Logo

CYBERSECURITY EVENT DETAILS

Redesigning Event Details to help security analysts understand event context, identify critical issues, and make faster investigation decisions.

B2B • Cybersecurity • Enterprise SaaS

Overview

As analysts, their daily task involves investigating events and deciding whether to escalate or dismiss them based on Event Details content. Therefore, the information within Event Details is crucial for informed decision-making. The goal of this project is to enhance the efficiency of event investigations.

Collaboration

3 Designers · 3 Cyber Engineers · 1 QA · 1 Developer

Research & Discovery

Reviewed user–engineer discussions and synthesized recurring investigation pain points.

Interaction & IA

Restructured event information, playbook status, and artifact relationships.

Design & Validation

Designed high-fidelity interfaces, and reusable UI patterns. Tested and iterated based on feedback.

The Challenge

Security analysts investigate events by reviewing the information contained in Event Details and deciding whether an event should be escalated or dismissed.


However, critical information was difficult to scan and some investigation signals were unclear. Analysts had difficulty identifying playbook errors, understanding artifact relationships, and quickly interpreting the event overview.

Our Goal

Make critical security information easier to find, understand, and act on — without adding unnecessary complexity to dense workflow.

Understanding the Investigation Workflow

Rather than starting from assumptions, I reviewed conversations between cybersecurity engineers and users to identify recurring issues during event investigation.

Grouping similar pain points into the same category can help to identify deeper insights

Critical errors were difficult to identify

Analysts had no clear way to understand whether an Event Playbook had failed.

Artifact relationships were difficult to interpret

The existing visualization made it difficult to understand how artifacts were connected.

Important event information lacked hierarchy

The overview presented information with similar visual weight, making critical details harder to scan.

Problem Analysis

Most users share the same pain points, indicating that those issues with higher priority have a greater impact during investigation.

100%

struggled to identify Event Playbook errors

67%

were unclear about how Artifact Behaviour worked

56%

found the overview lacked clear visual hierarchy

These findings helped us prioritize improvements around visibility, comprehension, and investigation flow.

Design Decisions

My focus is on making high-impact changes with minimal effort to enhance readability and productivity.

Make critical information scannable

Reorganize the event overview around the information analysts need first.

Make Playbook errors easier to find

Make Event Playbook status visible within the investigation context.

Turn artifact relationships into investigation cues

Redesign the relationship visualization so analysts can understand connections and identify patterns faster.

1: Establish a clearer information hierarchy

Analysts use the overview to investigate events. I emphasize the need to redesign the information organization and clear visual hierarchy.

Before

After

The solution

1

Reduced visual noise

Removed secondary elements that competed with critical event information.

2

Grouped related information

Used cards to establish clear content boundaries and improve scanning.

3

Enhanced investigation context

Added concise descriptions for tactics and techniques so analysts could interpret the event without leaving the workflow.

2: Making critical Playbook failures visible

Event Playbooks automate parts of the escalation workflow. When a playbook fails, analysts need to know immediately — otherwise a critical event may not be handled as expected.

The design challenge

How might we make Playbook failures visible without interrupting the analyst's investigation flow?

The solution

I introduced a visible Playbook status within Event Details, allowing analysts to:

1

access the relevant playbook context and investigate the error without leaving the event

2

identify failed playbooks at a glance and understand the current status

3: Making relationships actionable

Artifact Behaviour contributes to the event's risk assessment, but the previous relationship view made it difficult to understand how artifacts were connected.

Design Goal

Turn a complex relationship graph into a set of investigation cues.

Before

After

1

Clear relationship types

Different line styles and labels help analysts distinguish how artifacts are connected.

2

Improve the card design

Improved the card layout to make the information clearer and easier to scan.

3

Improve pattern recognition

A clearer relationship structure makes it easier to trace connections across artifacts.

Outcomes

I conducted testing again with the same internal users to evaluate the effectiveness of the enhanced feature.

Improved information clarity


  • Users were able to identify critical event information with less visual scanning and better understand the context of an event.

Better investigation visibility


  • Playbook status made automation failures visible within the existing investigation workflow.

Takeaways

This project reinforced an important principle for designing cybersecurity products: clarity does not mean removing complexity. It means helping users understand the right information at the right moment.


Working with cybersecurity engineers and internal users also showed me how important domain knowledge is when designing enterprise security workflows.


If I continued the project, I would expand the research beyond internal feedback by conducting direct interviews with security analysts.