Hello
top of page

Acme Analytics | Turning Security Noise into Decision-Ready Intelligence

Security teams face an overwhelming volume of alerts, fragmented tools, and limited context - making it hard to identify what truly matters.

Role

Lead UX Manager

Timeline

16 weeks · 2025

Team

4 UX Designers
2 UX Researchers
1 UX Writer
1 Product Director
2 Security SMEs
1 Product Engineer

Primary metric

46% ↓ alert noise
$2.1M+ annual savings

OVERVIEW

The snapshot

Challenge

Security teams were dealing with 18,000+ alerts a day from disconnected tools.
With 72% flagged as false positives, the noise buried real threats and slowed analysts down.

Approach

Led a 16-week UX research and design engagement.
Unified data, introduced AI-driven prioritization and explainability, and redesigned investigation workflows so analysts could focus on real threats.

Result

Cut alert noise by 46%, reduced mean time to respond from 2h 14m to 14 minutes, and increased analyst productivity by 37% in the first quarter.

HERO METRIC

46%

Reduction in alert noise, end to end

PROBLEM

What was breaking

Legacy fragmented security tooling before Acme Analytics unified the SOC workflow

18,000+ alerts per day with 72% false positives, overwhelming analysts and hiding real threats

Analysts used 5–7 tools per investigation, spending 63% of their time switching tools instead of investigating

Escalations delayed an average of 2h 14m, letting critical threats sit unattended

We aren't short on data. We're drowning in it. — CISO, Global Enterprise

DISCOVERY

How I learned it

Discover: stakeholder alignment & tool audit

Explore: 24 analyst interviews & contextual inquiry

Observe: investigation shadowing & workflow mapping

Synthesize & validate: co-design workshops with SMEs

18,000+ alerts ingested daily, with 72% identified as false positives or low priority

Found in review of 87 SIEM rule sets & 1,248 sampled tickets

Analysts use 5–7 tools per investigation, losing context between handoffs

Found in 32 shadow sessions & 24 analyst interviews

58% of investigations involve unclear ownership, with escalations delayed 2h 14m on average

Found in document analysis & stakeholder survey

INSIGHTS

The moments things clicked

Alert overload reduces signal quality

High alert volumes and false positives overwhelm analysts and hide real threats in the noise.

Context lives across too many systems

Critical information is scattered across siloed tools, forcing analysts to piece together the full picture.

Hospitals lack real-time visibility and control

Risk scoring lacks transparency, so analysts second-guess and re-validate what the system already checked.

STRATEGY

How I chose what to build

A compliance workflow so confusing, 1 in 3 users abandoned it mid-form.

A compliance workflow so confusing, 1 in 3 users abandoned it mid-form.

A compliance workflow so confusing, 1 in 3 users abandoned it mid-form.

A compliance workflow so confusing, 1 in 3 users abandoned it mid-form.

A compliance workflow so confusing, 1 in 3 users abandoned it mid-form.

A compliance workflow so confusing, 1 in 3 users abandoned it mid-form.

THE TRADE OFF

A compliance workflow so confusing, 1 in 3 users abandoned it mid-form.

SOLUTION

The final shape of things

1

Risk scores analysts can actually trust

Every alert ships with a confidence score and a plain-language reason code, so analysts stop re-validating what the AI already checked.

2

One incident, not a dozen alerts

Related alerts are automatically correlated into a single incident, reducing noise by up to 70% and cutting duplicate investigation work.

3

Every investigation, fully documented

A single investigation pane with timeline, evidence, and notes replaces scattered tickets and tribal knowledge.

IMPACT

What actually shifted

46%

Alert noise reduction

90%

Faster threat response

28%

False positive reduction

37%

Analyst productivity improvement

BEFORE

18,000+ alerts per day

2h 14m mean time to respond

12 tools in daily workflow

AFTER

9,720 alerts per day

14 minutes mean time to respond

5 tools unified into one platform

We didn't just ship a product. We changed how security gets done.

CISO, Global Enterprise

Curious how this could apply to your system?

REFLECTION

What I'd carry forward

What I'd do differently

I'd bring engineering into the explainability work earlier.
Trust in the AI turned out to be as much a design problem as a modeling one, and co-designing the reason codes from week one would have saved rework.

What this taught me

Great security products don't just process more data. They help people make better decisions, faster.
The real problem wasn't the UI. It was the broken system underneath it. Fixing the system made the right interface possible.

bottom of page