ThreatConnect (now Dataminr)

Product Strategy, UI/UX Design, Prototyping, Design Systems

Product Strategy, UI/UX Design, Prototyping, Design Systems

Redesign of Threat Graph from 60% usage decline to 73% monthly active usage

The Threat Graphs purpose was to allow cyber security analysts a way to visualize threat intelligence relationships for investigations, but the feature was experiencing a 60% decline in usage. I successfully redesigned the core threat visualization experience, incorporating our AI/ML CAL data layer resulting in 73% monthly active usage, 40% reduction in investigation time, and $2.3M in prevented customer churn.

Cybersecurity UX Innovation

Award at RSA 2022 Conference

Market Leader
Award

At Global InfoSec Awards 2022

At Global InfoSec Awards 2022

$2.3M

Prevented customer churn

58%

Increase in In monthly active users

$2.3M

Prevented customer churn

58%

Increase in In monthly active users

Before redesign

After redesign

Problem

ThreatConnect's Threat Graph was experiencing a usage declines of over 60% in just 18 months after launch. This put 23% of enterprise customers at churn risk, who cited poor visualization as a primary reason for not using the graph. We found that analysts were abandoning the graph for third party tools.


Through stake holder interviews and customer feedback analysis, I identified the following core issues:


1. Limited visibility: The graph was confined to 25% of screen real estate in the upper right hand corner

2. No visual hierarchy: Impossible to distinguish between data types, relationships, and threat levels.

3. Missing context: No way to understand why two pieces of data were connected.

4. Workflow disruption: Couldn't save, share, or export data.

5. Poor performance: Slow loading times when threat analysts used large data sets.


Part of the initiative was to incorporate the research team's CAL™ (Collective Analytics Layer), a crowdsourced, global threat intelligence engine. It aggregates anonymized telemetry, billions of global indicators, and data points to provide real-time context and global threat scores on indicators like IP addresses and domains.

Research

I conducted in-depth interviews with internal analysts and Fortune 500 customer analysts, exploring investigation processes, pain points, and tool preferences, with findings tracked in Airtable.


To gain deeper insights into real-world usage, I conducted contextual inquiry sessions where I observed 6 live threat investigations, documenting analysts workflows, their workarounds, and moments of friction that weren't captured in interviews alone.

Working session on how an analyst investigates, which functioned like solving a mystery

Insights

Team workflows

Analysts need to save, export, share, and comment on investigation graphs.

Analysts need to save, export, share, and comment on investigation graphs.

Context and trust

Needs relationship confidence, source attribution, and links to existing cases for context.

Needs relationship confidence, source attribution, and links to existing cases for context.

Graph evolves

Investigations run a week to a month, so the graph must evolve over time.

Graph evolves

Investigations run a week to a month, so the graph must evolve over time.

Primary gap -

no way to take action

There's currently no way to take an action on a piece of intel when it's needed.

Explorations and Testing

Usability testing

I ran 3 rounds with 18 participants total, using task-based scenarios with realistic threat data. Measured completion rate, time-on-task, and error recovery. I was able to test several layouts.

Wireframes to test layout and functionality

Iterations

  • Added bulk selection after 83% of users expected it

  • Changed the pivot pattern from a sidebar search to a right-click nested card

  • Added search and pagination once users struggled to find specific indicators in long result sets

  • Let users control which columns appear in the details panel, so they can surface the right data at each stage

  • Consolidated button controls at the top

Through research sessions we tested what visuals meant to each analyst and creating a visual language for the graph

Pivoting on over a Billion indicators

I originally explored different ways to pivot which included a side bar search, SQL, and other patterns that could be supported with Neo4j.


I found that as much as I wanted the query search to work, it brought up issues in my usability studies.

  • Cognitive Overhead — Analysts spend mental energy crafting queries instead of analyzing threats.

  • Syntax Barriers — Complex query languages require specialized knowledge, slowing down investigation flow

  • Assumption Bias — Analysts can only find what they think to query for, missing unexpected connections

  • Starting Point Paralysis — Without clear leads, analysts struggle to formulate effective initial queries

I originally explored different ways to pivot which included a side bar search, sql, and other patterns that could be supported with Neo4j.


I found that as much as I wanted the query search to work, it brought up issues in my usability studies.

Cognitive overload: Analysts spend mental energy crafting queries instead of analyzing threats.


