
Cloud Security
Cloud Web Application FirewallUX Revamp
Designing trust, safety, and scale in enterprise security.
The problem
The UX needed to reduce risk
Who used it
- Worked in the product daily
- Were accountable for outages and breaches
- Needed to move quickly without introducing risk
What went wrong
- Blocking legitimate traffic
- Leaving vulnerabilities exposed
- Losing trust internally and externally
Constraints
Every decision was shaped by what we could not change
- 01Core data model could not change
- 02Large legacy UI already in production
- 03Multiple security products depended on this foundation
- 04No design system or UX standards
- 05Limited customer access early on
- 06Engineering and product teams were new to working with UX
My role
Systems designer and cross-org partner
Principal Product Designer responsible for vision, research, workflows, and the design system—not just screens.
- Product and UX vision
- User research and validation
- End-to-end security configuration workflows
- Foundational design system
- Partnership with engineering and product
Design principles
Aligned decisions across teams
Control
Users can fine-tune behavior without fear.
Trust
The system clearly communicates protection and outcomes.
Confidence
Users understand the impact of their actions.
Core insight
Users think in systems—not wizards.
Security configuration is not linear. The existing wizard forced a step-by-step flow that hid relationships between controls, made changes hard to revisit, and promoted a “set it and forget it” approach.
We chose clarity and transparency over hiding complexity.
Core design decisions
From wizard-based configuration to a policy-based system


Tradeoffs
Visible complexity over hidden risk
What we gained
- Visibility into how protections work together
- Safer iteration and fine-tuning
- A scalable foundation for future products
What we accepted
- More visible complexity
- A learning curve for existing users
In security, hidden complexity creates more risk than visible complexity.
Designing for scale
New protections without rethinking the model
Phased implementation
01
Shared Resources
Engineering Phase 1
02
Security Config Versions
Engineering Phase 2
03
Editing a Security Policy
Engineering Phase 3
04
Security Configuration Overview
Engineering Phase 4
Integrating with the legacy system safely reduced risk while maintaining momentum.

Closing the loop
Configuring security is only half the job
Without validation, confidence is false. Reporting became a core UX component—connected to configuration, validating effectiveness, supporting rollback, and reinforcing trust.
- Expose misconfiguration patterns
- Inform smart defaults and grouping
- Reduce fear of making changes
Outcomes
Impact across users, product, business, and org
Security BU growth from ~$200M to $1.2B, with a shared foundation across seven security products and growing.
User
- Faster, safer configuration
- Increased confidence
- Reduced cognitive load
Product
- Shared foundation across 7+ security products
- Scalable system for future growth
Business
- Security BU growth from ~$200M to $1.2B
- Increased adoption of advanced protections
Org
- UX process where none existed
- Trust between UX, Product, and Engineering
- Grew designers, researchers, and UX writing
UX became a strategic partner, not a service function.
“I have been able to try out the new security policy editor UI… and I love it! It’s a major process/workflow improvement… This UI (and the color coding) help us to quickly move through the UI.”
“Bonnie is the mastermind behind this amazing UX revamp… we wouldn’t have been able to achieve this milestone without her creativity, vision, dedication and leadership.”
Reflection
How this shaped how I design at scale
These principles guide how I approach complex, high-stakes products today—navigating ambiguity, designing under constraints, and aligning systems, people, and outcomes.
UX as risk reduction
Systems over screens
Trust as a design outcome
Validation over assumptions
This is the kind of impact I’m excited to bring to my next role.