Cybersecurity
We design interfaces for SOC teams, fraud detection analysts and threat intelligence engineers. We work with thousands of alerts a minute, incident hierarchies, and decisions that have to be made between a sip of coffee and an escalation to the CISO.
We have worked with leading companies and startups
Challenges
A security product wins when the analyst and the board read the same screen
-
„Our analysts have stopped reading alerts - there are so many that half get dismissed unopened.”
UX audit of the SOC dashboard, research with L1 and L2 analysts, redesign of the alert hierarchy and prioritisation rules. We measure mean time to detect (MTTD) and mean time to respond (MTTR) before and after.
-
„Fraud detection blocks honest customers, and the team is drowning in manual review.”
Workflow research with fraud analysts, redesign of the decision view (approve / decline / review) with model explainability, design of a case management panel. We measure the false-positive rate and the time to decision per case.
-
„We talk kill chain and MITRE ATT&CK to the board, and nobody on the other side is buying it.”
An audit of how the product communicates, redesign of the “for decision-makers” section (CISO, CFO, board) - we translate IOCs, kill chains and MITRE ATT&CK into the language of business risk, compliance and incident cost. Without scaring anyone with hackers.
Who it is for
SOC, fraud, threat intel - three worlds, one demand for clarity under pressure
Whatever the product - we hand over the design in a format a team working under compliance requirements (ISO 27001, SOC 2, NIS2, DORA) can read, on-prem and cloud-native alike.
-
SOC and SIEM dashboards
Panels for Security Operations Center teams - alerts consolidated from many sources (EDR, network, cloud, applications), a priority hierarchy, L1/L2 triage, escalation to a threat hunter. Less alert fatigue, an auditable trail behind every analyst decision.
-
Fraud detection and antifraud tooling
Interfaces for fraud analysts in banking, e-commerce and insurance. A decision view with model explainability (why a transaction was flagged as suspicious), behavioural biometrics, device fingerprinting, auditable case management.
-
Threat intelligence and threat monitoring
CTI platforms with IOC feeds, attack-graph visualisation, exploration of the links between domains, IPs and malware samples. UX designed to prevent information overload and to support the threat hunter’s hypotheses.
Process
Five steps - from the first conversation to post-launch measurement
We scale the scope to the product. For SIEM and SOAR the emphasis is on alert hierarchy and triage. For fraud detection - on the decision view (approve / decline / review) and model explainability. For threat intelligence - on visualising relationships, attack graphs and IOC feeds. For compliance tooling - on auditability and reporting to the regulator.
- 30 min
Discovery call - 30 minutes
Online, with the lead designer. We get to know the product, the metrics you judge it by, and the regulatory context it operates in.
- Week 1–2
Audit and discovery
Analytics, session recordings, user interviews, heuristic review. The barriers people actually hit become design hypotheses.
- Week 3–6
UX/UI design
Wireframes, a prototype you can click through, the final interface. Documentation written for the team that will ship it - tokens, states and responsive behaviour included.
- Week 6–7
Validation
Tests with real users, or an A/B test in production. The design changes on the strength of what we saw, before it reaches code.
- After launch
Delivery and care
We work side by side with your developers - implementation review, fixes, additions to the library. After launch we measure and come back with the next hypotheses.
Toolkit
Security standards, platforms and frameworks
- SIEM (Splunk, QRadar, Elastic, Microsoft Sentinel)
- SOAR (Cortex XSOAR, Splunk SOAR)
- EDR / XDR
- MITRE ATT&CK Framework
- ISO 27001 / SOC 2 / NIS2 / DORA
- Zero Trust Architecture
- Behavioural biometrics & device fingerprinting
- Cloud-native (AWS / Azure / GCP) + on-prem
Next step
Let us talk about your project
Tell us what you have to do. We will come back with scope and a quote.
Selected work
Selected work in Cybersecurity
Some of our work is under NDA - we walk you through it live during the discovery call.
Client voices
What our clients say
-
„Working with the Wzór team was a genuinely great experience! They always answered our questions quickly and were flexible about our comments. They have no shortage of creative ideas and are at the same time thoroughly reliable and on time. The end result fully met our expectations; we recommend them to anyone looking for professionals who care.”
Maja Wieloch-Silecka Operations Director, Bosfor Group -
„Our clients expect us to act fast and effectively across a very wide scope - from building a brand, through a website with a store, to running an effective sales campaign. Not an easy task, but doable when you have a tight-knit team and partners who take on challenges on the fly. For us, quality, accountability and commitment are key, and working with UX Agency Wzór gives us that 100%.”
Piotr Alberski Chief Operating Officer, Agencja XO Media -
„Our cooperation with UX Agency Wzór started with our own website. We really liked the way they work, so we decided to subcontract projects for our clients to them on a White Label basis. We loved their workflow, the way they hand projects over to our team, their documentation and their work on the design system. Now we can take on bigger risks.”
Mateusz Swół Chief Operating Officer, Sellace
The team
Who runs it
The people who run the services this industry leans on most. You talk to them directly, from the first call through to delivery.
-
Aleksandra Bondar
Senior UX/UI Designer
-
Katarzyna Adamczuk
Prezes, Analityk Biznesowy
-
Patryk Korycki
CEO, Analityk Biznesowy
-
Tadeusz Wadas
Senior UX/UI Designer
FAQ
Questions that come up most often
How do you design SOC dashboards to reduce alert fatigue?
Alert fatigue is not a problem of alert volume but of hierarchy and context. We design views where an L1 analyst sees the 5–10 highest-priority incidents (not 5,000), with triage built in (suppress / escalate / assign), context from previous incidents, and a clear rationale for the priority. We measure MTTD and MTTR.
Do you design for ISO 27001, SOC 2, NIS2 and DORA?
We treat compliance requirements as a design frame - auditability of every action, roles and permissions (RBAC), log retention, report export for the regulator. We prepare design documentation in a format that makes compliance audits and certification easier.
Do you cover fraud detection in banking and e-commerce?
Yes - we have experience with antifraud tooling, including model explainability (why a transaction was flagged as suspicious), behavioural biometrics, device fingerprinting and case management. We design the L1 analyst view (fast decision) and the L2 view (deeper analysis), with an auditable trail for every action.
How do you work with on-prem, air-gapped environments and NDAs?
We understand the specifics of systems cut off from the public internet. We hand over the design in a format the client’s team can deploy inside their own network with no dependency on external services (fonts, icons, component libraries - all self-hosted). NDAs and confidentiality clauses are standard, with additional terms on request.
Related services