Case study · Enterprise web platform

Giving CISOs eyes on the attack surface no firewall covers

Attackers stopped storming the castle and started targeting the people who hold the keys: executives' personal accounts. I designed Sunday Security's CISO platform — a dashboard that lets security teams monitor and protect those accounts across an entire organization — from initial concept to a fully functional product.

Role
Product Designer
Company
Sunday Security
Users
CISOs & security teams
Scope
Concept → launch + design system

In 30 seconds

Interviews with CISOs, security experts and executives surfaced three needs: centralized visibility, real-time threat detection, and actionable guidance. I translated them into a dashboard balancing enterprise power with clarity — account aggregation, real-time alerts, case handling, and automated responses — and built the design system that kept the platform scalable and the teams aligned.

The CISO Platform: a dashboard with an enterprise-wide security benchmark and critical events feed, overlaid by a Users screen listing executives with per-person security levels
The heart of the platform: an enterprise-wide security benchmark, the week's critical events, and per-executive security levels — the weakest links, made visible.

Problem

Fortified companies, exposed people

Enterprise systems are hardened, so sophisticated attackers exploit what isn't: the personal Gmail, Dropbox and social accounts of high-profile employees. Those accounts have no enterprise security controls, yet a single breach can cascade into organizational exposure.

CISOs had no unified way to see — let alone manage — this personal attack surface. The challenge: integrate personal-account protection into an enterprise workflow without overwhelming users with complexity, and without invading the privacy of the executives being protected.

Research

Understanding the security team's day

We worked closely with security experts, CISOs and executives, interviewing them about daily responsibilities, the tools they rely on, and the gaps they experience in protecting personal accounts. The research pointed to three requirements:

  • Centralization. One platform to monitor the personal-account security of every key individual.
  • Proactive monitoring. Real-time threat detection with automated responses — the threat landscape moves too fast for manual review.
  • Actionable insights. Clear next steps to mitigate risk, not raw alert noise.

Design process

From wireframes to a working security cockpit

I translated the research into user flows, wireframes and prototypes centered on a dashboard that answers a CISO's first question — “how exposed are we right now?” — then lets them drill into people, events, and reports. We validated the design in usability tests with real CISOs and refined it until powerful didn't mean complicated.

CISO Platform dashboard showing a personal security benchmark gauge at 60%, critical and suspicious event feeds, most vulnerable executives, and a preventative-actions-taken chart
The dashboard leads with one benchmark number, then answers the follow-ups: what happened this week, who's most at risk, and is our work paying off (preventative actions over time).
The Events screen: a filterable list of critical and suspicious events beside a case-handling timeline that tracks an incident from detection to account restored
Case handling turns an alert into a story: detected → user alerted → recovery attempted → accounts neutralized → restored. Security teams see where each case stands and when it's due at a glance, instead of reconstructing timelines.
The Reports screen with per-person security levels and risk counts, and a detail panel for one user showing their security score and top risks grouped by severity
Reports roll up per-person risk; the detail panel prioritizes it — high, medium, low — with the specific account and issue, so the fix is always one step away. Personal data stays minimal by design.

Design system

The system behind the screens

As the platform grew, consistency became a product feature. I created a comprehensive design system from scratch — components (buttons, forms, modals, date pickers, navigation), a style guide for typography, color and iconography, and a centralized repository of assets and documentation.

The payoff was practical: design and development stopped re-solving solved problems, handoffs got faster, and new screens shipped looking like they belonged.

The design system in Figma: typography scale, color palettes, buttons in all states, date picker, input fields and checkboxes, each marked released or ready for development
Components documented with states and release status (“Ready for dev”, “Released”) — the design system doubled as a communication tool with the development team.

Results

What the platform delivered

Full visibility CISOs gained sight of executives' personal-account risk — closing previously invisible entry points
Faster response automated alerts and responses let security teams act on threats in minutes, not days
Scalable design the design system kept quality consistent as the platform and the team grew

What I took away: enterprise tools don't have to feel like enterprise tools. The same clarity that makes consumer apps pleasant makes security software effective — because a dashboard nobody understands protects nobody.