Uncovering deep problems
EXECUTIVE SUMMARY
Role: Senior Product Designer
Domain: Cybersecurity & Attack Surface Management (ASM)
The Challenge: Security directors spent up to half their working hours manually tracking who owned exposed IPs and servers.
The Solution: Pivoted platform strategy from passive vulnerability listing to automated asset ownership assignment and context-specific search.
Key Impact: Overcame enterprise buyer hesitation and eliminated an estimated 10 to 20 hours per week of manual routing overhead per analyst.
Overview
During enterprise sales discovery, an enterprise Director of Security hesitated to purchase the Censys platform. The tool identified vulnerabilities, but lacked the ownership context required to remediate threats.
The Customer Problem
During a discovery interview, the security director shared a defining quote:
"I am a trained security professional who spends more than half his time acting as a lost-and-found operator."
Analysts spent 10 to 20 hours every week tracking down internal owners for unassigned servers and IP addresses.
Strategy & Discovery
I partnered with the Product Manager and Engineering Team Lead to map where users abandoned the product to search internal spreadsheets.
Decision Architecture & Trade-Offs
Decision Architecture: Asset Surface Management Routing
| Approach | Trade-Offs & Technical Limits | Decision Rationale |
|---|---|---|
| Option A: Passive Vulnerability Listing | Surfaced raw lists of CVE vulnerabilities and IP addresses without internal asset ownership metadata. | Rejected: Forced security analysts to spend 10 to 20 hours per week in spreadsheets acting as 'lost-and-found operators'. |
| Option B: Automated Asset Ownership Routing Engine | Engineering teams register cloud assets and IP ranges once. Platform auto-routes detected CVE threats directly to responsible owners. | Selected: Eliminated 10-20 hours/week of manual routing overhead and secured enterprise buyer purchase. |
Collaborative Ideation
I facilitated collaborative sketching sessions with engineering and sales partners to design automated ownership assignment workflows.
The Architectural Pivot
We designed an automated asset routing engine: engineering teams register their IP ranges once, and incoming CVE vulnerabilities auto-assign to the responsible owners.
Business & Operational Results
- Won Enterprise Deal: Presenting the revised ownership-driven designs reversed the security director's hesitation, securing the customer contract.
- 10-20 Hours Saved Weekly: Automated routing eliminated up to half of an analyst's weekly manual triage overhead.
- Informed Core Product Roadmap: The auto-assignment architecture became a cornerstone of the Censys attack surface management roadmap.
Want to discuss this project? Contact Joe at josephnewell90@gmail.com.