Cybersecurity is a painful, costly, and complex operation for large institutional banks. Our team set out to address this problem with an end-to-end traceability and compliance auditing tool, Cymetric.
Cybersecurity compliance in a global financial organization is a veritable nightmare. (Not an exaggeration.)
Imagine you are Chief Compliance Officer at Chase bank.
You manage a global cybersecurity program for tens of thousands of employees. You must slay a three-headed compliance dragon:
1. Identifying which regulations to comply with, including current federal and state regulations like HIPPA or NYCRR-500; adding new regulations like GDPR into your compliance roadmap.
2. Managing security control implementation and ownership across dozens of information systems and thousands of people.
3. Providing gapless records to prove to auditors that the organization is truly compliant with all relevant regulations at all levels.
If you do your job improperly, there are dire penalties; for instance, non-compliance with GDPR means your organization may be fined up to €10 million, or 2% annual global turnover — whichever is higher.
Surprisingly, most of this type of sensitive compliance work is still being done by siloed, ad hoc teams using outdated tools like paper journals and excel spreadsheets. Given my team's expertise in software and our partner firm's deep working relationships with the target customer segment, we decided that this is a billion-dollar problem for which we can design a 10x better solution than what exists in the market today.
To create an end-to-end cybersecurity compliance solution for large institutions to ensure compliance with the latest regulations across all levels of the organization.
15% UX Researcher | 75% Product designer | 10% Frontend engineer
Sketch, Marvel, Zeplin, Abstract, Optimal Workshop, Atom, Bitbucket
Angular, Node, GraphQL, Docker, Postgres, Python, Authy, Google Material Design
To understand the functionality of Cymetric, let's take a look at the conceptual architecture of the compliance lifecycle:
1. There are Regulations at State, Federal, and International Levels. These regulations can be mapped onto a security framework which taxonomizes and details the type of security controls for compliance.
2. Each canonical security control may be applied to information systems, which may be owned by sub-organizations. Each control-information system pairing is known as a "control instance"
3. Auditors would evaluate the compliance at the organization, information system, and control instance levels as one of 5 ratings (ranging from Fully Compliant to Non-Compliant.)
After 6 expert interviews with members of the partner team and 5 contextual inquiries with auditors, I focused on the experiences of two main personas:
Compliance Officer: the compliance owner inside the organization.
Auditor: The external auditor who performs assessments on the organization, information system, and control instance levels.
Research insights led us to understand that the most addressable aspects of the problem are:
This led to a sequential system design that is end-to-end, mapping out the relationship between each actor and each step of the compliance process. I focused on two main design strategies:
1. I designed a sequential, step-wise navigation menu that follows the lifecycle of compliance activities, starting with managing information and ending with the audit.
2. To reduce cognitive load, I optimized for familiar design patterns over newfangled ones; simple list-detail views. Lastly, I broke out complex processes as workflow-modals and gave the ability to reuse past audits to help auditors manager optimize their workflow.
Design Constraints
1. Massive number of features and data to work with; complex flows
Work-around:
2. Working with a law firm and banks, we were deeply embedded within the sales cycle and had a lot of restrictions on the way in which we conducted customer interviews. The feedback cycles were short, but most of the feedback came from non-end-users.
Work-around:
My design process starts with mapping out the main workflows for each persona. Important flows include:
1. Searching for a control instance
2. Viewing and managing pending controls and groups of pending controls
3. Mapping assessments onto control instances
Our top research insight from auditors yielded that it is painful to work with such an astronomical number of people. Hence, I designed an integrated contact managment tool with the following considerations:
1. Roles, not people, are the owners of a compliance objective. Hence, this CRM is designed around "contacts", knowing that people will change roles in the organization
2. The responsibilities and information of each contact is in this database for reference, even if they are not a Cymetric user.
The first task I set out to do was to map out the different list-detail views that will house the essential data for the compliance management lifecycle. My design process:
1. Brainstorm list of datasets & objects to be presented with stakeholders
2. Card sorting exercise with stakeholders and engineering team
3. Qualitative testing and iterate from feedback
This navigation hierarchy was designed to conform to the natural workflow of domain experts. The flat architecture also allows Cymetric users to navigate fluidly between different parts of the compliance management lifecycle and for easy cross-referencing.
The data was rigorously analyzed to produce the navigational architecture based on the responses from interviews.
See details on the Navigation Design Process here.
As our research surfaced that compliance officers have a lot of trouble mapping controls onto information systems, one of the key value propositions of the system is to provide automated control instance generation based on inputs. The workflow becomes a simple two-step process:
1. Create information system, adding regulatory objectives
2. Approve automatically generated pending control instances and publish to organization
As each information system must have a security control instance to meet a regulatory line item, I designed a simple process for compliance officers to easily look up and modify security controls active for their org.
One of the most painful problems surfaced during our research is the lack of traceability for past assessment work that has been done by previous auditors. Additionally, banks and auditors often elect to use an assessment that has been done in a previous year to cover a current-year requirement. Currently, the assessments are duplicated manually. I designed this feature to allow auditors to instantly reuse a previous audit.
Cymetric is a full-featured application that has instances running in production for 2 clients. Here's what I learned:
On the product design roadmap: