Home / Projects

AI-Assisted Decision-Making for Security Analysts

AI-Assisted Decision-Making for Security Analysts

Overview

This project explores how AI can be used to improve decision-making in cybersecurity by supporting Security Operations Center (SOC) analysts throughout the threat response process. Through research and collaboration with analysts, key challenges such as alert overload, lack of transparency, and fragmented workflows were identified. In response, the solution focuses on an AI-powered interface that prioritises alerts, provides clear explanations, and enables fast, informed actions within a single, unified system.

Role

Senior UX Designer

Contributions

Shaping strategyUser research and testingEnd to end design

Company

Rapid7

01. Project introduction

As AI systems become increasingly embedded within cybersecurity operations, the challenge is no longer detection alone, it is interpretation.

Security analysts operate in environments shaped by:

Yet many security platforms continue to overwhelm users with fragmented tooling, opaque AI behaviour, and high volumes of alerts that are difficult to interpret or prioritise.

This project explored how AI could shift cybersecurity systems from passive monitoring tools into active decision-support environments. Rather than focusing solely on automation, the work examined how intelligent systems could help analysts:

The result was a shipped AI-assisted investigation experience designed to:

More broadly, the project explored a larger question:

How should humans collaborate with intelligent systems in high-risk environments where trust, speed, and judgement matter simultaneously?

02. The Problem

Modern Security Operations Centres (SOCs) face a growing imbalance between:

AI systems have significantly improved threat detection capabilities, yet analysts remain overwhelmed by:

Most platforms optimise for:

But not necessarily:

This creates a critical gap:

Analysts don't struggle to detect threats, they struggle to confidently decide what to do next.

03. Discovery and Research

Market landscape analysis

To understand how AI is currently used in cybersecurity, I conducted a review of leading industry platforms and emerging trends.

Platforms Reviewed:

Key Observations:

Strengths Across the Market:

Gaps & Opportunities:

Key insight:

AI in cybersecurity is not failing at detection, it's failing at decision support. Analysts don't struggle to find threats; they struggle to confidently act on them.

Palo Alto Networks, Microsoft Defender and Darktrace platforms.

Data Driven Design

To understand how analysts interact with the platform and where inefficiencies occur, I used Pendo to analyse user behaviour across key workflows, including alert triage, investigation, and response. This allowed me to track how frequently features were used, how long analysts spent in each stage, and where drop-offs or delays occurred.

The data revealed that analysts were spending a disproportionate amount of time navigating between views and interpreting alert data, rather than taking action. High volumes of alerts were being opened, but only a small percentage led to meaningful action, suggesting a low signal-to-noise ratio.

Key Metrics

Insight

The data showed that analysts were not lacking access to information, but were slowed down by the effort required to interpret and validate alerts. A large portion of time was spent understanding context rather than making decisions, reinforcing the issue of cognitive overload.

Journey Mapping

1. Signal vs Noise Problem

Important threats risk being missed

2. Cognitive Overload

Mental fatigue and slower decisions

3. Lack of Explainability

Underutilised AI systems

4. Fragmented Tooling

Time lost in navigation, not analysis

5. Slow Actionability

Increased impact of attacks

Security Analyst Journey Map
Security analyst workflow

Workshop: Co-Designing with SOC Analysts

Objective

To validate initial assumptions and uncover real-world challenges, we conducted a collaborative workshop with 15 SOC analysts from a range of experience levels.

The goal was to move beyond desk research and understand:

Participants mapped their end-to-end threat response process, revealing consistent stages but a strong reliance on personal judgement rather than system guidance. Through collaborative discussions, key frustrations emerged, particularly alert overload, lack of context, fragmented tools, and low trust in AI-driven decisions.

A focused conversation on AI highlighted that analysts are not opposed to automation, but to systems that lack transparency. In response, participants co-designed ideal solutions, emphasising the need for explainable alerts, confidence scoring, unified data views, and faster, more intuitive response actions. This session reinforced that the core opportunity lies not in improving detection alone, but in supporting clearer, faster decision-making.

Key Insights from the Workshop:

1. Decision-making is the real bottleneck

Analysts don't struggle to detect threats, they struggle to decide what to do next.

2. Trust is built through transparency

AI systems are often ignored when they behave like a "black box."

3. Context is more valuable than volume

More data doesn't help, better-structured insight does.

4. Speed is critical, but clarity comes first

Analysts prefer slightly slower systems if they are more understandable and reliable.

