Back to home

02, Cybersecurity & complex operations

OrganisationAZT Protect

AZT Protect

Monitoring an industrial estate and investigating what it reports

Across an industrial estate, location, protection status, inventory and data freshness need to be read together. The console moves from all sites to a single plant, then through zones, network relationships, endpoints, vulnerability findings and inventory composition, before an operator opens one event and records a review.

Product design · Industrial cybersecurity console · Figma design and prototype

Sheffield Manufacturing Plant dashboard: endpoint, protection, attention, offline, threat and compliance tiles above an isometric plant overview of the industrial site with annotated operating areas, a threat surface radar, highest exposure table, recent threat activity and protection efficiency panels.

Project brief

About

AZT Protect is an industrial cybersecurity console: a management plane where an operator monitors sites, reads endpoint grouping and inventory, triages vulnerability findings, investigates an execution event and records a review, without that review altering enforcement on the endpoint.

Problem

The design challenge was the complexity of sites, endpoints, applications and policies, and the need to understand security state without an investigation being mistaken for an act of enforcement. A recorded review must never read as permission granted, and a stale report must never read as lost protection.

Objective

Move readably from all sites to plant, zone, endpoint and application, keep inventory and assessment coverage honest about what is unknown, and state the consequence of a review before it is confirmed.

How the interfaces support the task

Desktop console: Monitor the estate, follow a site or zone into endpoint and application context, and investigate events with timeline and policy information side by side.

Tablet and mobile views: Tablet retains monitoring context; mobile prioritises the event timeline, supporting detail and review action in sequence.

Together: Across these views, recording a review documents investigation without changing application trust or endpoint enforcement.

Scope, work needed

  • Object model and journey from organisation through Trust Center, zone, endpoint and application
  • Plant overview, threat surface and exposure ranking compositions
  • All Sites comparison, zone grouping, network relationships and endpoint detail views
  • Vulnerability radar triage and inventory composition with assessment and freshness coverage
  • Investigation screen linking execution timeline, application context and policy impact
  • Review confirmation and recorded-review states
  • Semantic status, action and policy-domain component families
  • Desktop, 880 tablet and 390 × 844 mobile investigation layouts

Personas

  • Illustrative portrait of a person, used for the OT security operator design persona.

    OT security operator

    TaskMonitor exceptions on the plant and investigate why an execution was blocked or allowed.

    Design responseThe investigation view leads with the exception, its device and the evidence trail, with the action always in reach.

  • Illustrative portrait of a person in an office, used for the administrator design persona.

    AZT administrator

    TaskReview assignments and run day-to-day administrative operations across sites and groups.

    Design responseAssignment and admin screens separate what is being changed from what is protected, and show the state after review.

  • Illustrative portrait of a person, used for the read-only viewer design persona.

    Security / OT viewer

    TaskFollow protection status across the estate without changing anything.

    Design responseA read-only path through estate, site and device views keeps monitoring complete while write actions stay unavailable.

Design personas · Portrait · Alex Nguyen / Pexels; Portrait · Polina Zimmerman / Pexels; Portrait · Estevam Foto / Pexels.

Our contribution

Information hierarchy for the estate and the site, so an operator reads location, protection state and data freshness together before opening a single event.

Relationship design across endpoints, applications and policies, including policy coverage shown as an assignment structure rather than a single toggle.

The investigation and review flow, with confirmation and recovery states that state the consequence of an action before it is taken.

Semantic status patterns where meaning carries through label and icon as well as colour, and desktop, tablet and mobile compositions of the console.

Design narrative

01Overview

Overview orients the operator within a single plant before any issue is opened. Plant operating areas sit with endpoint, protection, attention and offline summaries, the threat surface, an exposure ranking, recent activity and operations status, so location and security context are read together.

Status and severity carry separate meanings here. An offline endpoint is a reporting question, while a severity value describes how serious a finding is, and the layout keeps the two from collapsing into one number.

Overview: operating areas, exposure ranking and recent activity in one read.

Figma source, frame 6:2 · Read source

02All Sites

All Sites lets an operator compare the organisation's plants and choose where to investigate. A world map is paired with an equivalent plant table listing reported protection, endpoint totals, alerts and last-seen time, with a focused panel for the site needing attention.

