CASE STUDY · CYBERSECURITY
CYBERSECURITY EVENT DETAILS
Event playbook status · Artifact behaviour

Improving the event details in the cybersecurity product to enhance the readability and productivity
B2B · UX/UI Design · SaaS
Overview
As analysts, their daily task involves investigating events and deciding whether to escalate or dismiss them based on Event Details content. Therefore, the information within Event Details is crucial for informed decision-making. The goal of this project is to enhance the efficiency of event investigations.
As UX Designer
Research · Problem Analysis · User Testing · Iterations
As UI Designer
UI Components · High-Fi Mockups · Documentations · Prototypes
Collaboration
3 Designers · 3 Cyber Engineers · 1 QA · 1 Developer
Research
To gather additional information, I conducted a review of meetings between cyber engineers and users. This process aimed to identify and understand as many pain points as possible in order to enhance our understanding of user experiences and address any challenges that may have arisen during these interactions.

Affinity Map
Created an affinity map to group similar pain points into categories, extracting key insights to enhance Event Details.

Grouping similar pain points into the same category can help to identify deeper insights
Problem Analysis
Most users share the same pain points, indicating that those issues with higher priority have a greater impact during investigation.
100%
Difficulty checking event playbook errors
67%
Unsure how to use artifact behaviour
56%
No clear visual hierarchy in the overview
Design Decisions
My focus is on making high-impact changes with minimal effort to enhance readability and productivity.
Overview revamp
Prioritize information and enhance readability to guide users
Add playbook status
Added a playbook error and status could help analyst be aware of changes and report to escalate
Artifact behaviour
Redesign the Artifact structure to help users understand the relationship
Overview Enhancement
Analysts use the overview to investigate events. I emphasize the need to redesign the information organization and clear visual hierarchy.
Before

After

What specific changes have been made?
1
Header optimization for essential details
Revised the visual hierarchy by reducing the title size and making the event name stand out more.
2
Organized information with cards
Implemented a card-based design to group information, providing users with a visually hierarchical structure.
3
Enhanced content for tactics and techniques
Added a short description for tactics and techniques to provide more insights during the investigation process.
Add Playbook Status
The Event Playbook is used to automate the escalation process, so any errors related to a failed event playbook are critical. A clear Event Playbook status can help analysts track progress and make informed decisions.

What specific changes have been made?
1
Integration of event playbook tab
Allow users to check and investigate errors within the same module to streamline the workflow.
2
Visual indicator of error
A clear visual cue provides quick insight into the current error conditions.
Artifact Behaviour Redesign
The Artifact Behaviour is used to calculate the Event risk level. A clear structure can help analysts make investigation decisions more efficiently. Therefore, I redesigned the relationship structure.
Before

After

What specific changes have been made?
1
Enhanced relationship view
Revamped relationship layout for clear pattern identification and clear relationships.
2
Different line types for artifact relationships
Different line types with names help analysts gain insightful investigation cues.
3
Early detection with time stamps
Added first-seen time stamps to artifacts for proactive threat detection.
Outcomes
I conducted testing again with the same internal users to evaluate the effectiveness of the enhanced feature.
Improved user experience
Simplified the interface by removing unnecessary elements to create a clean and minimalist design.
Added supporting details like first time seen of each artifact to help analysts investigate events.
Enhanced productivity
Helped users understand the progress and make decisions during investigation with a clear playbook status.
Helped users easily understand the relationships between artifacts through a clear artifact relationship graph.
Takeaways
Although I gathered pain points from recorded meetings, and they all highlighted the same issues that proved beneficial in the design process, given more time, I would have conducted user interviews to gain further insights and performed usability testing to gather additional user feedback.