Darktrace / CLOUD

"Securing Infrastructure as a Service (IaaS): Protecting Cloud-Based Systems from the Ground Up"

My role

Lead Designer — Feature Scoping, Research, Interaction Design, Visual Design, Prototyping

Timeline & Status

9 Months

Overview

SkyShield provides comprehensive security for all infrastructure as a service, including AWS, GCP and Azure. It uses a contagion model to prioritise alerts and a graph on the back end to ensure everything is connected.

SkyShield provides asset linking, auto-mitigations, malware scanning, and enforcement of best practices. It exports to Sims, integrates with teams, email, and ServiceNow, and has discoverability checks to identify potential vulnerabilities.

HIGHLIGHTS

Detect known and unknown threats across your on-premises and cloud environments
0.1
Details View
IMAGE
0.2
Alerts View
IMAGE
0.3
Core component catalogue
IMAGE
0.4
New Alerts
IMAGE
0.5
Account Setup
IMAGE

Context

A new direction for Darktrace.

The need was clear from the start.

SkyShield was created to tackle the rising challenges of managing and securing multiple cloud services. With cloud adoption booming, organisations needed a solution for full visibility and control. This product aligned with the company’s vision to address the evolving demands of cloud security.

1
Article from Darktrace
IMAGE

The Problem

A complex landscape of cloud services.

The challenge is daunting.

Getting familiar with AWS Architecture Icons and AWS Architecture Center for diagramming was time-consuming.

Current tools lack the ability to prioritise alerts and offer a comprehensive view of the infrastructure.

The caveat

No one really had a concrete sense of direction as to how we could materialise and productise the vision of Skyshield.

Emerging Opportunities

What if SkyShield simplified the process of securing all cloud infrastructure with real-time monitoring and automated mitigation?

What if this allowed organisations to ensure compliance with best practices while reducing the time spent on manual security management?

RESEARCH SUMMARY

Implementing Darktrace Cloud's dynamic visibility

Automated threat detection

It was critical to first understand where the real-time cloud monitoring and threat detection fit within the broader cloud security and infrastructure management lifecycle.

3.0
Hypothesis
IMAGE

More users making more things.

A research workshop informed us that for Darktrace Cloud's vision to succeed, we had to expand our focus beyond traditional security teams to include cloud infrastructure experts and DevOps professionals.Naturally, this meant ensuring the platform could support the diverse needs of tactical users managing complex, multi-cloud environments (Figure 3.1)

3.1
Scope
IMAGE

To name but a few

Overlooking legibility & formatting.

Lack of visual treatment to support longer entries and text wrapping.

Finding structure amidst the chaos.

To make sense of an otherwise unconventional set of steps for creating a release, I started by exploring ways to foster a perceived sense of progress.

Shown in Figure 3.1, categorising releases into two stages helped mitigate the cognitive load of seeing all the steps at once.

Additionally, overly-technical terms were revised to better cater to a general audience.

3.1
User Flows
IMAGE

Pinpointing the issues.

Having structure also helped surface some heuristic issues; whichmainly involved confusing navigation and lack of edge case considerations.

3.2
Updated User Flow
IMAGE

Depth Interviews

I conducted three in-depth interviews, these interviews allowed me to explore participants' past experiences with music distribution platforms and their expectations for Beatclap services.

The findings confirmed my assumption that users prefer managing their music revenue and distribution on a computer, as they believe it minimises errors and streamlines the process.

One participant expressed their frustration:
"I find it incredibly inconvenient to track my music revenue across different platforms every single time. It's frustrating and time-consuming."

Diagram FLOW

Every function in its own place.

You gotta start somewhere.

After two weeks period I created the flow diagram to illustrate the whole process, with the aim to scope the application with its problematic parts as well as possible conflicts.

4.0
Diagram Flow
IMAGE

A modular approach to data representation.

Based on research, flow diagrams and information architecture I began working on the interface designs. High-fidelity wireframes were used as foundation for demoing and usability testing.

4.1
Wireframes
IMAGE

A New Design Language

One of the most significant impacts of working on this project was introducing a new design language throughout the company.

4.2
Design System
IMAGE

Depth Interviews

I conducted three in-depth interviews, these interviews allowed me to explore participants' past experiences with music distribution platforms and their expectations for Beatclap services.

The findings confirmed my assumption that users prefer managing their music revenue and distribution on a computer, as they believe it minimises errors and streamlines the process.

One participant expressed their frustration:
"I find it incredibly inconvenient to track my music revenue across different platforms every single time. It's frustrating and time-consuming."

4.3
Persona
IMAGE

Final DESIGNS

Simplify and accelerate the investigation process

Detect known and novel threats

Darktrace / CLOUD is an intelligent cloud security solution that uses Self Learning AI to deliver complete cyber resilience for multi-cloud environments.

5.0
Dashboard - Scans - Details View
IMAGE
5.1
Dashboard - Architectures View
IMAGE
5.2
Dashboard - Alerts View
IMAGE

Final designs

An effortless experience

Keepin' it old school — responsive layout grids.

A standard set of layout grids and breakpoints (Figure 4.0), was critical in ensuring we could design and build quickly and consistently.

6.0
Account Setup
IMAGE

Minimising cognitive load

By treating the dashboard and account setup as customisable hubs (Figure 6.0), it enables security teams to collaborate more efficiently and gain quicker insights into their cloud environment.

6.1
Misconfig Alert
IMAGE

Alerts inspection

By allowing users to visualise the event log and inspect multiple alerts simultaneously (Figure 6.1), Darktrace Cloud streamlines the investigation process, enabling security teams to quickly identify and address potential threats.

6.3
Advanced Search
IMAGE

Product Integrations

By integrating Microsoft Teams with the event log dashboard (Figure 6.), Darktrace Cloud facilitates real-time communication among team members while allowing users to quickly access and filter alerts through Advanced Search, ensuring swift collaboration and incident resolution.

6.4
Architecture View
IMAGE

Architecture Diagram

By offering an intuitive, visual representation of AWS architectures (Figure 6.4), Darktrace Cloud enables users to interact with and monitor resource relationships in real-time, quickly identifying high-risk areas and associated alerts for a more informed decision-making process.

6.5
Release Creation
IMAGE

Contracts

Create and access to your royalty splits, terms and payees.

Progress was lookin' awesome!

Retrospective — key takeaways and growth.

A Skyshield design prototype was presented at an all-hands in mid-February 2023 and was well-recieved. The team really wanted to start building it.

Retrospective

A HUGE SUCCESS

It excited many stakeholders — it fulfilled our PM’s vision, garnered engineering support, and set a critical stepping stone for Darktrace's future.

Project Takeaways:

Working with research is a cheat code

It helped uncover opportunities to explore and led to quick and informed design decisions.

Ambiguity can be a blessing

Not having a concrete direction pushed me to be creative and explore big ideas that led to fun and unexpected solutions.

Whiteboards are awesome

Being in the same physical space and seeing collective ideas visually unfold led to some of the most highly fruitful conversations I've ever had.

Simplicity was about reducing complexity, not quantity

If an added extra step led to a more intuitive and error-free experience, it was worth the additional manual effort.