CTEM Core
About XM Cyber
XM Cyber is a continuous exposure management platform. It models attacker paths across enterprise networks to highlight critical security risks. The engine behind it is an attack graph: devices and accounts as nodes, attack techniques as the links between them, and choke points where many attack paths converge.
CTEM Core: Simplifying Entity and Exposure Flows
The attack graph is the product's greatest strength and its heaviest usability cost. For years, the answer to almost any question was "go look at the graph," and every new capability added more screens on top of that same model. This project was a company-wide simplification initiative to make the platform usable without weakening the underlying graph model. I served as the design owner for the CEM entity and exposure flows inside this initiative.
My Role
Owned the UX strategy and end-to-end design for core platform surfaces: choke points, critical assets, entity cards, exposure reports, and remediation workflows.
Design Owner for CEM Entity and Exposure Flows
- Problem Framing: Built a joint brief with the product manager rather than receiving a finished spec, directly shaping project direction.
- Flow Mapping: Mapped shipped journeys against proposed flows with persona labels on every step, establishing the core argument for the redesign.
- The Persona Split: Drove and defended the two-user model that determined the information architecture of downstream screens.
- Specification: Wrote detailed component specs in Figma covering interaction states, accessibility notes, and interface copy.
- Delivery Verification: Reviewed front-end PRs against design specifications, commenting on spacing, tokens, states, and responsive behavior, verifying implementations locally in Storybook prior to sign-off.
The Problem
- Lack of Guided Investigation: The entity card stacked inventory details, scores, exposures, a large attack graph, and remediations into a single scroll. Nothing indicated where a user should start.
- Visual Overload: Entity details remained on screen long after they stopped being relevant to the active task.
- Graph Disorientation: Long chains and high node density left users without clear starting points or priority guidance. Greying nodes out added visual noise instead of removing it.
- Unsupported Prioritization: Choosing remediation sequence depends on fix complexity, asset ownership, required downtime, and bulk action support. The legacy interface exposed none of these factors.
- Weak Choke Point Signals: Choke points are a core product concept, yet graph nodes carried no choke point indicators. The side-rail score functioned as decorative metadata rather than an actionable signal.
- Cross-Module Blindness: Vulnerabilities identified by the attack path engine failed to surface in the dedicated vulnerability module, causing a single finding to appear as two unrelated issues.
Business Goals
- Reduce Time to Action: Shorten the path from opening an entity to executing a remediation.
- Protect the Core Model: Simplify the interface without degrading the core attack graph capabilities the product is evaluated on.
- Make Core Concepts Visible: Surface choke points directly at decision points rather than isolated in side panels.
- Restore Cross-Module Trust: Ensure a finding reflects consistently across every module.
- Support Scale: Maintain interface usability from empty environments up to massive enterprise estates without structural redesigns.
Target Audience
Enterprise security teams and the IT teams responsible for executing remediation work.
User Persona
- Two distinct users arrive at the same interface:
- The Fixer: Usually in IT rather than security research. Needs direct instructions on what to execute next and was previously overwhelmed by research tooling they did not need.
- The Researcher: Handles complex edge cases where optimal fixes are unclear. Was not provided sufficient contextual depth to reach confident decisions efficiently.
Research & Competitor Analysis
- Continuous Field Feedback: Partnered with Sales Engineers and Customer Success teams observing live user sessions to pinpoint friction points and workflow stalls.
- Product Telemetry & Funnel Analysis: FullStory journey tracking validated the core problem before design began. As the platform's most visited surface, the Entity Card retained users twice as long as any standard report yet yielded the lowest completion rate, with sessions repeatedly cycling back without resolution. This aligned directly with customer feedback, making entity investigation a top feature demand that year.
- Cross-Functional Working Sessions: Conducted structured alignment sessions with Product Managers, Customer Support, and Engineering Leads to define technical constraints early.
- Competitive Benchmarking: Evaluated eight enterprise security products on adjacent inventory workflows, validating industry patterns around scope selection, saved views, and summary-first layouts.
- Edge-Case Framework: Tested flows against a six-archetype framework (timing, user attributes, technical constraints, content scope, UGC, and system boundaries), identifying early that an empty state differs fundamentally from an inapplicable state.
