Custom Scenarios Studio
Role
Senior Product designer
Company
Safebraech
Role
Senior Product designer
Company
SafeBreach
Role Analysis
Job Level
Role title - IT security specialist
Reports to chief information security officer (CISO).
Does not have direct reports
System Competency
High familiarity with SafeBreach and other B2B security systems. Very high proficiency in complex digital systems.
Task Analysis
Create custom scenarios composed of several attacks by using the The Studio.
Run simulations of these attacks on the company's system to identify vulnerabilities.
Address the company's security weaknesses based on the simulation reports.
tools
SafeBreach, alongside other information security products, forms a comprehensive defense system, protecting the company's security from various angles.
Required Skills and Knowledge
High technological capabilities.
Strong analytical skills.
Bachelor's degree in Computer Science.
Ability to work with multiple systems simultaneously.
Ability to prioritize tasks.
Up-to-date with various information security breach methods.
High baseline requirements.
Advanced technical operation skills
Role-Related Goals
Protect the organization's information security. Defend the organization against cyberattacks. Proactively prevent potential breaches. Anticipate and test potential breach scenarios in the system. Prevent potential security breaches and stay a step ahead of attackers.
Challenges
Juggling multiple security systems to protect the company from various threats leaves the user with limited time (approx. 15 minutes weekly) for SafeBreach. High learning curve of SafeBreach.
The Studio
The newer platform provides an interactive visual interface that allows users to create and execute security testing scenarios easily. With a range of pre-built scenarios, users can select the ones that fit their needs and combine recommended attacks for specific topics. Compared to the Playbook, SafeBreach Studio aims to make it easier for users to create and run security tests.
The Problems
Users struggled with unclear selections, interface navigation, understanding specific elements like bubbles, and inconsistencies in button functionality and action naming, leading to overall confusion.
The challenge
Maximum value, minimum effort
The main challenge was to do the maximum to change the UI without altering the system's logic. The approach was to start from a situation where users did not understand the screen rules and, through the UI, provide the solution while minimizing changes in logic and development.
User flow
The Goal
The main goal was to ensure that the user could easily understand the screen's functionality intuitively
Final Design
Before & After
Full demo
01
The challenge
Problem
Users had difficulty in recognizing the selection, orienting themselves within the Studio, understanding the purpose of the bubbles, and navigating the left tree. They were also confused by the disabled "test scenario" button, the unclear functionality of the "Start" button, and the multiple names for the same action.
Solutions
To address these issues, I added an indication in the tree when a bubble is clicked and highlighted the relevant bubble when a step is clicked, creating a visual connection between the two. I also emphasized animations to show connections, such as highlighting the row in the left tree when a bubble is clicked, highlighting the bubble itself, and opening the relevant panel. I added a small map to show the overall structure of the Studio and made the upper part sticky to the top of the screen to maintain orientation.
To reduce the size of the bubbles and remove irrelevant information, while narrowing and reducing the tabs on the sides, the left tab now opens only when a problem is clicked to save screen space and link the bubbles to the left panel. I added an indicator to show whether steps were successful, added tooltips to explain problems, and enabled expansion to find solutions.
I added button features such as hover mode and activation, and linked it with an icon in the left panel. I also renamed it from "Start" to "Scenario" to clarify its function. I divided the tree into three levels, adding an "Attack" icon on the third level to improve clarity. Finally, I suggested changing "Run Test" to "Run Scenario" to avoid confusing users, as they are the same action. I also renamed the "Test Scenario" button






