Cybersecurity / research → product → system

One company.
Five attack surfaces.
One question.

“Is my company data breached?” became the entry point into a much larger security system. We researched how exposure moves across people, identity, IT, platform, cloud/code and vendors — then designed products that turn that risk into evidence and action.

8major experiences
6risk surfaces
3access levels
0→1research to launch system
organisation attack surfaceinteractive scan
VENDORSthird-party dependencies
CLOUD + CODEruntime + repositories
PLATFORMURLs · containers · assets
IDENTITYcredentials · sessions · devices
PEOPLEemployees · behaviour · policy
illustrative scan
17 signalsexample.com · 5 connected surfaces
Risk rarely lives in one place.That became the product thesis.

Cyber risk is no longer a single “security team” problem.

Current research points in the same direction as the product: people, credentials, vulnerabilities, cloud assets and third parties overlap. That is why the system could not be designed as one vulnerability table.

The domain research showed five different reasons the product needed to connect people, platform, IT, vendors and identity intelligence.
VERIZON DBIR 2026 · APAC
71%
of APAC breaches involved the human element. This supported treating People Security as an operational security surface, not an LMS add-on.
VERIZON DBIR 2026 · APAC
69%
of APAC breaches involved a third party. Vendor risk therefore belongs inside the same risk model as first-party posture.
SPYCLOUD 2025
1 in 2
corporate users were reported exposed through infostealer malware, reinforcing the need for identity + device + session context beyond a password row.
MANDIANT M-TRENDS 2025
16%
stolen credentials became the second-most common initial infection vector in Mandiant investigations; exploits were 33% and email phishing 14%.
IBM INDIA 2025
₹220M
average organisational cost of a data breach in India. IBM also reported phishing at 18%, third-party/supply-chain compromise at 17%, and vulnerability exploitation at 13% among top initial causes.

We stopped thinking in terms of “features” and started thinking in terms of connected attack surfaces. A compromised employee can create an identity event; the same identity can touch code, cloud and vendor systems; the product therefore needed shared context and different depths for different users.

Six discoveries that shaped what the product had to explain.

These chapters separate external domain evidence from our design inference. The numbers are research inputs; the product implications are the decisions we derived from them.

01 · Human attack surface
71%

APAC breaches still carry a human element.

Domain proof → identity and behaviour cannot sit outside the security model.
Discovery → compromised users need a route from evidence to intervention.
SOURCE · VERIZON DBIR 2026 · APAC
02 · Third-party propagation
69%

Vendor exposure becomes your exposure.

SOURCE · VERIZON DBIR 2026 · APAC
03 · Identity artifacts
1 in 2

Infostealers expand the incident beyond passwords.

Credentials
Cookies / sessions
Device context
SOURCE · SPYCLOUD 2025
04 · Entry-vector competition

There is no single dominant door.

33%
EXPLOITS
16%
STOLEN CREDENTIALS
14%
EMAIL PHISHING
Discovery → the product must correlate technical, identity and human evidence rather than rank one category in isolation.
SOURCE · MANDIANT M-TRENDS 2025
05 · India business consequence
₹220M

Average breach cost turns security evidence into a board-level business problem.

Phishing 18% · third-party / supply chain 17% · vulnerability exploitation 13% among reported top initial causes.
Discovery → executive surfaces need consequence and direction; analyst surfaces need raw evidence.
SOURCE · IBM INDIA COST OF A DATA BREACH 2025
06 · Content hierarchy discovery

One signal needs three explanations.

Executive: What changed? What does it cost? Are we improving?
Operator: What should I fix first? Who owns it?
Analyst: What is the raw evidence, source and artifact?
Design implication: progressive disclosure became a system rule, not a screen pattern.
OUR SYNTHESIS · DERIVED FROM DOMAIN RESEARCH

Eight experiences, but not eight disconnected products.

The design journey starts with public proof, grows into an authenticated operating platform, then branches into focused intelligence products for customers who need less depth or a different commercial model.

01 · PUBLICDomain discovery
02 · OPENBreach proof
03 · LOGINDashboard
04 · PEOPLEIntervention
05 · PLATFORMTechnical depth
06 · ITReputation + vendors
07 · BITWATCHFocused visibility
08 · INFOLEAKIdentity intelligence

The sticky wall was not documentation. It was where product ideas were born.

Filter the board. Each note contains a real product question or risk plus the interface/product response it suggests.

