CYBERSECURITY EVENT DETAILS

Redesigning Event Details to help security analysts understand event context, identify critical issues, and make faster investigation decisions.
B2B • Cybersecurity • Enterprise SaaS
Overview
As analysts, their daily task involves investigating events and deciding whether to escalate or dismiss them based on Event Details content. Therefore, the information within Event Details is crucial for informed decision-making. The goal of this project is to enhance the efficiency of event investigations.
Collaboration
3 Designers · 3 Cyber Engineers · 1 QA · 1 Developer
Research & Discovery
Reviewed user–engineer discussions and synthesized recurring investigation pain points.
Interaction & IA
Restructured event information, playbook status, and artifact relationships.
Design & Validation
Designed high-fidelity interfaces, and reusable UI patterns. Tested and iterated based on feedback.
The Challenge
Security analysts investigate events by reviewing the information contained in Event Details and deciding whether an event should be escalated or dismissed.
However, critical information was difficult to scan and some investigation signals were unclear. Analysts had difficulty identifying playbook errors, understanding artifact relationships, and quickly interpreting the event overview.
Our Goal
Make critical security information easier to find, understand, and act on — without adding unnecessary complexity to dense workflow.
Understanding the Investigation Workflow
Rather than starting from assumptions, I reviewed conversations between cybersecurity engineers and users to identify recurring issues during event investigation.

Grouping similar pain points into the same category can help to identify deeper insights

Critical errors were difficult to identify
Analysts had no clear way to understand whether an Event Playbook had failed.
Artifact relationships were difficult to interpret
The existing visualization made it difficult to understand how artifacts were connected.
Important event information lacked hierarchy
The overview presented information with similar visual weight, making critical details harder to scan.
Problem Analysis
Most users share the same pain points, indicating that those issues with higher priority have a greater impact during investigation.
100%
struggled to identify Event Playbook errors
67%
were unclear about how Artifact Behaviour worked
56%
found the overview lacked clear visual hierarchy
These findings helped us prioritize improvements around visibility, comprehension, and investigation flow.
Design Decisions
My focus is on making high-impact changes with minimal effort to enhance readability and productivity.
Make critical information scannable
Reorganize the event overview around the information analysts need first.
Make Playbook errors easier to find
Make Event Playbook status visible within the investigation context.
Turn artifact relationships into investigation cues
Redesign the relationship visualization so analysts can understand connections and identify patterns faster.
1: Establish a clearer information hierarchy
Analysts use the overview to investigate events. I emphasize the need to redesign the information organization and clear visual hierarchy.
Before

After

The solution
1
Reduced visual noise
Removed secondary elements that competed with critical event information.
2
Grouped related information
Used cards to establish clear content boundaries and improve scanning.
3
Enhanced investigation context
Added concise descriptions for tactics and techniques so analysts could interpret the event without leaving the workflow.
2: Making critical Playbook failures visible
Event Playbooks automate parts of the escalation workflow. When a playbook fails, analysts need to know immediately — otherwise a critical event may not be handled as expected.
The design challenge
How might we make Playbook failures visible without interrupting the analyst's investigation flow?
The solution
I introduced a visible Playbook status within Event Details, allowing analysts to:
1
access the relevant playbook context and investigate the error without leaving the event
2
identify failed playbooks at a glance and understand the current status

3: Making relationships actionable
Artifact Behaviour contributes to the event's risk assessment, but the previous relationship view made it difficult to understand how artifacts were connected.
Design Goal
Turn a complex relationship graph into a set of investigation cues.
Before

After

1
Clear relationship types
Different line styles and labels help analysts distinguish how artifacts are connected.
2
Improve the card design
Improved the card layout to make the information clearer and easier to scan.
3
Improve pattern recognition
A clearer relationship structure makes it easier to trace connections across artifacts.
Outcomes
I conducted testing again with the same internal users to evaluate the effectiveness of the enhanced feature.
Improved information clarity
Users were able to identify critical event information with less visual scanning and better understand the context of an event.
Better investigation visibility
Playbook status made automation failures visible within the existing investigation workflow.
Takeaways
This project reinforced an important principle for designing cybersecurity products: clarity does not mean removing complexity. It means helping users understand the right information at the right moment.
Working with cybersecurity engineers and internal users also showed me how important domain knowledge is when designing enterprise security workflows.
If I continued the project, I would expand the research beyond internal feedback by conducting direct interviews with security analysts.