  • Syntax Barriers - Complex query languages require specialized knowledge, slowing down investigation flow

  • Assumption Bias - Analysts can only find what they think to query for, missing unexpected connections

  • Starting Point Paralysis - Without clear leads, analysts struggle to formulate effective initial queries

Example of the query and pivot pattern explored early on.

Single node pivoting

Single-node pivoting transforms investigation
  • Serendipitous discovery — Exposing all relationship types surfaces unexpected connections analysts wouldn't think to query, letting them follow the trail from one finding to the next.

  • Contextual intelligence — Starting from a known indicator shows why entities connect, not just that they do, building a coherent narrative through progressive disclosure.

  • Efficiency — This matches how analysts naturally work, which is why 78% prefer visual starting points: faster insight, less cognitive load, no query-crafting overhead.

Single-node pivoting transforms investigation

  • Serendipitous discovery — Exposing all relationship types surfaces unexpected connections analysts wouldn't think to query, letting them follow the trail from one finding to the next.

  • Contextual intelligence — Starting from a known indicator shows why entities connect, not just that they do, building a coherent narrative through progressive disclosure.

  • Efficiency — This matches how analysts naturally work, which is why 78% prefer visual starting points: faster insight, less cognitive load, no query-crafting overhead.

Example of the pivot pattern using CAL AI Data in the graph

Pivot options

Pivot with TC Data

Pivot with CAL AI data

Enrich with third party tools

Final Solution

Full screen graph experience

  • Expanded to full viewport for maximum data visibility, accessible via a new tab in the nav titled, “Graph”. Analysts can access from any piece of intel in the platform.

  • A legend for analysts to control what is viewed on the graph. Pairing back information is extremely important to reduce visual noise. Selecting a type of intel to show or not show, helps analysts narrow down their investigation.

  • Zoom and pan controls optimized for large datasets, with a zoom to fit and restore layout option if data becomes too spread out.

The final UI strategically positions controls in the top left, includes contextual breadcrumbs for multi-entry navigation, and key actions.

An interactive legend onboards new users while helping experienced analysts filter noise, and a collapsible right panel handles advanced filtering and bulk actions. The score comes from CAL and allows analysts to sort by most critical inidicators.

Tooltips and menus for the UI

Dialogs and overlays including filters

Save or share

  • View saved investigations from one place with most recent graphs located at the top with a snapshot view

  • Edit a previously saved graph so the graph evolved with an analysts investigation over time

  • Export to PDF/PNG for executive reporting and documentation

Overview the graph landing page with all graph files

Ability to save within the graph view

Search

  • Boolean search capabilities across all threat intelligence data

  • Filter by confidence level, source, threat type, and time range

  • Bulk action capabilities enabling users to create cases, run playbooks, or assign owners directly from graph selections

  • Object removal capabilities allowing analysts to declutter investigations by removing irrelevant nodes through both individual and bulk selection ive initial queries

  • Boolean search capabilities across all threat intelligence data

  • Filter by confidence level, source, threat type, and time range

  • Bulk action capabilities enabling users to create cases, run playbooks, or assign owners directly from graph selections

  • Object removal capabilities allowing analysts to declutter investigations by removing irrelevant nodes through both individual and bulk selection ive initial queries

Advanced search filters available in table view

Bulk actions as well as user control over what data is visible from the side panel

Connecting to the rest of the platform

  • View a case in the graph from the case view

  • Run a playbook for full automation on an indicator

  • Add associations to a piece of intel from the graph

As a pivot option analysts can select a playbook automation within the graph

As a pivot option analysts can add new indicators/ data into the graph

Results and Impact

$2.3M

Prevented customer churn

58%

Increase in In monthly active users

40%

$2.3M

Reduction in investigation time

Prevented customer churn

Top 100

58%

Innovative Cybersecurity Companies Of 2022 by Expert Insights

Increase in In monthly active users

40%

Reduction in investigation time

Top 100

Innovative Cybersecurity Companies Of 2022 by Expert Insights

"The icon system is pure gold. We can finally distinguish between threat types at a glance.”

Senior Threat Analyst

Financial Services

"Investigation time cut in half. The AI insights help us focus on real threats instead of the noise."

Security Ops Manager

Tech Company

"This actually has me excited and I'd prefer to use this to [competitor name]. The visual clarity is exactly what we needed."

CISO

Fortune 500 Customer