Overview
Helix was FireEye's premier cloud-hosted security operations platform, letting organizations take control of an incident from alert to fix. It integrated multiple standalone and on-premise products into a single experience and augmented them with advanced threat protection.
Platform capabilities
- Next-generation SIEM
- Security orchestration
- Threat intelligence
- Alert workflow management
- Investigation and case management
- Unified, customizable dashboards
- Advanced reporting
My role
- Led UX design for FireEye's flagship next-generation cloud security platform.
- Conducted UX research to develop data and insights, test assumptions, and guide development of new features toward business goals and user needs.
- Worked closely with Product and Engineering to develop a powerful alert workflow module.
- Helped guide strategy and design for integrating FireEye's services into the UI, working with Product and Engineering leads from both teams.
- Created an alert visualization system to render complex detection data visually, reducing the time it took junior analysts to assess alerts.
Case study: alert visualization
The problem
The conventional approach to alert management is confusing and time-consuming. Alerts are largely managed in a vacuum, as a single event in time. Users are presented with alert data that is highly technical and data-dense, making it hard to understand what actually happened. Newer analysts lack the skills to interpret the alert. Reaching a conclusion often takes multiple steps across different tools — and it is left to the analyst to determine what action to take.
The solution
An interactive visualization library able to parse complex alert data and render it as a clear picture of what happened. The visualizations told the story of:
- What triggered the alert
- Who was affected
- Events that occurred or were attempted
- Mitigations taken automatically
- Source and destination
- Whether something is malicious or benign
- Intel enrichment — known good, bad, or unknown
- Any related or correlated alerts
The process
In discovery we decided to focus on making the software easier for junior analysts to use. I set up a working group including Product and Data Science leads that met regularly for collaboration sessions and design review, and facilitated a strategy workshop using the Lean UX Canvas to define business goals, metrics, and hypotheses.
From there I led the effort from discovery to deployment:
- Crafted a research plan and interview questions
- Conducted user interviews
- Synthesized findings to understand user needs
- Created designs and prototypes for testing
- Ran usability tests to confirm the designs solved the right problems
- Ran A/B impression tests to further refine
- Iterated continuously, validating with users and key stakeholders along the way
- Broke the designs down into a component library and a mini design system able to render every different type of alert
Impact and results
The experience increased analyst efficiency by creating a system that parses complex alert data and renders it in consistent, easy-to-understand visualizations. It provided context and encouraged users to inspect elements to see detail and take the appropriate action to remediate a threat.
- Analyst triage time and alert volume both dropped significantly. Reading an alert stopped being an investigation in itself.
- Junior analysts could work the queue. The visualisation answered what triggered the alert, who was affected, and what had already been mitigated — removing the escalation to a senior analyst that interpreting raw detection data used to require.
- One system rendered every alert type. The component library underneath meant new detection types inherited the visual language instead of needing bespoke design.
- Validated before launch. Usability testing and A/B impression testing confirmed the designs solved the problem rather than simply looking different.