Home / Projects

Attack Surface Dashboard and Widget Builder for Reporting

Attack Surface Dashboard and Widget Builder for Reporting

Overview

Users need a simple, central place to understand their attack surface—to quickly see where they are exposed, assess risk, and decide what to act on, without jumping between different products or screens. This project focused on improving how users explore, understand and report on attack surface data, with a key focus on redesigning the report-building experience to make it clearer and easier to use. Because reporting is used across many areas of the platform, it required close collaboration across product teams and the design system team to ensure consistent, scalable flows and patterns.

Role

Senior UX Designer

Contributions

Shaping strategyUser research and testingEnd to end design

Company

Rapid7

01. Project introduction

What the Attack Surface Dashboard is

The Attack Surface Dashboard gives users a central, real-time view of the assets in their environment. It highlights exposure, risk and overall security posture in one place, helping users understand where they stand at a glance.

It brings together visibility across both:

Although the dashboard reflects live data, users also need to export snapshots of their attack surface. These are typically shared as PDFs to support reporting and conversations with stakeholders.

What the widget builder is

The widget builder is a tool that allows users to create and customise visual widgets without writing complex queries. For attack surface reporting, it enables users to select the metrics, trends and signals that matter to them and turn that data into clear, actionable reports.

Why this was needed

Customers needed a single place to understand:

Previously, they had to piece this information together across multiple products and views. This work aimed to bring that visibility and control into one coherent experience.

An attack surface dashboard is not only about operational visibility, but also about meeting compliance and regulatory obligations. Many organisations are required to maintain an accurate inventory of assets, continuously monitor for vulnerabilities, and demonstrate that risks are being identified and addressed in a timely manner. Standards such as ISO 27001, SOC 2, and industry-specific regulations expect clear evidence of oversight and control.

Without a reliable view of their attack surface, teams struggle to prove that they understand what assets they own, which ones are exposed, and how risks are being prioritised. Reporting becomes manual, fragmented and time-consuming. In the event of an audit, security review or breach investigation, this lack of clarity can lead to failed audits, financial penalties, reputational damage and loss of customer trust.

A centralised dashboard, paired with exportable reports, gives organisations a defensible record of their security posture. It helps them demonstrate due diligence, show progress over time, and communicate risk clearly to leadership and external stakeholders.

02. The Problem

Attack surface reporting presents several challenges:

As a result, reporting becomes a technical task rather than an intuitive way to understand and communicate risk.

03. Discovery and Research

Use Cases and User Stories

While Assets and Identities focuses on searching for and managing individual assets, the Attack Surface Dashboard serves a different user goal. Its primary purpose is to support awareness, assessment, and prioritisation of risk at an environment level.

Defining use cases and user stories separately ensured:

This separation helped the dashboard complement the asset experience rather than duplicate it.

User Interviews

Throughout discovery, we spoke with customers on a continual basis. A consistent theme emerged: while existing reporting capabilities were adequate, the experience of building reports was cumbersome.

Key insights included:

These insights directly shaped the direction of both the dashboard and widget builder.

User-Defined Context

Interviews also highlighted a critical need for users to apply their own business, operational, and security context to attack surface data.

While the platform can surface signals and changes, users made it clear that:

As a result, the platform cannot reliably determine whether a change is "good" or "bad" without user input. This reinforced the importance of designing experiences that support user-defined context and interpretation, rather than relying solely on automated judgement.

Mapping out widget flows
Mapping out widget flows to incorporate user-defined context

Conceptualising the Attack Surface Dashboard required close cross-functional collaboration due to its importance as one of the most requested customer capabilities.

This phase focused on:

I worked closely with product, engineering, and data teams to ensure the vision was ambitious but achievable, and could evolve as data capabilities matured.

A key part of this work involved defining the out-of-the-box widgets provided after onboarding, in partnership with Product Management. This helped clarify the flows and requirements needed to support the widget builder itself.

Because the widget builder would be used across multiple reporting contexts, significant effort went into ensuring its flows aligned with established platform patterns. Consistency was critical to reduce cognitive load and create a predictable experience across the platform.

04. Conceptualisation

Conceptualising the Attack Surface Dashboard required close cross-functional collaboration due to its importance as one of the most requested customer capabilities.

This phase focused on:

Lo-fi dashboard mockups
Lo-fi mockups to figure out the dashboard and out of the box widgets that would be needed by the customer
Lo-fi design exploration Attack surface external dashboard exploration
Exploring further lo-fi designs in Miro
Hi-fi external attack dashboard
Using AI to mock up hi-fi version of the dashboard

05. Solution

The project delivered two closely connected experiences: the Attack Surface Dashboard and the Widget Builder.

Together, they allow users to explore attack surface data visually, build meaningful reports more easily, and maintain context between high-level insights and deeper analysis.

The Attack Surface Dashboard

The dashboard provides a guided experience for users who want Rapid7 to help them understand and prioritise risk. Once onboarding is complete and data is ingested, users are presented with a curated set of widgets tailored to their environment, asset types, and security posture.

Benefits of a guided, widget-based approach

Supporting different user needs

The dashboard acts as a bridge between high-level awareness and detailed asset analysis.

The Widget Builder

The widget builder enables users to create customised reports through an intuitive, visual experience rather than complex queries.

Benefits

Supporting different user needs

This approach transforms reporting from a technical task into a flexible, approachable experience.

External Attack Surface dashboard
External Attack Surface dashboard
Widget builder experience

06. Results and Learnings

Attack Surface Dashboard

User testing showed the first version of the dashboard was effective as a V1. Users valued the clear, centralised overview and felt it delivered immediate value by surfacing key signals without requiring navigation across products.

Testing also revealed a strong desire for deeper contextual customisation. Users want to apply business, operational, and security context to better interpret risk, reflecting the reality that acceptable behaviour varies across organisations. This will likely need to encompass industry benchmarking so that customers can understand how they're performing within their industry. This will be an additional feature for V2.

Widget Builder

User feedback showed strong interest in the widget builder as a more intuitive alternative to query-based reporting. Participants felt the visual, guided approach reduced friction and made report creation more accessible.

At the same time, testing highlighted the need for future support of third-party integrations. Many users already rely on internal dashboards or external reporting tools and want Rapid7 to help populate those systems rather than operate in isolation. This reinforced the importance of designing the widget builder as a flexible, interoperable reporting layer that can evolve alongside users' broader tooling ecosystems.

Get in touch

I am always happy to discuss new opportunities or anything design related!

Contact Now