20
cybersecurity product design challenges Jen Andre

Design talk

Embed Size (px)

Citation preview

cybersecurity product design challenges

Jen  Andre

about me• not  Dus)n  Webber  

• not  a  designer  

• developer/entrepreneur  

• co-­‐founded  Threat  Stack  

• formerly  Mandiant,  Symantec  

• @fun_cuddles,  [email protected]

previously @ threat stack

*  the  work  of  my  talented  co-­‐founder,  Dus)n  Willis  Webber,  from  whom  I  learned  the  importance  of  good  design  even  in  a  B2B/enterprise  product.

challenges

• many  cybersecurity  products  are  technical  products  

• helping  find  or  prevents  aKacks  and  breaches.  

• helping  developers  write  safer  code

security is seen as inconvenient

… a lot of these products are designed by

engineers.

challenges for startups

• Higher  level  of  product  maturity  is  expected  from  security  products.  

• Sales  require  credibility.    Customers  are  relying  on  you  to  supplement  security  exper)se.    

great design can make up for both of these.

key success factors

• Subject  ma<er  exper>se  plus  

• Good  UX  plus  

• Good  design  polish  from  the  start  ins)lls  confidence  in  your  company  and  product.

the consequences of bad UX

real life examples

• Mul>-­‐factor  auth  too  annoying?    Users  will  not  use  it.  

• Too  many  alarms  generated?    Users  stop  looking  at  them.  

• Crypto  too  hard  to  use?      No  one  uses  crypto.  

• Performance  too  slow?  Users  disable  the  security  mechanisms.

emotional design factors

crediblefun practical

security productconsumer products

B2B productcute

reliablecreative

beware of alarm fatigue

challenge for designer: avoiding alarm fatigue

• Some  ideas:  

• Rollup  repeated  events.  

• Is  this  alert  really  cri)cal?    

• If  you  are  making  the  user  take  ac)on,  be  specific.

it’s ok to tell the user things are fine

challenge for designers: too much data

The  sad  state  of  many  security  event  management  consoles.  :(

It’s possible to make this information beautiful and engaging!

*  cybereason.com

in conclusion

• Design  is  a  first  class  ci>zen.  For  B2B/Enterprise  products,  great  design  is  a  differen)ator.      

• You  can  make  an  impact.  Great  design  and  usability  in  a  security  product  actually  can  make  the  online  world  safer.