Last-reported data that has gone stale is presented as unknown current status, not as proof that protection has been lost. The locations and figures in this view are fictional illustrative content, not a Pfizer engagement or deployment.

All Sites: many plants read together, with stale data marked as unknown rather than unprotected. The plant table continues below the captured view.

Fictional illustrative estate. Locations, ownership and figures are prototype data, not a Pfizer engagement or deployment.

Map: Natural Earth, public domain · Figma source, frame 105:17281 · Read source

03Endpoints

Endpoints is the fleet overview. Protection, attention and offline summaries sit above a grouped endpoint map, with an attention panel naming the priority device, why it needs review and its latest event, and a ranked list of the endpoints most at risk below.

The screen is built for triage: it prioritises which device to look at next and routes into device inspection. The ranking uses illustrative weights rather than a validated security score.

Endpoints: fleet protection, attention and offline counts with the next device to inspect.

The risk ranking uses illustrative weights, not a validated security score.

Figma source, frame 479:42567 · Read source

04Zones

Zones explains how the site's endpoint fleet is grouped. Six operating areas, Engineering, Production, Robotics, Paint Shop, Packaging and Utilities plus Control, are drawn as workcells connected to the Trust Center, with attention and offline counts on each group and a priority endpoint panel bringing the next investigation into focus.

Zones draws the plant's operating areas as workcells connected to the Trust Center, while Endpoints draws the same groups as their devices, so each view answers a different question. The accompanying risk ranking is prototype prioritisation for the design, not a validated security score. The view describes grouped endpoint coverage and does not offer network segmentation or rule editing.

Zones: plant areas drawn as workcells linked to the Trust Center, with attention counts and the next endpoint to inspect.

The risk ranking is prototype prioritisation, not a validated security score.

Figma source, frame 79:14601 · Read source

05Network

Network traces relationships between site, Trust Center, operational group, endpoint, application and event. Plant topology is paired with the selected group's protection scope, inherited policy, signals and reporting status.

A relationship list gives the same content in words and routes toward endpoint, policy and investigation context, so nothing depends on reading the diagram. It shows reported relationships rather than live packet inspection.

Network: the spatial view always carries a relationship list as its text equivalent.

Figma source, frame 7:1458 · Read source

06Vulnerability Radar

Vulnerability Radar prioritises findings while keeping assessment coverage visible. The radar groups critical, high and medium findings alongside affected endpoints, checked versus pending endpoints and assessment freshness.

A priority review queue names the device and the finding, and a check-status panel makes incomplete coverage explicit. This is distinct from the dashboard threat surface, and it is a simulated prototype with no connected live vulnerability feed, no scan engine and no automatic remediation.

Vulnerability Radar: severity triage held next to how much of the estate has actually been checked.

Simulated prototype view. No live vulnerability feed, scan engine or automatic remediation is connected.

Figma source, frame 99:17111 · Read source

07Inventory Summary

Inventory Summary answers what the estate is made of and whether that record is current. A device-class catalogue covers workstations, PLCs, servers and HMI panels, with application and endpoint totals, the operational-group footprint and last-seen freshness supporting device-context follow-up.

Utilities and Control are combined in this view and labelled as such. The figures describe composition and freshness, not a count of vulnerabilities.

Inventory Summary: what the estate is made of, and whether the record is current.

Composition and freshness figures, not a count of vulnerabilities. Utilities and Control are combined in this view.

Figma source, frame 79:15727 · Read source

08Keep management separate from enforcement

The Trust Center is the management plane. Enforcement happens locally, at the Trust Agent on the endpoint. That separation shapes the whole journey: an operator can inspect an event and record a review without the interface suggesting that protection has been changed.

Policy coverage is shown as an assignment structure rather than a single toggle, so an exception can be read against the group it inherits from.

Policy coverage, an exception is read against the group it inherits from.

Application trust and execution policy remain separate controls.

09Connect the event to its cause and scope

The investigation screen places the execution timeline beside application context and policy impact. Endpoint, application and policy links give routes to supporting detail without leaving the event.

TrustID detail compares the trusted baseline with the observed execution, so the reason for the block is legible before anyone decides what to do about it.

