Sigalit Mualem
← Back to work

Malanta.ai · 2024-2026

Reading Risk in Seconds: Threat Cards, Semantics, and Pre-Attack Triage

My role: Lead Product Designer

2
Power users surfaced the same trust gap, unprompted, in separate sessions
3-step
Reading order: story, then evidence, then controls
70%
Of deep investigations start with a threat-card click, not manual entry

Tools

CursorFigma

Teams

Product DesignFrontend EngineeringProduct ManagementSecurity AnalystsThreat Research

Bottom line

My role: Lead Product Designer. I owned the threat card's information hierarchy, language, and triage interactions end to end.

The problem: Every field on the card competed for attention at the same visual weight, so analysts had to read the whole card before they knew whether to act, dig deeper, or dismiss.

  • Reordered the card into a clear reading order: story, then evidence, then controls.
  • Prevention scope and AI rationale now sit right next to Prevent; analysts reported less hesitation at the moment of commitment.
  • Empty and zero states are explicit, so the UI never implies more certainty than the data supports.

Challenge

Job to be done: an analyst opens a threat card mid-shift and needs to know within seconds whether it's urgent enough to act on, so they can commit to Prevent or move on without re-reading the whole card.
Before · Fields at equal weight
The original card was information-rich but cognitively heavy: fields competed at equal weight, with no obvious path through what's happening, why it matters, and what to do now.
Rationale and prevention scope lived apart from the moment of commitment, increasing hesitation exactly when analysts needed speed.
Two of the platform's super users said this almost word for word in usability testing: they could see the threat and the assets it named, but not why it was urgent, so committing to Prevent meant taking the AI's word on faith.

Approach

Reorganized content into a deliberate scan order: risk narrative first, supporting metadata second, controls last.
Shipped · Story, then evidence, then controls
  • 1Story leads: What's happening, in plain language, before any field ID or severity badge competes for attention.
  • 2Evidence second: Exposure type, asset status, attack infrastructure: supporting metadata earns its place after the narrative, not before it.
  • 3Controls last: Prevention scope and the AI rationale sit right next to Prevent, so committing to it isn't a leap of faith.
Introduced progressive disclosure so dense fields never drowned primary risk signals.
Co-located prevention scope with the primary Prevent action and added a card-level AI explanation, built to answer that exact trust gap, not as a default AI feature.
Mapped every backend concept to a defined UI layer with threat research, with conditional rendering for zero and empty states.
None of the card's badges or the AI explanation panel were built from scratch: they're instances of the component library first governed in Imminent Threats, reused here rather than reinvented.

Impact

Stronger first-screen orientation and faster scanning in high-density triage views.
Higher trust: explicit empty and zero states, honest confidence signals, dismissal paths that don't fight the primary remediation story.
The AI explanation shipped scoped to the card, wired to the same object the card renders, because that's where the two testers said the trust gap actually lived, not on a generic help screen.
Card clicks account for 70% of all entries into deep investigation (120 of 172 IoPA visits over six months), evidence the reordered hierarchy, story then evidence then controls, gets analysts to a decision fast enough to act on, not just read.
Analysts spend a median of 163 seconds on the page holding these cards each visit, real evaluation, not a skim past the headline.

Validation

Two independent sessions, the same trust gap, unprompted

Same embedded relationship as IoPA and Scopes: 2 power users, not external test subjects, in a SOC analyst base too small (5-10 active users at any point) for a quantitative test to carry weight on its own. What makes this finding worth citing isn't sample size, it's that neither analyst was asked directly about trust in the AI. Both raised the same gap unprompted, in separate sessions, while walking through unrelated tasks on the card.

Both power users said close to the same thing: they could see the threat and the assets it named, but not why it was urgent, so committing to Prevent meant taking the AI's word on faith.

Changed to:

A card-level AI explanation, wired to the same object the card renders, scoped to that one threat instead of a generic page-level help icon.

What I'd do differently

Retrospective

  • The trust gap that justified the AI explanation came from two power users. I haven't tested whether that trust pattern holds across every threat type and severity, or only the scenarios those two sessions happened to cover.
  • I haven't measured scan time or dismissal accuracy before and after the reorder, the hierarchy change is grounded in the testing sessions, not in instrumented before/after numbers.
  • Card click-through isn't universal: at least one enterprise account splits roughly evenly between clicking a card and entering an indicator directly into IoPA, a reminder that experienced analysts sometimes route around the card entirely once they already know what they're looking for.