User says: “I don’t know what a CVE is.”Idea: translate technical evidence into business consequence first, then reveal raw detail.USER · 001
User asks: “Why should I sign up before I know you found anything?”Idea: move domain discovery and first breach proof outside authentication.USER · 002
Security lead wants to know who is compromised.Idea: every identity signal needs employee, source, recency and owner context.USER · 003
Employer asks how to reduce repeat phishing.Idea: breached employee automatically enters a relevant course + simulation loop.USER · 004
IT lead asks whether a vendor is safe enough.Idea: reuse the same security-grade language for vendor comparison.USER · 005
Founder wants the product to feel useful in 10 seconds.Idea: one domain input + live counters + visible evidence, no feature tour.USER · 006
Analyst needs to export evidence to another team.Idea: design export status, filters and stable evidence IDs as first-class states.USER · 007
Buyer only needs threat intelligence, not a suite.Idea: separate BitWatch/Infoleak as focused products with lower cognitive load.USER · 008
Leadership asks “are we improving?”Idea: show history and direction, not only current score.USER · 009
Security ops asks “what should I fix first?”Idea: severity alone is not enough; add asset, owner and exploit context.USER · 010
Risk: stolen credentials survive device cleanup.Idea: show credential, browser/session and machine context together.RISK · 011
Risk: third-party compromise becomes first-party exposure.Idea: vendors live inside the same company risk model, not a separate spreadsheet.RISK · 012
Risk: public bucket looks harmless to non-technical users.Idea: connect bucket → data type → owner → remediation.RISK · 013
Risk: phishing is a people issue and an identity issue.Idea: let one incident trigger both identity review and behaviour intervention.RISK · 014
Risk: score can feel arbitrary.Idea: every grade must open into measurable vectors and failed controls.RISK · 015
Risk: stale intelligence destroys trust.Idea: expose freshness, last seen, source and last checked everywhere.RISK · 016
Risk: code secret may already be used in runtime.Idea: link repository finding to cloud/resource context.RISK · 017
Risk: too much red creates fatigue.Idea: use neutral surfaces; reserve severity colour for state and motion.RISK · 018
Risk: unpatched services stay open for months.Idea: surface aging, owner and remediation SLA beside vulnerability evidence.RISK · 019
Risk: breach result may be sensitive before signup.Idea: reveal enough evidence to prove value without exposing unnecessary personal data.RISK · 020
JTBD: “When I suspect exposure, tell me if I’m breached.”Idea: domain check is the primary public product action.JOB · 021
JTBD: “When I see a low score, tell me why.”Idea: grade → vector → failed check → affected asset.JOB · 022
JTBD: “When an employee is exposed, prevent recurrence.”Idea: auto-recommend training, then verify through phishing simulation.JOB · 023
JTBD: “When code is risky, tell the right team.”Idea: map repo finding to service owner and create remediation.JOB · 024
JTBD: “When choosing a vendor, quantify the risk.”Idea: vendor score + questionnaires + open issues + evidence freshness.JOB · 025
JTBD: “When investigating a credential, show the whole incident.”Idea: stealer family, IP, device, OS and artifact expand from the row.JOB · 026
JTBD: “When I fix risk, prove the improvement.”Idea: score movement and historical trend after remediation.JOB · 027
JTBD: “When I only need a quick answer, don’t force the suite.”Idea: BitWatch uses a compressed information architecture.JOB · 028
JTBD: “When I’m an analyst, don’t hide detail for simplicity.”Idea: progressive disclosure rather than simplification.JOB · 029
JTBD: “When I’m leadership, don’t make me inspect tables.”Idea: strong executive summary that links to evidence.JOB · 030
Business question: how do we earn trust before signup?Idea: free public proof becomes the acquisition engine.BIZ · 031
Business question: how do smaller customers buy?Idea: lower-cost focused products rather than discounting the full platform.BIZ · 032
Business question: how does one product expand into many?Idea: shared risk language lets modules sell independently and together.BIZ · 033
Business question: how do sales demos become memorable?Idea: interactive domain scan and score movement instead of static slides.BIZ · 034
Business question: how do we avoid a generic cyber brand?Idea: signal-based identity system where motion carries product meaning.BIZ · 035
Business question: how do we explain the suite in one sentence?Idea: signal → context → action becomes the narrative across products.BIZ · 036
Business question: how do vendors become a growth wedge?Idea: third-party posture becomes a decision product, not compliance admin.BIZ · 037
Business question: how do we justify subscription?Idea: continuous change, freshness and improvement create recurring value.BIZ · 038
Business question: how do we support enterprise depth?Idea: authenticated modules preserve raw evidence and operational ownership.BIZ · 039
Business question: how do we create expansion paths?Idea: public discovery → dashboard → modules → focused intelligence products.BIZ · 040
System rule: live vs historical must never look identical.Idea: live states use motion/freshness labels; historical states remain still.SYS · 041
System rule: every action needs an observable system response.Idea: assign, scan, export and remediate all show queued/running/completed states.SYS · 042
System rule: severity colour cannot do all the work.Idea: pair colour with text, position, grade and motion.SYS · 043
System rule: empty state must explain what creates data.Idea: show integration/source needed, not a blank card.SYS · 044
System rule: scores need deterministic detail.Idea: vector breakdown and checks must always be reachable.SYS · 045
System rule: integrations have lifecycle states.Idea: disconnected, connecting, synced, degraded and stale.SYS · 046
System rule: VAPT has thousands of checks.Idea: show grouped categories + progress, not 3,500 flashing rows.SYS · 047
System rule: permission-limited users need context.Idea: explain what they cannot see and why without looking broken.SYS · 048
System rule: exports can take time.Idea: background export queue with status and notification.SYS · 049
System rule: one visual grammar across products.Idea: shared spacing, typography, risk state and evidence hierarchy; different composition per job.SYS · 050