Investigation, timeline, application context and policy impact side by side.

Illustrative event. Reviewing does not trust the application or disable protection.

TrustID detail, the trusted baseline and the observed execution are compared side by side.

Illustrative event. Completing a review never approves an unknown application or changes policy or trust.

10Explain the consequence before confirmation

The confirmation states plainly that the executable remains blocked and that application trust and endpoint policy are unchanged. Cancel and confirm are explicit actions.

This is the key decision of the project. Recording a review documents that someone looked at the event. It never grants trust, unblocks an executable or changes protection on the endpoint.

Confirmation, the consequence is stated before the reviewer commits.

Recording a review never unblocks an executable or changes policy or trust.

11Recompose the investigation for mobile

The mobile view brings the timeline and the review action forward. Supporting information moves into a narrower sequence instead of shrinking the desktop dashboard, and status words accompany colour throughout.

The same consequence wording travels with the action, so the smaller screen never loses the distinction between reviewing and enforcing.

Mobile, the timeline and the review action come first, not a shrunken dashboard.

Illustrative event data; recording a review does not change protection.

12Follow one site down to regional and assessment detail

Beneath the site comparison, a regional view carries one plant's location context, last-reported protection and the next connectivity check, and a site risk page separates assessment coverage from findings.

Both keep the same rule as All Sites: stale reporting is unknown data, and coverage that is incomplete says so.

Australia site detail: regional context, last-reported protection and the next connectivity check.

Part of the same fictional illustrative estate. Site state and figures are prototype data; stale reporting is shown as unknown, not unprotected.

Figma source, frame 107:20535 · Read source

Site risk and health, coverage and assessment freshness shown as separate questions.

Part of the same fictional illustrative estate. Assessment figures are prototype data; category counts overlap and must not be summed.

13What was delivered

Reusable status and action families, policy-domain controls and connected review states, documented as one architecture across the console.

Desktop, tablet and mobile compositions covering monitoring, investigation, review and recovery, with an interactive prototype of the investigation and review sequence.

Status family, semantic labels share a shape and never rely on colour alone.

Status components from the design file. Informational states are not enforcement guarantees.

Object model, incident route and recovery paths written down as one architecture.

Relationship views connect the product objects without replacing their administrative meaning.

Systems & responsive

Design system

A compact variable set covers primitives, semantic meaning and geometry, supporting semantic status labels, action states, rows and policy-domain controls. Component and pattern pages carry the operational model, so a status means the same thing wherever it appears.

Responsive behaviour

Desktop investigation presents the timeline and the application and policy context side by side. Tablet monitoring sits at 880px. Mobile at 390 × 844 prioritises the event timeline and the review action, with supporting detail following in sequence.

Prototype

AZT Protect · Prototype walkthrough

Monitoring and investigation walkthrough

Desktop management plane, recorded end to end.

2:20

Move through plant monitoring, network and zones, all sites, vulnerability radar and inventory composition, then follow alert activity into endpoint coverage and device detail, an investigation, the TrustID comparison and the policy coverage and policy dialog screens, before returning to the overview.

Recorded prototype walkthroughs with illustrative data.

The prototype covers monitoring and investigation: moving between all sites, plant overview, zones, network relationships, endpoint detail, vulnerability radar and inventory summary, then into an event where confirmation swaps to the recorded-review state and its return actions lead back to investigation and the dashboard. Policy editing, export configuration, vulnerability scanning and enforcement are represented as designed screens rather than working operations.

Project notes

A short set of notes on the material shown in the screens.

  • Sites, topology and security figures shown are illustrative prototype data.
  • Recording a review never trusts an application or changes endpoint protection. The executable remains blocked.
  • The Pfizer-labelled global estate is fictional illustrative content, not a Pfizer engagement or deployment.

Takeaway & evaluation

Operational security interfaces earn trust by separating investigation from enforcement, so an operator can review an alert with full context and always know that recording a review changes nothing on the endpoint.

Outcome metrics not available.

What to measure

Proposed evaluation, not conducted research.

  • Can an operator explain what recording a review does and does not change, before they confirm it?
  • Can they move from an alert to its endpoint, application and policy context without losing the timeline?