Abnormal Security

Detection 360

Detection 360 is where customers report missed attacks and false positives and get a response from Abnormal. I redesigned the experience to make cases easier to scan, support detailed automated insights, and reduce the manual work required from the security team.

Automation Cybersecurity Enterprise
Redesigned Detection 360 experience
100% of Detection 360 responses automated
177 / week manual documents eliminated
~90 hrs / week security analyst effort saved

Context

Abnormal learns the behavior of every identity in a company’s email environment and analyzes the risk of every event to block attacks. By understanding what is normal, it can detect and prevent malicious and unwanted emails that bypass traditional security solutions.

Sometimes, Abnormal gets it wrong. Detection 360 is where customers report missed attacks and false positives and receive a response from Abnormal.

Detection 360 before the redesign
The Detection 360 experience before the redesign.

The hypothesis

For high-profile customers — or particularly serious missed attacks — Abnormal’s Support team would sometimes write a custom document explaining why the attack was missed and how the issue would be addressed.

If we could provide useful automated insights for every submission, we could save company time while improving the customer experience by providing meaningful feedback for every case.

User research

I interviewed customers to better understand why they were using Detection 360, what they expected to learn from it, and what information mattered most when reviewing a case.

The full research presentation is embedded below rather than reducing those findings to a few summary bullets.

Problems with the existing experience

Based on the research and my own analysis, I identified a number of issues in the current UI: it was difficult to scan, the table contained too much information at once, hierarchy was weak, and the structure would not scale well to the longer automated insights we planned to add.

Annotated critique of the existing Detection 360 experience
Annotated critique of the existing experience.

Redesign goals

01 · Readability

Make the page much easier to scan and understand quickly.

02 · Scale

Design for the addition of detailed insights, which could be lengthy.

03 · Hierarchy

Highlight the most important information and reduce competition between fields.

04 · Comprehension

Make the status and meaning of a case understandable even when a user is scanning.

The redesigned Detection 360

I redesigned the experience around an expandable table. Missed attacks and false positives are combined in one table by default, with filtering available when the user needs to narrow the results.

I paid particular attention to which information belonged in the collapsed row versus the expanded view. The row needed to communicate the critical state quickly, while expansion created room for submission details, analysis and insights, remediation status, and campaign information.

Expandable Detection 360 table redesign
The selected row expands in place so the user can get more information without losing the surrounding case list.

Testing an alternate direction

I also designed a version where all of the case information was displayed directly in the table. It made more information visible without interaction, but it made the page substantially denser.

Customers preferred the expandable version because it let them scan the list quickly and only gather more detail when they needed it.

Alternate Detection 360 design with all case information shown in the table
Alternate version with all case information visible at once.

Designing the variations

The expanded row was not a single static template. It needed to communicate different states depending on the report type, investigation status, outcome, and remediation state.

I designed the major variations so the structure stayed consistent while the content and status treatment adapted to the case.

Detection 360 variations for multiple statuses and outcomes
System-level exploration across the major report and remediation states.
Detection 360 pending analysis state
Pending analysis
Detection 360 false positive resolved state
False positive / resolved

Content design was a major part of the product

A significant part of this project was designing the messaging itself. The response needed to be detailed enough to be useful to security teams, structured enough for engineering to generate automatically, and understandable enough that it still felt like a human explanation rather than a machine-generated status message.

Build reusable reasoning patterns

For example, a false-positive explanation could be caused by a suspicious link, vocabulary, an unknown sender, an attachment, or a combination of signals. We needed sentence structures that could adapt to those combinations without sounding broken or robotic.

Content design variations for automated false-positive reasoning
Examples of reusable language for different false-positive causes.

Explain both what happened and what Abnormal would do about it

The content also needed to communicate remediation clearly. In more complex cases, multiple detection gaps and planned improvements could need to be assembled into one coherent response.

Automated Detection 360 remediation explanation
A generated response explaining both the detection gap and planned remediation.

Roadmap and post-launch iterations

After the initial redesign was released, we continued iterating based on feedback from the original research and from customers using the new experience. I worked with the PM and engineering to build a roadmap of follow-up improvements.

Detection 360 post-launch roadmap
The roadmap combined research findings, customer feedback, UX improvements, and new functionality.

Additional workflow improvements

More powerful filtering

Customers needed more ways to quickly locate the cases they were looking for, so we expanded filtering across details such as sender, recipient, subject, submitter, case number, time, status, and VIP state.

Expanded Detection 360 filtering

Email notifications

Users were regularly returning to Detection 360 just to check whether a report had been addressed — or missing that it had been resolved because they did not remember to check. We added email notifications so they could leave the dashboard and still know when a case was complete.

Detection 360 case resolution email

Downloading results

Customers needed to use Detection 360 results in their own reporting, so we added the ability to download case data as a spreadsheet.

Download spreadsheet action in Detection 360

Contact Support directly from a case

Users sometimes needed additional help with a case. The existing support workflow was convoluted and error-prone for both the customer and Support, so we let users contact Support directly from the relevant report.

Contacting Support directly from a Detection 360 case

More precise timestamps

Customers wanted to know exactly when an attack was remediated and when the case was resolved, so we added timestamps to the case timeline.

Detection 360 timeline with precise timestamps

Cancel a mistaken submission

Sometimes a customer submitted a report by mistake. Previously there was no way to stop it, so we added a cancellation action while the case was still pending.

Cancel submission action in Detection 360

Outcome

We automated 100% of responses to Detection 360 submissions, eliminating 177 manually written documents per week and saving the security analyst team roughly 90 hours of effort every week.