Web app | Netenrich | 2022

Mitigating security risks with a Mitre-based framework

ROLE

Lead designer - user research, end-to-end design process & implementation support.

TEAM

Design Manager, VP, Security Analysts, Developers, UX Designer (me)

DURATION

9 Months

OVERVIEW

A cybersecurity framework that helps users detect threats and coordinate cyberattack responses. I designed the experience where analysts used the MITRE-based framework to understand adversary behaviours and find gaps in their security coverage.

Project Under NDA

Unfortunately, due to NDA restrictions, I am unable to share the details of the project. This page contains a brief overview of the project but doesn't reflect everything I worked on— please contact me for the complete portfolio walkthrough :)
If you want to read about the entire project & have the password please
Click Here

THE BEGINNING

It all began with this image and the word “MITRE”.

Our design lead sent a message asking me to figure out a way to implement MITRE into our platform. At first glance, the image was pretty daunting, a matrix of some sort with a bunch of colours. I was excited about this project as it was a rare opportunity to be involved in the zero-to-one effort of a new product from its early stages.
So I delved into the realm of cybersecurity in search of answers to some questions, such as what even is MITRE? And how can we use it?

Image sourced from Security Risk Advisors
CONTEXT

Think like an attacker

MITRE Att&ck framework is a comprehensive matrix that is used to document the various attacker behaviours in different stages of a cyberattack. By understanding why and how an attack would take place, organisations can improve their coverage against risks.

Image sourced from Security Risk Advisors
OPPORTUNITY

How might we integrate the Mitre framework into our web app to strengthen our threat detection tools?

VALIDATION

“This is easy to understand. It is flexible and I can see how this can adapt in different ways.”

CSO of Netenrich

Once phase 1 was implemented, we met with internal users to validate the solution. The feature was met with a lot of excitement. Feedback for additional features matched our initial roadmap.

IMPACT

Mitre detection went on to become a key feature in the platform’s solution offering.

Phase 1 of this module was implemented in August and Phase 2 was implemented in November. This went on to become a key feature in the company’s threat detection bundle and resulted in securing a partnership with Google Chronicle.

LEARNINGS

Dive into data

Articulating ideas

Understanding the business landscape and basic knowledge of the product itself, helped me become a crucial part of the product design process. Due to the insights from my research, I could help define the value proposition through brainstorms with the rest of the team.

The role of UX goes beyond making decisions on the user experience. We form the bridge between product owners, stakeholders and engineers, visualising ideas and making sure everyone is on the same page.