BACK TO WORK ARCHIVE
SVIGIL(SUPPLY CHAIN SECURITY)

Third-Party Risk Intelligence

Shifting SVigil (Supply chain security) from "data-heavy monitoring" to an "insight-driven prioritisation and remediation platform."

Scope of Work:AI EraLeading UXStrategised the adoption
CLIENT / DOMAINCloudSEK / Svigil(Supply Chain Security)
PROJECTThird-Party Risk Intelligence
YEAR2026
ROLELead Product Designer

Overview

Enterprise companies depend on hundreds of third-party vendors. Every vendor introduces security risks—exposed assets, leaked credentials, outdated technologies, vulnerable servers, and much more.

SVigil (Supply chain security) helps organisations continuously monitor these vendors.

The problem was that the product had become very good at collecting security data, but not very good at helping users decide what to do next.

Customers were looking at thousands of findings every day, but they still struggled to answer simple questions like:

QUESTION 1

Which vendors are the biggest risk?

QUESTION 2

What should I fix first?

QUESTION 3

Which action will have the highest impact?

Our redesign focused on answering these questions instead of simply displaying more security data. This direction is also reflected in the product vision of shifting SVigil (Supply chain security) from "data-heavy monitoring" to an "insight-driven prioritisation and remediation platform."

SVigil Redesign Overview
Click to view full screen

Understanding the Users

Before starting the redesign, we worked closely with the product team to understand how different users interacted with SVigil (Supply chain security).

Although everyone used the same product, they all had different goals.

Understanding the Users - CISO, Vendor Risk Manager, Security Analyst
Click to view full screen

The Problems We Found

After reviewing the existing experience, four major problems became clear.

The Problems We Found - Information overload, Lack of prioritization, Friction, Disconnected workflow
Click to view full screen

Defining the Experience

Instead of redesigning individual screens, we redesigned the product around four principles.

Defining the Experience - 4 Core Principles
Click to view full screen

Redesigning the Dashboard

Redesigning the Dashboard View
Click to view full screen

The dashboard became the entry point for decision-making.

Instead of presenting isolated widgets, every section answered a specific question.

Overall Risk Score

The first thing users now see is the overall organisational risk score.

This provides an immediate understanding of security posture without reviewing hundreds of vendors.

Risk Trend

Showing historical movement makes it easy to understand whether the organisation's security posture is improving or declining over time.

Critical Vendors

Rather than forcing users to search through long vendor lists, the dashboard immediately highlights vendors requiring attention.

Technology Exposure

Instead of viewing vendors independently, users can understand which technologies create the highest shared risk across the ecosystem.

Recent Updates

Recent changes help users understand what's new since their last visit, reducing the need to manually search for changes.

Helping Users Prioritize

Helping Users Prioritize - Exposure Snapshot & Score Improvement
Click to view full screen
Score Improvement Plan - Axis Bank Subsidiary Detail
Click to view full screen

One of the biggest changes was shifting from listing findings to prioritising outcomes.

Instead of asking users to fix everything, we introduced a Score Improvement Plan.

Each issue now explains how much it can improve the vendor's security score if remediated.

PREVIOUS CONVERSATION

"Here are 300 issues."

NEW CONVERSATION

"Fix these five issues first."

For security teams, this dramatically reduces the time spent deciding where to begin.

Making Investigation Faster

Making Investigation Faster - Tech Stack Exposure & CVE Breakdown
Click to view full screen
Asset Inventory & Geolocation Mapping
Click to view full screen

Security analysts often need to investigate before taking action.

Instead of navigating through multiple pages, we introduced focused investigation views that progressively reveal information.

Every issue presents:

  • Affected assets
  • Supporting evidence
  • Severity
  • Remediation guidance
Evidence-led Investigation Detailed View & Dark Web Scan Modal
Click to view full screen

This keeps analysts inside a single workflow while reducing unnecessary context switching. The issue drawer requirements emphasise evidence-led investigation.

Connecting Insight to Action

Connecting Insight to Action - Request Remediation Modal Workflow
Click to view full screen

Finding problems is only half the job.

Teams still need to work with vendors to resolve them.

To close this gap, we designed an integrated remediation workflow.

Users can:

  • select issues
  • preview expected score improvement
  • choose vendor contacts
  • edit the remediation message
  • send the request directly from SVigil (Supply chain security)

Instead of ending at analysis, the workflow now continues through communication and remediation.

Outcome

The redesign fundamentally changed how users interacted with SVigil (Supply chain security).

Instead of acting as a dashboard full of security metrics, the product became a decision-making tool.

The experience now helps users:

  • Understand overall business risk in seconds.
  • Identify which vendors need immediate attention.
  • Investigate issues with less context switching.
  • Prioritise remediation based on impact.
  • Start remediation directly from the product.

These outcomes directly support the goals defined in the PRD: improved dashboard engagement, better prioritisation, faster investigations, and greater remediation adoption.

DESIGN DECISIONS & STRATEGIC RATIONALE

Why the Overall Risk Score is positioned first:

CISOs and executive security leaders need immediate strategic posture awareness without wading through hundreds of raw vendor rows. Placing the score at the top left creates an instant executive cognitive anchor.

Why the dashboard uses progressive disclosure:

Security data overwhelm causes decision fatigue. Progressive disclosure allows analysts to start with macro organizational metrics, opening focused detail drawers only when investigating a specific anomaly.

Why certain cards are grouped:

Grouping Tech-Stack Exposure alongside Initial Attack Vectors connects infrastructure vulnerabilities directly to external threat intelligence, answering why an asset vulnerability matters.

Why the vendor page is organised in a particular order:

The layout prioritises action by showing the Score Improvement Plan before raw issue lists, turning an overwhelming issue count ("300 issues") into an actionable roadmap ("fix 5 key items").

What alternatives were explored and rejected:

We explored traditional flat data tables with extensive filter bars. We rejected this because user interviews confirmed that filters alone didn't solve the core question: "Which action yields the highest risk reduction?"