Adaptiva’s Vulnerability Management

Overview

The goal of Adaptiva's Evolve Vulnerability Management was to provide fast and transparent vulnerability management for companies with a large number of endpoints. I designed dashboards to report vulnerabilities and experiences to automate vulnerability detection and remediation. The development of this project was executed in four phases:

Process.png

Background

Company

Adaptiva is a Kirkland, WA based company that provides endpoint management products for businesses to easily distribute content to and monitor compliance of endpoints.

Problem

Evolve Vulnerability Management came from a desire to break into the security space of endpoint management. IT professionals were concerned about weaknesses that they don’t know about and needed a way to find and fix those weaknesses before they became a problem.

Project goal

Evolve Vulnerability Management came from a desire to break into the security space of endpoint management. The goal of this project was to provide fast and transparent vulnerability management for companies with a large number of endpoints.

Role and responsibilities

As the only product designer at Adaptiva, I worked with product managers, engineers, and other stakeholders to see this project from concept to development. I conducted competitive analysis and SME interviews, created prototypes to review with stakeholders, and worked with the engineering teams during development.

Process

Research

For preliminary research, I conducted a competitive analysis on competing products. I also spent time strengthening relationships with internal Adaptiva employees I knew were former IT professionals to understand their values and goals. With new insights, I created a persona to highlight the values and goals of IT professionals. Ideally, I would have liked to use my interviews with internal Adaptiva employees to inform the questions asked during more in-depth interviews with real customers.

Prototype

This project was one of the first projects I worked on when I started at Adaptiva and initially designed and helped the front-end team develop a working demo with limited functionality to show off at Microsoft’s Ignite 2019. The goal was to gauge customer interest and gather feedback before fully developing the product. Shortly after Ignite, the project was deprioritized and I moved forward with other projects. After a little over a year, this project was pulled from the backburner. I used feedback with the demo version and created a revised interactive prototype in Adobe XD with all the functionality needed to build the full product.

Review

During the review stage, I got feedback from engineers on the feasibility of my designs, worked with support to fine-tune important data points, and obtained approval from upper management. In the future, I would like to conduct usability tests with our customers to improve designs and experience flows.

Engineering handoff

After a few rounds of internal reviews with different stakeholders, I created a final high-fidelity interactive prototype to hand off to the engineering team. I worked with the engineering team to ensure design consistency in the final product. Internally, the reaction to this product was very positive and I plan to collect customer feedback in the form of interviews and usability testing.

Solution

The following are designs and features from my solution that I would like to highlight:

Dashboards for visibility into vulnerability state

Much like Endpoint Health, I created an overview dashboard with drill-down capabilities to allow users to find a specific problem and links to detail dashboards that provide overall information for a particular object. IT administrators can use dashboards to see vulnerability results and take action with remediations.

 

Automate vulnerability checks

Vulnerability policies consist of vulnerability checks that run on specified groups on a schedule. Allowing a user to add vulnerability checks using criteria like product ensures that related vulnerability checks added later will automatically be included in the policy.