. The sum is a paragraph only its authors can skim. The grade level is not a personality trait of your company. It is the residue of a process, which means a process can remove it.

Complexity is not credibility. Making a hard thing easy to understand is the credibility move, because it proves you understand it yourself.

The reader you forgot about#

There is a second reader your prose has to survive, and they never appear in your persona documents.

Security buying is bottom-up. A practitioner discovers you and becomes the champion. The CISO gathers consensus and sponsors the spend. And then the link reaches someone in finance who does not know what your acronyms mean, does not care about your architecture, and holds a real vote. They will judge you on how quickly the page makes sense.

See it in action.

Your website must survive being forwarded to someone who is not your audience. Post-graduate prose fails that test by definition. The champion who wants to advocate for you internally is handed a page they have to translate before they can share it, which means most of the time they simply do not share it. Plain language is not a concession to the least technical reader. It is the thing that lets your most technical reader sell you onward.

How to fix it without dumbing down#

The objection arrives on schedule: our product is genuinely complex, and simplifying the language will misrepresent it. This confuses two different things. Dumbing down removes the substance. Plain language changes the delivery and keeps every bit of the substance. Here is what the second one looks like in practice.

One idea per section#

Most dense pages are dense because they are trying to say four things at once. Give every section a single job. If a paragraph is carrying two ideas, it is two paragraphs. The reader skimming your page should be able to name what each section is about from its first line.

Translate jargon the moment it appears#

You do not have to avoid technical terms. You have to pay for them on arrival. The first time a term of art appears, spend a clause saying what it means in ordinary words. Experts skip past the translation at no cost. Everyone else stays in the room. The pages that lose readers are the ones that spend that trust nowhere and assume the vocabulary is shared.

Short declaratives#

Long sentences are where readability goes to die, because grade-level scores are largely a function of sentence length and word length. Cut the qualifiers. Break the compound sentences. Say the thing, stop, then say the next thing. It feels blunt when you write it. It reads as confident when they skim it.

Write for the skim first#

Since the visitor behaves like the fly and not the scholar, design for the fly. Put the argument in the headings, so that reading only the headings delivers the whole case. Front-load the first sentence of every paragraph. Then layer the depth underneath, in the diagrams, the docs, the technical blog, for the minority who slow down. You are not choosing between skimmers and readers. You are sequencing them.

Depth belongs one click deeper#

None of this argues against technical depth. Depth is where security credibility lives, and the startups that publish real research and real opinions earn inbound that no advertising buys. The argument is about placement. The homepage is not the venue for your hardest prose. It is the venue for the clearest sentence you can write, with the depth one click away for the reader who has decided to care.

The sequence matters, too. Readability is the second problem. The first is that the visitor cannot tell what you do at all, which no amount of simplification fixes if the underlying line is abstract. That failure, and the concrete-mechanism fix for it, is the subject of the five-second homepage. And if you want the readability finding in context, alongside what we found about color, tone, and the three tiers the category splits into, the full study is in our Cult Products Awards report.

Your buyers are clever. That was never the question. They are also busy, skeptical, and gone in seconds. Write for the fly, keep the library one click away, and both readers get what they came for.

Phill Keaney-Bolland

Phill Keaney-Bolland

Co-founder and Designer, Yaya

Co-founder and designer at Yaya, and host of the Cult Products podcast. Fifteen years designing products, brands and UX across multiple industries before narrowing to cybersecurity, and lectures on design at Imperial. Works with cybersecurity founders on positioning, strategy and the website that has to carry a launch, across identity, cloud security, AI agents and software supply chain, including Twine out of stealth and Geordie AI, which won the RSA Innovation Sandbox in 2026.

Frequently asked questions

Related content

The latest news, technologies, and resources from our team.

  • Website

    Buyers of early-stage security products know the product is immature. They get comfortable with the people instead. A missing team page is a hole in the buying journey.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • CISOs and buyers

    Justin Woody planned 100 buyer conversations for Twine and did 250. Nearly all of them pointed at a different problem, and the company pivoted before writing code. Here is how validation actually works.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Brand

    Cybersecurity founders want to stand out and fear standing out. Both instincts are right. There is a working test for where the line sits, and it involves your champion's CFO.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Brand

    Founders debate launch timing endlessly: before or after the raise, before or after the product feels ready. There is no perfect moment. There is a market calendar, and it should set your date.

    Phill Keaney-Bolland

    Phill Keaney-Bolland

  • Website

    Buyers describe a use case to an LLM and get a shortlist of three to five names. How security startups earn a place on it, and why the answer runs through a website you own.

    Phill Keaney-Bolland

    Phill Keaney-Bolland