Systems Thinking Diagram

Systems Thinking Diagram

04. Conceptualisation

The concept is guided by a set of core design principles aimed at improving how analysts interact with AI-driven systems. Information should be prioritised and simplified to reduce cognitive load, allowing analysts to quickly understand what matters and why. AI decisions must be transparent, providing clear explanations and supporting evidence to build trust.

Insights should be directly actionable, enabling faster transitions from detection to response. All relevant data and tools should be brought into a single, unified interface to minimise context switching, while maintaining a human-in-the-loop approach where automation supports, rather than replaces, analyst decision-making in high-risk scenarios. Most interfaces are often dense and require expert interpretation. Visualisations such as anomaly graphs and threat timelines provide deep insight but can increase cognitive load under pressure.

The solution is centred around four key components:

Intelligent Alert System

A prioritised alert feed that highlights high-risk threats and reduces noise.

AI Summaries

A dedicated space showing why an alert was triggered, including behavioural patterns and evidence.

Unified Threat View

A consolidated interface combining logs, user activity, and historical data in one place.

Rapid Response Actions

Predefined, easy-to-execute actions such as blocking IPs or isolating devices.

UI Exploration

Between sketching and vibe coding, I put together some concepts for how we could approach the UI.

Cybersecurity Dashboard Design
Experimenting by placing all necessary information in cards in an organised manner.
Cybersecurity Dashboard Design 2
As a user clicks on a card, they'll see an AI summary in the middle so as to not overwhelm them. Extra data points were removed, which analysts didn't like.

AI Search and Alert Summary Types

We explored search functionality that enables analysts to use natural language prompts to quickly surface relevant threats, behaviours, and assets without needing complex queries. Instead of relying on manual filters or technical syntax, analysts can ask questions such as "Show all high-risk alerts from the last 24 hours," "Find users with unusual login behaviour," or "Any activity linked to this IP address?" The system interprets intent, aggregates data across sources, and returns contextualised results, allowing analysts to investigate faster and with greater confidence.

I worked with the content team to explore alert types that users can become accustomed to based on the nature of the alert:

Proactive alerts

Alerts generated before a threat fully occurs, based on predictive patterns and risk signals.

Examples:

Prioritised alerts

Alerts automatically ranked and filtered based on risk, context, and potential impact.

Examples:

Contextual alerts

Alerts enriched with relevant information and background context to support understanding.

Examples:

Actionable alerts

Alerts that directly suggest or enable next steps.

Examples:

Adaptive alerts

Alerts that improve over time based on analyst behaviour and feedback.

Examples:

AI Summary

05. Solution

In response to the challenges identified through research and workshop insights, the final solution is an AI-powered cybersecurity platform designed to support SOC analysts in making faster, clearer, and more confident decisions.

Rather than focusing solely on threat detection, the system reframes AI as a decision-support tool, helping analysts prioritise, understand, and respond to threats with reduced cognitive load.

The platform enhances the analyst workflow across four key stages:

The final concept transforms cybersecurity systems from passive monitoring tools into active decision-support platforms, empowering analysts to move from detection to action with greater speed, clarity, and confidence.

This solution aligns advanced AI capabilities with real human needs, ensuring technology supports rather than overwhelming those using it.

An efficient experience in which an analyst has a clearer view of what they need to prioritise and why.
Alerts dashboard
This interface presents a centralised AI-powered cybersecurity dashboard that helps SOC analysts monitor and prioritise threats in real time. It combines high-level metrics, visual insights, and a detailed alert feed to support faster, more informed decision-making and response.
Alerts dashboard panel
This interface allows analysts to quickly select an alert and view a detailed summary within the same screen, eliminating the need to navigate between multiple tools. By keeping investigation, context, and actions in one place, it enables faster exploration and more efficient decision-making through seamless interaction.

06. Reflection

This project reinforced the importance of designing AI systems around human decision-making rather than technical capability alone. While the technology behind threat detection is highly advanced, the real challenge lies in making that intelligence clear, trustworthy, and actionable for analysts working under pressure. Through research and collaboration, I learned that reducing cognitive load and improving transparency can have a greater impact than adding more features. Due to the legacy nature of some backend issues, this is an ongoing project but AI summaries alone have had a massive impact on analyst workflows:

"I don't have to dig through logs anymore: the summary tells me exactly what I need to know."
"Before, I'd spend minutes understanding an alert. Now I can make a call in seconds."
"I don't need to jump between tools anymore. Everything I need is already there."

Get in touch

I am always happy to discuss new opportunities or anything design related!

Contact Now