Safer pen testing for industrial systems

I co-founded this project and led product design. We were building a platform that lets industrial companies find security gaps in their factory systems without touching live production, by testing against a digital replica instead of the real thing.

2024

Year

DeepTech

Category

Figma | Framer | Miro | ChatGPT | Lovable | Fillout

Stack

Problem

Industrial companies are getting hit hard: manufacturing is now the most-targeted sector for cyberattacks<sup>1,2</sup>, and 73% of OT (operational technology) devices, the systems that run physical equipment on a factory floor, remain unmanaged, which makes them hard to secure and easy to miss.<sup>3</sup> 55% of manufacturers experienced an operational outage tied to a cybersecurity incident in 2024.<sup>4</sup>

The core problem with fixing this: testing for vulnerabilities usually means taking systems offline, and for a factory, that's expensive and often not viable. Security teams were stuck choosing between real risk and real downtime.

Sources: 1. Cybercrime Magazine, "Manufacturing Is The Most Hacked Sector. What Can Be Done?" 2. Exploding Topics, "How Many Cyber Attacks Occur Each Day (2024)" 3. Blackcell.io, "The State of OT Security" 4. Fortinet, "2024 State of Operational Technology and Cybersecurity Report"

Solution

The idea was a digital twin, a live-enough replica of a factory's OT systems, that security teams could pen test against instead of the real infrastructure. No downtime, no risk to production.

We didn't build that onboarding experience as software first. Instead, we ran expert interviews to understand the problem, then used a Fillout form as a lead-gen hook: a "free vulnerability assessment," asking prospects for details on their OT infrastructure, assets, and criticality. In exchange, they got a simple PDF vulnerability report, not a digital twin.

That real asset data then fed two things in parallel: the technical modeling behind an actual digital twin, and a Lovable prototype mocking up the product experience:

  • Dashboard for posture at a glance

  • Assets inventory (table or network map)

  • Prioritized Vulnerabilities list traceable back to each device

  • Reports view showing pen test history

We used that mockup for UX testing with the same people we'd interviewed.

Beyond UI/UX design, I worked on product strategy and the value proposition, helped design the startup website, did early-stage business development including cold outreach, and owned the design process end to end: research, discovery, defining pain points, through to the MVP screens above.

0+

Leads generated via cold outreach

0%

Conversion from cold call to pilot conversation*

0%

SUS usability score (vs. 60-65 industry norm)

0

Industry Experts Interviewed

Trade-offs & decisions

The hardest problem wasn't the dashboard. It was earlier: building a real onboarding flow, role selection, live asset intake, criticality tagging as software would have taken months before we knew if anyone wanted the product at all.

We replaced it with something faster to test: a fillout form positioned as a free vulnerability assessment, not the platform itself. Prospects gave us their real infrastructure data in exchange for a PDF report, and we used that data twice, once for the actual technical groundwork of the digital twin, and once to build a Lovable mockup we could put in front of the same people for UX testing. The pitch also shifted: instead of "give us access to your infrastructure," it became "get a free assessment, and test your systems without shutting down your plant, which normally costs a lot more than this." Lower friction, same destination, and it got us real data and real user feedback before writing a line of onboarding software.

Early on, we also considered letting users manually add every device into a live platform. We moved away from that too, for the same reason: it was more software to build before we'd validated anyone wanted it.

Workflow overview

Vulnerability assessment

Website preview

Dashboard overview

Vulnerabilities detail

Assets detail

Early ideas

Testing & Iteration

The dashboard itself went through several iterations, working with a student designer I was directing, before landing on the four-section structure above.

Once the full platform was built out in Lovable, we validated it end to end through moderated UX sessions with 22 industry experts: showing them the prototype, having them work through real tasks across the dashboard, assets, vulnerabilities, and reports, and watching where they hesitated or asked for clarification, especially around information density. At the end of each session, we ran a System Usability Scale (SUS) questionnaire covering the platform as a whole, a standard, quick way to get a subjective usability score. We landed on a SUS score of 64, above the 60 to 65 industry norm for data-heavy enterprise and OT security tools.

Key Learnings

Key Learnings

Designing for a specialized B2B, expert-only audience taught me how different "clarity" looks when your user already has deep domain expertise. The interface needed to respect that expertise, not simplify past it.

Cold outreach and expert interviews were slow and often didn't lead anywhere, but the ones that did gave me qualitative depth that no amount of desk research would have. Getting even a handful of real OT security professionals to talk through how they'd actually use the tool shaped the dashboard more than anything else.

Taking ownership across research, design, and outreach at once meant I was constantly switching between building the thing and selling it. That forced design decisions (like the intake form) that were as much about business viability as usability.

*Note: Leads and conversion reflect founder-led business development, run in parallel with design work. Not a direct design-caused metric.

Next Steps

We reached real user data and a clearer picture of what the product needed to become next. At that point, I made the decision to step back from the project due to differences with my co-founder on direction. A redesigned version of the site, aimed at improving on the initial 10% conversion rate, was in progress but never launched.

Moving forward, I'm applying these learnings to future projects: designing for highly specialized B2B markets, running lightweight usability testing early even with a small expert pool, and building trust-based entry points when direct access to a client's systems or data isn't possible on day one.

Want to dive deeper on this case study?

Many of my projects are not available publicly, but feel free to contact me if having any questions.

Want to dive deeper on this case study?

Many of my projects are not available publicly, but feel free to contact me if having any questions.

That's the end of this project.

Wanna hop to the next?

Designing for complex products in SaaS and AI.

I work with founders on B2B SaaS, AI, and other products where the design problem is figuring out what the product even is, not just how it looks. Available for freelance work.

Designing for complex products in SaaS and AI.

I work with founders on B2B SaaS, AI, and other products where the design problem is figuring out what the product even is, not just how it looks. Available for freelance work.

Designing for complex products in SaaS and AI.

I work with founders on B2B SaaS, AI, and other products where the design problem is figuring out what the product even is, not just how it looks. Available for freelance work.

Designing for complex products in SaaS and AI.

I work with founders on B2B SaaS, AI, and other products where the design problem is figuring out what the product even is, not just how it looks. Available for freelance work.

prototype blocks tested

Enter Password