Samsung
2024
Endpoint Security Internal Risk Management
To design a system to enable security officers to efficiently manage insider anomalies.

Project Background
As the service transitions from an on-premise model to SaaS, the project aims to develop a system that leverages user logs to empower security officers, ensuring more efficient and effective security management
From research to ideation
Due to security constraints preventing user interviews, we investigated workflows and support methods for insider risk management across different solutions. The findings were reviewed with security officers to generate ideas and identify areas for improvement.

Product Development
Home/Dashboard
Shows insider risk status and user analytics overview in chart/graph format.
Save Log Functionality
Allows security officers to save suspicious log activity for future monitoring.
Action & Investigate function for Advanced Activity
Security officers can search for specific incident that Machine learning detected, and can take action on suspicious activities or examine detailed logs through investigate feature
Generative AI Chatbot
Even first time users can easily and quickly navigate security policies and manuals through generative AI chatbot


