Split donuts
Why it failed: Equal scale implied recommended controls held equal operational urgency to mandatory audit blockers.
Cloud Administrators didn’t know Cyber Resiliency capabilities—and even when they did, baseline security lived across 6 Scattered Pages. I designed discovery onboarding plus a Readiness Score for Mandatory and Recommended setup in place.
Confidentiality note: This project is under NDA. Design is complete and moving into development. Interface redrawn and figures synthesized for case study presentation — core architectural logic and UX constraints remain true to production.
Problem 01
Problem 02
Solution
Existing
Shipped
Explore Cyber Resiliency Features → solves Problem 01
Cyber Resiliency Readiness Score → solves Problem 02
“I don’t have time to check six settings pages. I need to know what’s wrong and fix it before InfoSec asks.”
Jordan opens Security Center in the morning, then jumps into other IT work. When InfoSec asks whether basic controls are configured, Jordan has to prove it fast. The hard part: learning what the product offers, seeing what’s misconfigured, and fixing it — without becoming a full-time compliance person.
Problem 01 · Onboarding
The tools were already in the product — buried in the sidebar with no plain explanation. First-time Cloud Admins landed cold. Paid protections went unused, and when new features shipped later, there was still no reusable place to introduce them.
Solution: Explore Cyber Resiliency Features
Problem 02 · Security posture
Basic protections — Multi-Factor Authentication, Single Sign-On, Geofencing, Reports, Alerts, and Restore Scan — lived across six separate pages. The old screen only showed a static risk list. It did not walk admins through Mandatory vs Recommended tasks, so gaps stayed open longer.
What was broken
The goal
Make readiness feel like guided setup — walk the user through Mandatory and Recommended tasks so they actively strengthen security, instead of staring at a static risk list.
Before
Six disconnected settings menus for one hygiene check.
After
One Security Center anchor with in-context fix.
Time spent
Multi-page hunt across disconnected settings before Jordan even knew what was missing.
Reduced friction
Single-hub remediation — scan, locate the gap, and fix without leaving the dashboard.
Problem 02 · Iterations
Two failed visual models, then a shipped hierarchy: Mandatory and Recommended cannot share equal visual weight.
Why it failed: Equal scale implied recommended controls held equal operational urgency to mandatory audit blockers.
Why it failed: Concealed mandatory audit blockers behind small asterisks in an adjacent text list.
What shipped: Inner arc (Mandatory) + outer arc (Recommended) + interactive Gauge/List toggle + in-context configuration modals.
Problem 02 · Shipped
Inner arc tracks Mandatory progress; outer arc tracks Recommended. A Gauge/List toggle lets Jordan switch between macro compliance and a granular action list—then fix gaps in place.
01 · Macro
Answers “is my environment protected?” at a glance. Inner ring = audit-blocking Mandatory controls. Outer ring = risk-reducing Recommended controls. Hover reveals the exact gap.
02 · Micro
Answers “where is the immediate exposure?” Direct pass/fail status with pencil edit affordances per row, plus Mandatory asterisks and subscription minimums.
03 · Action
Answers “can I fix it without leaving?” Local modals let admins configure missing settings — SSO, Alerts, Geofencing, and more — without changing routes or losing page state.
Same Security Center hub — switch between Gauge (macro scan) and List (remediation checklist).
Decision 01
Supports two mental modes—scanning the high-level score (gauge) or reviewing specific failed controls (list).
Decision 02
Edit opens configuration flows in a local modal so admins fix gaps without leaving Security Center.
Decision 03
Dashboard arranged top-to-bottom from macro readiness down to active risk triage and threat hunting.
Deliberate tradeoff: Nested arcs alone weren’t enough for micro-tasking. We kept the concentric hierarchy for scanning, then offloaded the full checklist into a toggleable List view so the widget stayed scannable without sacrificing actionability.
Impact
Explore Cyber Resiliency Features gives new admins a guided tour on first login—and a reusable surface when future capabilities ship.
Reduced 6-page setting navigation to in-context local modals—higher baseline adoption without leaving Security Center.
Clear visual hierarchy plus Gauge/List toggle supports both executive macro-scanning and admin micro-tasking on one card.
Product demo
Druva's official walkthrough of the Security Center — real-time visibility into backup security risks, readiness scoring, and threat triage in one unified dashboard.
Watch product demo →
Confidentiality note: This project is under NDA. Design is complete and moving into development.
Interface redrawn and figures synthesized for case study presentation.
The core architectural logic and UX constraints remain true to production.