The wall collapsed into one operating model: signal → context → action.

Different users enter at different points, but every meaningful product interaction follows the same logic.

The three jobs

Know it.
Understand it.
Do something.

This gave us a way to keep executive views simple without taking evidence away from analysts.

01Am I exposed?
02Why / where?
03What next?
PeopleIdentityCloud + codeVendorsOrganisation context

We designed access like a trust journey, not a login wall.

The user gets evidence first. Authentication appears only when the job changes from discovering risk to continuously operating on it.

PROOF

ACTION
Domain check

One input. No account. Answer the question already in the user’s head.

Open breach result

Show enough evidence to prove the product before signup.

Authenticated dashboard

History, score, monitoring and entry into deeper operations.

Operational modules

People, Platform, IT, VAPT, vendors, cloud and code.

Focused products

BitWatch and Infoleak package selected jobs for different buyers.

Continuous value

Freshness, change, remediation and recurring intelligence justify subscription.

Typography carried hierarchy. Colour carried risk. Motion carried change.

The system uses different scale and density for executive storytelling versus analyst evidence, while keeping the same state grammar.

identity principle

Make invisible risk visible.

RISK
IS
RELATIONAL
Display64–120 / strategic story
Product12–28 / operational UI
Mono8–11 / evidence + metadata
Grid8px / reusable rhythm

The first experience does one thing: answer “is my company data breached?”

Live counters and a continuously moving data field establish scale. The domain input creates a direct path into open evidence without onboarding friction.

Why this shape

No feature tour before proof.

The strongest acquisition argument is the product doing something useful. We deliberately keep navigation quiet and the main action singular.

Primary inputcompany domain
Valueinstant exposure signal
Trustlive-updating research scale
Nextopen result, still no signup
BlackSignalAbout · Plans · Sign in
continuous exposure intelligence

Is my company data breached?

0EMPLOYEE RECORDS EXPOSED
0OPEN PORTS OBSERVED
0DATABASE SIGNALS INDEXED

Don’t show dots. Show the evidence chain.

The open result tells the user what was found, where it touches the organisation, and which surface deserves attention — without exposing every authenticated detail.

BlackSignal / public exposure resultSign in · Sign up
Identity exposurecredential + session evidence
Platform exposureURL · container · public asset
People exposureemployee risk + next intervention
Vendor exposurethird-party dependency risk
Organisation contextsame company · connected risk

History → current exposure → score → operational entry points.

The graph is deliberately annotated, not decorative. Each point is hoverable, every axis is labelled, and the score can be drilled into vector-level evidence.

Organisation security commandlive posture · updated 2m ago
History of breach

Employees vs users · 2019–2026

Hover points
256BREACHED EMPLOYEES · ↓32 THIS WEEK
241BREACHED USERS · ↓32 THIS WEEK
241THIRD-PARTY CREDENTIALS · ↑32 THIS WEEK
People Security

Move breached employees into training, simulations and policy completion.

VAPT

Run 3,500+ structured checks and prioritise findings.

Cloud + Code

Correlate repositories, workloads, owners and runtime consequence.