Product Goals
- Split by Job, Not by Data: Organize screens around user intent rather than system data structures.
- Unified Mental Model: Implement a single filter model that scopes every view simultaneously.
- Choke Points as First-Class Signals: Encode primary product concepts directly onto graph nodes.
- Reduce Complexity by Removal: Provide real filtering controls rather than greying out irrelevant nodes.
- Single Source of Finding Truth: Maintain consistent finding representation across all platform modules.
Solution
Split the Entity Card by Job
Structured the entity card into an Overview tab for general facts and cross-module posture, paired with a Lateral Movement area containing two dedicated workflows: Fix-First and Investigate.
Implementation Note: The 'Fix-First' workflow was implemented as the 'Recommended paths' view, while 'Investigate' triggers the 'Full graph investigation' canvas.
Alternatives Considered: Progressive disclosure within a single scrollable page, or role-based routing driven by system permissions.
- Rationale : Progressive disclosure fails to solve conflicting information needs, while role-based routing assumes rigid organizational boundaries.
- Trade-off : Adds an extra click for users seeking all data at once, requiring clear visual separation so no information feels hidden.
Unified Filter Across List and Graph
Introduced a shared filter bar that scopes the prioritized remediation list and the attack graph simultaneously.
- Rationale : Maintaining separate filter states for list and graph views created unnecessary cognitive load.
- Trade-off : Constrains both views to a shared data model, making filter capabilities dependent on the common denominator between list and graph datasets.
Integrated Choke Point Indicators
Elevated choke points from static metadata to first-class visual signals directly on graph nodes and within list sorting algorithms.
- Trade-off : Adds visual encoding to a dense graph interface, necessitating pairing with real node-visibility controls to prevent visual clutter.
Direct Node Visibility Controls & User Exclusions
Enabled users to mark specific techniques, paths, or remediations as excluded. The list and graph recalculate automatically to present the next optimal remediation path and project security improvements.
Designed explicit loading and transition states during graph recalculation to maintain user spatial orientation.
- Alternative Rejected : Allowing direct deletion or editing of underlying findings, which would compromise source data integrity.
- Trade-off : Increases front-end and back-end logic complexity while introducing permission rules managed in subsequent phases.
Cross-Module Posture Alignment
Ensured vulnerabilities proven exploitable by the attack graph surface in the vulnerability management module with clear status labels (such as "105 devices vulnerable, 15 actively exploitable").
- Rationale : Discrepancies between modules eroded user trust in platform accuracy.
- Trade-off : Requires cross-team engineering coordination between groups operating on independent release schedules.
UX Flow
Old Flow :
- Open entity
- Single long scroll of mixed data
- No clear entry point
- Return to graph.
New Flow :
- Open entity
- Overview tab for posture
- Select job (Fix-First vs. Investigate)
- Apply single filter across list and graph
- Execute remediation or apply exclusion and recalculate.
Outcome & Status
- Architecture Approved: The job-based split and unified filter model were approved and transitioned into delivery during 2026.
- Phased Rollout: Core components shipped to production, with secondary flows currently in active development.
- Managed Open Variables: Specific ranking algorithms, advanced permission matrices for exclusions, session persistence rules, and final cross-module metrics were structured as open variables to be refined iteratively rather than finalized prematurely.
Initial Measurements & Telemetry
Defined the measurement framework alongside product managers using FullStory and Pendo telemetry:
- Time to First Remediation Action: Tracked from entity card open to action execution, segmented by persona path. Serves as the primary validation for whether Fix-First accelerates execution.
- Fix-First vs. Investigate Usage Ratio: Monitored to validate or adjust the initial two-persona hypothesis based on real interaction volumes.
- Graph Engagement as an Efficiency Signal: Reduced time spent navigating complex graphs to reach decisions is evaluated as a success metric rather than user disengagement.
- Choke Point Visual Influence: Comparing remediation choices before and after introducing node-level choke point indicators to isolate whether visual cues directly alter user decision-making.
Layout Grid
UI Designs
Overview & Recommended Paths (Fix-First) – Surfacing prioritized remediations without forcing users into complex graph navigation.
Full Graph Investigation Canvas – Providing security researchers with deep path exploration, node exclusions, and filter controls.