A case study on the development of a CISO dashboard to provide security leaders with real-time visibility and actionable insights.
The key reasons for this research are the uncertainty of the end user, unspecified CISO Dashboard KPIs and requirements, and the uncertainty of the legacy components needed for the CISO Dashboard view.
The research aims to validate the end user focus persona (CISO/CIO), define the CISO Dashboard functional requirements, and reveal the legacy relevant components to migrate to the new product.
The research will align with the end user needs - the CISO - to understand the risk in the organization and fill the unknown for the CISO.
The research aims to validate the end user focus persona as the CISO/CIO, understanding their responsibilities and day-to-day activities.
The research will explore the CISO's key responsibilities, such as managing cybersecurity risks, ensuring compliance, and making data-driven decisions.
The research will aim to understand the typical day-to-day activities and workflow of a CISO, to ensure the dashboard aligns with their needs.
The research will validate the assumption that the CISO will be the primary end user of the dashboard, and explore any other potential user groups.
The research will identify the key performance indicators (KPIs) that are most critical for the CISO, to ensure the dashboard provides the necessary insights.
The research will explore the expected frequency and duration of usage for the CISO dashboard, to inform the design and development process.
Conducted qualitative interviews with internal subject matter experts to gather in-depth insights and perspectives.
Interviewed CISOs from other organizations to understand their responsibilities, pain points, and requirements.
Performed online open-source intelligence (OSINT) Desk research to gather additional insights and validate findings.
Conducted a thematic analysis to define the key performance indicators (KPIs) that are most critical for the CISO.
Gathered feedback from CISOs through a prioritization matrix survey to understand their top priorities and requirements.
Performed a gap analysis to identify the differences between the new CISO dashboard KPIs and the former capabilities.
Identified "quick win" opportunities that could be implemented quickly to provide immediate value to the CISO.
Interviewed CISOs from other organizations to understand their responsibilities, pain points, and requirements.
Conducted qualitative interviews with internal subject matter experts to gather in-depth insights and perspectives.
Performed online open-source intelligence (OSINT) research to gather additional insights and validate findings.
Conducted thorough online research to complement the qualitative interviews and uncover a broader range of data points and perspectives.
Conducted a thematic analysis to define the key performance indicators (KPIs) that are most critical for the CISO.
The thematic analysis provided a structured and rigorous framework to deeply examine the research data and identify the most important KPIs for the CISO dashboard.
Gathered feedback from CISOs through a prioritisation matrix survey to understand their top priorities and requirements.
The prioritisation matrix survey allowed us to directly engage with CISOs and gather their input on the most critical KPIs and features for the dashboard.
By analysing the survey results, we were able to identify the highest priority KPIs and requirements from the CISO perspective, informing the development of the dashboard.
The survey helped validate our assumptions about the CISO's needs and priorities, ensuring we were aligned with their real-world requirements.
Performed a gap analysis to identify the differences between the new CISO dashboard KPIs and the capabilities of the legacy security systems.
The gap analysis allowed us to pinpoint areas where the new KPIs and requirements were not fully supported by the existing security tools and components. This helped us understand where integration challenges or additional development might be needed.
The research team highlighted "quick win" opportunities that could be implemented quickly to provide immediate value to the CISO.
By identifying these "quick win" solutions, the team was able to take a pragmatic and action-oriented approach to delivering tangible improvements to the CISO dashboard.
Stakeholders pivoted into approaching lower level persona
Stakeholders rethought the persona and considered the time and effort required for the changes.
The team adjusted the solution to better address the persona's problem space, taking into account the new insights gained from the research.
The research provided a better understanding of the time and effort required to implement the product changes.
The research insights helped the company save money by identifying more efficient solutions.
The research discovered the personas that will use the tool, providing valuable insights to better address their needs.
The research helped orient product decisions towards a stronger sales focus, improving the product's market fit.
The research fostered stronger strategic collaboration with the stakeholders, aligning the product roadmap and development.
The researcher's job is never over. This is an ongoing process.
Assumptions and reality are two different things.
Always ask questions, even question the research itself.
Raising flags is important. When necessary, do that.
Continually sharing back is super critical. Can save money.
Pivot can be a very good outcome as well!
Products are only great if there is a precise market for them.
Interview less external CISO's, conduct 2 researches at once (both personas), and delegate to other team members to simultaneously research in addition to the lead researcher.
If allowed, use AI to cross-check the primary research insights with the Osint secondary insights, to accelerate the process.
CISO Dashboard