Third-party

See vendor posture beside first-party risk.

Exposure becomes intervention, not another alert.

The product turns an identity event into a behavioural loop: classify the risk, recommend a course, schedule a simulation, track policy completion and verify improvement.

Automation logic

One employee.
Five system reactions.

Breach detected

Credential or session exposure attaches to the employee.

Risk classified

Phishing, password, policy or technical risk determines the next action.

Programme recommended

The relevant course is assigned instead of a generic awareness module.

Simulation scheduled

Behaviour is tested after the learning intervention.

Improvement verified

The employer sees completion and repeat-risk reduction.

Employee intervention board

Recommended for compromised cohort

38at-risk users
EDU
Adaptive awareness sprintcredential-risk cohort · 7 day path
SIM
Phishing simulationtriggered after learning completion
MFA
Identity hardeninghigh-risk users · enforce + verify
POL
Policy interventionrole-specific control acknowledgement
Current trigger
Phishing credential exposure

The system assembles an intervention sequence from the observed risk: learn → simulate → harden identity → verify behaviour.

Not a vulnerability list. An attack-surface command graph.

The redesign maps internet-facing entry points to repositories, workloads, secrets, cloud assets and owners. Findings sit beside the graph as evidence, while the bottom narrative turns scattered signals into an actionable attack path.

ATTACK SURFACE / LIVE CORRELATION

One exploitable path, reconstructed from six evidence types.

184assets27findings4reachable paths
01 · INTERNETportal.company.compublic · auth surface
02 · SERVICEproduction-apiowner · Platform
03 · CODEbilling-serviceGitHub · main
04 · SECRETpayment-tokenlast rotated 91d
05 · CLOUDprod-accountAWS · privileged
06 · DATAcustomer-exportPII · 18.4k rows
REACHABILITYInternet → runtimeconfirmed
EXPLOITABILITYCVE-2026-18421critical
PRIVILEGEAdmin scopeexcessive
BLAST RADIUS18.4k recordscustomer PII
OWNERPlatformSLA 4h
01 · ENTRYInternet-facing URL
02 · BRIDGECode + secret
03 · IMPACTRuntime + customer data
04 · OWNERPlatform / Payments
VAPT engine

3,500+ checks, compressed into evidence families.

The engine stays dense without becoming noisy: families, state, progress and exceptions remain inspectable.

A grade should lead to the failed control. A vendor score should change a partnership decision.

We use the same reputation language across first-party and third-party risk, while preserving the exact reason behind each score.

Overall brand cybersecurity score

Reputation you can actually diagnose.

HSTS not enforcedCriticalFailed
Email authenticationHighFailed
Network segmentationMediumPassed
Third-party decision intelligence

Who is safe enough to partner with?

Security posture is translated into a procurement decision: exposure, control coverage, evidence freshness and remediation velocity.

27monitored vendors6need action
VendorRisk postureEvidenceOpen riskDecision
PORTFOLIO EXPOSURE22% of critical workflows depend on vendors below B
NEXT ACTIONReassess Payments Partner before renewal · 12 days

Six grades, one interaction grammar.

Colour, needle position, vector detail and remediation behaviour change together so the score is consistent across company, IT and vendor views.

A
Strong posture
B
Healthy with gaps
C
Needs attention
D
High exposure
E
Critical posture
F
Severe risk

A focused product for customers who need quick visibility, not the entire operating suite.

BitWatch compresses the same security thinking into recent compromise discovery, clear threat context and subscription access.

Commercial product decision

Reduce depth.
Keep trust.

The information architecture becomes lighter, but evidence and visual quality stay serious. This is a different product job, not a cheaper-looking version of the platform.

Audiencesmaller teams / focused buyers
Jobquick compromise visibility
Modelsubscription access
24/7 monitoring

Your cybersecurity is our job.

Discover compromised credentials and recent data leakage without adopting the full suite.

123KUSERS COMPROMISED
1.8MDATA SETS INDEXED
3KNEW DATA SETS / 24H
Compromised credentialsusername + password exposure
Compromised IPsmachine and network context
Recent breachesfresh exposure timeline

From “240 leaked users” to a live identity-exposure command view.

The redesign prioritises active sessions, privilege, artifact type, recency, device context and exploitability. The table is denser, but the hierarchy is clearer because each column answers an investigation question.

