Custom Scenarios Studio

Role

Senior Product designer

Company

Safebraech

Role

Senior Product designer

Company

SafeBreach

Role Analysis

Job Level

Role title - IT security specialist
Reports to chief information security officer (CISO).
Does not have direct reports

System Competency

High familiarity with SafeBreach and other B2B security systems.  Very high proficiency in complex digital systems.

Task Analysis

Create custom scenarios composed of several attacks by using the The Studio.
Run simulations of these attacks on the company's system to identify vulnerabilities.
Address the company's security weaknesses based on the simulation reports.

tools

SafeBreach, alongside other information security products, forms a comprehensive defense system, protecting the company's security from various angles.

Required Skills and Knowledge

High technological capabilities.
Strong analytical skills.
Bachelor's degree in Computer Science.
Ability to work with multiple systems simultaneously.
Ability to prioritize tasks.
Up-to-date with various information security breach methods. High baseline requirements. Advanced technical operation skills

Role-Related Goals

Protect the organization's information security. Defend the organization against cyberattacks. Proactively prevent potential breaches. Anticipate and test potential breach scenarios in the system. Prevent potential security breaches and stay a step ahead of attackers.

Challenges

Juggling multiple security systems to protect the company from various threats leaves the user with limited time (approx. 15 minutes weekly) for SafeBreach. High learning curve of SafeBreach.

The Studio

The newer platform provides an interactive visual interface that allows users to create and execute security testing scenarios easily. With a range of pre-built scenarios, users can select the ones that fit their needs and combine recommended attacks for specific topics. Compared to the Playbook, SafeBreach Studio aims to make it easier for users to create and run security tests.

The Problems

Users struggled with unclear selections, interface navigation, understanding specific elements like bubbles, and inconsistencies in button functionality and action naming, leading to overall confusion.

The challenge

Maximum value, minimum effort

The main challenge was to do the maximum to change the UI without altering the system's logic. The approach was to start from a situation where users did not understand the screen rules and, through the UI, provide the solution while minimizing changes in logic and development.

User flow

The Goal

The main goal was to ensure that the user could easily understand the screen's functionality intuitively

Final Design

Before & After

Full demo

01

The challenge

Problem

Users had difficulty in recognizing the selection, orienting themselves within the Studio, understanding the purpose of the bubbles, and navigating the left tree. They were also confused by the disabled "test scenario" button, the unclear functionality of the "Start" button, and the multiple names for the same action.

Solutions

To address these issues, I added an indication in the tree when a bubble is clicked and highlighted the relevant bubble when a step is clicked, creating a visual connection between the two. I also emphasized animations to show connections, such as highlighting the row in the left tree when a bubble is clicked, highlighting the bubble itself, and opening the relevant panel. I added a small map to show the overall structure of the Studio and made the upper part sticky to the top of the screen to maintain orientation.

To reduce the size of the bubbles and remove irrelevant information, while narrowing and reducing the tabs on the sides, the left tab now opens only when a problem is clicked to save screen space and link the bubbles to the left panel. I added an indicator to show whether steps were successful, added tooltips to explain problems, and enabled expansion to find solutions.

I added button features such as hover mode and activation, and linked it with an icon in the left panel. I also renamed it from "Start" to "Scenario" to clarify its function. I divided the tree into three levels, adding an "Attack" icon on the third level to improve clarity. Finally, I suggested changing "Run Test" to "Run Scenario" to avoid confusing users, as they are the same action. I also renamed the "Test Scenario" button

NEXT PROJECT

Market Insights On-the-Go