INFOLEAK / DOMAIN INTELLIGENCE

240 compromised identities

Ranked by what can still be abused now. Instead of treating every credential equally, the view separates session artifacts, privileged identities, device evidence and freshness.

domain: company.comlast sync: 2m4 sourcessort: exploitability × privilege × recency
Exposure compositioncurrent domain
Credentials
7832.5%
Session / cookies
6426.7%
Device artifacts
3815.8%
Weak / reused
5221.7%
Privileged
177.1%
IDIDENTITYEXPOSED ASSETARTIFACTSTEALERDEVICEGEOFIRST SEENLAST SEENPRIVILEGEEXPLOITRISKSTATUSACTION
#242335350admin@company.comadmin.company.com/logincookie + pwdRedLineWIN-7F2AIN · BLR2h ago11m agoAdmincriticalactive
SESSIONvalid cookie detected
IP10.24.2.18
OSWindows 11
ARTIFACTbrowser-session.db
PASSWORDreused · weak
OWNERIT Security
NEXT ACTIONrevoke + rotate
#242335351finance.ops@company.comerp.company.comsession cookieLummaMAC-02A9SG · SIN6h ago32m agoFinancecriticalopen
#242335352user3@company.comvpn.company.compasswordRedLineWIN-10C3IN · HYD1d ago3h agoStandardhighreset sent
#242335353user4@company.comportal.company.com/loginbrowser cookieRaccoonWIN-44D1US · SFO3d ago1d agoStandardhighmonitor
#242335354sales.lead@company.comcrm.company.compasswordRedLineWIN-921FUK · LON6d ago2d agoManagerhighreset
#242335355user6@company.comdocs.company.comdevice tokenLummaMAC-A008IN · PUN11d ago4d agoStandardmediumcontained
#242335356dev@company.comgit.company.compassword + tokenVidarLINUX-EE2DE · FRA18d ago8d agoDevelopermediumcontained
240 total · 31 seen <24h · 17 privilegedshowing highest actionable risk · freshness weighted

Collaboration is visible through the decisions it unlocked.

The case study documents how founder input, research, design and engineering changed specific parts of the system.

DISCOVERYDo not hide the first proof behind authentication.

Founder goal was acquisition through usefulness, not a standard marketing funnel.

→ public domain scan
PEOPLETraining should react to breach evidence.

Research showed awareness programmes become more valuable when tied to actual employee risk.

→ automatic intervention
PLATFORMDo not collapse analyst evidence into one score.

Engineering and security workflows required URLs, CVEs, sources, owners and states to remain inspectable.

→ progressive disclosure
COMMERCIALDo not force every buyer into the full suite.

Different depth and price sensitivity justified BitWatch and Infoleak as focused products.

→ portfolio architecture

After launch, the question changes: did people build a habit around the product?

Because actual production telemetry was not supplied here, the visual below is an instrumentation model with clearly labelled demonstration shapes — not claimed product performance.

POST-LAUNCH PRODUCT SIGNALS

Activation is not the win. Repeated security action is.

The measurement model follows the product journey: public proof → account → first meaningful action → cross-module adoption → return → remediation. Each signal tells us where product value is becoming habitual or where the journey leaks.

Telemetry status: structure readyReplace demonstration shapes with Mixpanel / Amplitude / GA / database events before publishing. No adoption or retention claim is made here.
01 / VALUE LADDER

Where does the user stop believing?

Demo cohort normalised to 100 visitors for visual structure only.

01
Domain scannedpublic proof started
100 demo
02
Evidence exploredopened breach categories
72 demo
03
Account createdasked for persistent monitoring
46 demo
04
First security actionscan / course / remediation
33 demo
05
Returned for new valuefresh risk or progress check
24 demo
02 / RETENTION COHORT MATRIX

Do organisations return when security context changes?

Demo heatmap only. Final version should use organisation-level cohorts and active-value events, not page visits.

W0W1W2W4W6W8W12 Launch cohort100 Onboarding v2100 People trigger v2100
03 / MODULE ADOPTION

Which products become repeat workflows?

Final bars = % of active organisations using each module in a rolling 30-day window.

Dashboard
actual →
People
actual →
Platform
actual →
IT / vendors
actual →
Infoleak
actual →
04 / REMEDIATION VELOCITY

Does insight turn into closed risk faster?

Measure median time from first actionable signal to verified closure by severity.

slowmedianfast
18 / The point of the system

Cybersecurity is complex enough.
The product should make the next decision obvious.

From the first domain check to identity evidence, employee intervention, technical remediation and vendor decisions, the system was designed around one principle: signal → context → action.