Case study

Building CyberShield360

At Invia, I designed and helped launch an attack surface management product that turns external asset discovery into prioritized exposure information.

Invia · Senior Security Engineer · September 2022–November 2023

Featured build Built at Invia · 2022–2023

CyberShield360

From an exposed asset to an actionable finding.

I designed the architecture and security workflow for an attack surface management product, and helped take it to launch.

Explore the workflowIllustration · Example data
ASSESSMENT SCOPE example.com Web application app.example.com API endpoint api.example.com IP address 198.51.100.24 Web application app.example.com API endpoint api.example.com example.com IP address 198.51.100.24
An inventory of assets to assess

01 Discover

Make the external footprint visible.

Bring domains, IP addresses, and exposed services into a view that a security team can investigate.

Design decision

Start with a defined assessment scope and make discovery repeatable as the environment changes.

api.example.com OBSERVED SERVICE HTTPS · 443 IDENTIFICATION Web endpoint CORRELATION Version match Needs validation Correlation is the start of investigation. api.example.com HTTPS · 443Observed service Web endpointIdentification Version matchCorrelation Needs validation
An asset with supporting evidence

02 Enrich

Add context to every observation.

Connect each asset to service information and relevant vulnerability data so an analyst has a useful starting point.

Design decision

Keep a version match distinct from evidence of exploitability. Correlation starts an investigation.

Exposure Evidence Context Analyst review Make the reasoning and uncertainty visible. Investigation priority Exposure Evidence Context Analyst review Reasoning + visible uncertainty Investigation priority
A reasoned investigation priority

03 Prioritize

Turn signals into a risk decision.

Use exposure, supporting evidence, and the affected service to decide which findings deserve investigation first.

Design decision

Give the security team the context behind a priority, with uncertainty visible alongside the finding.

Finding → engineering action AFFECTED ASSET api.example.com SUPPORTING EVIDENCE Exposure + impact RESPONSIBLE TEAM Service owner NEXT STEP Review evidence and plan remediation Finding → engineering action Assetapi.example.com EvidenceExposure + impact TeamService owner Next: plan remediation
A finding ready for remediation triage

04 Report

Give engineering enough to act.

Present the affected asset, supporting evidence, and remediation context in a report the responsible team can use.

Design decision

Design the output around the next engineering action, making the finding understandable beyond the security team.

My ownership
Product architecture, security design, and the discovery-to-reporting workflow.
Design trade-off
Broad discovery needed validation and context to become useful signal.
Shipped result
A launched product, introduced in Invia’s public launch videos.

An illustrated explanation of the documented workflow. Invia’s original launch video

CyberShield360 · Illustrated workflow

An asset’s journey to action

The problem

Security teams needed a repeatable view of their internet-facing assets and changing exposure. Periodic assessments and manually maintained inventories made it difficult to keep that view current across multiple customer environments.

CyberShield360 brought discovery, analysis, and reporting into a product workflow that teams could use for ongoing triage.

My ownership

I owned product architecture and security design, defined the discovery and analysis pipeline, and worked with engineering and leadership to scope and launch the product.

This included translating security requirements into product priorities and deciding how findings should be presented to the people responsible for remediation.

From assets to decisions

The interactive illustration above follows four stages: discovery, enrichment, prioritization, and reporting. It explains the operating model using example assets. The 75-second visual tour covers the same workflow with captions and a written transcript.

Design priorities

Repeatability: discovery and enrichment needed to support continuing assessment across environments.

Useful signal: service identification and CVE correlation are starting points for validation; a matched version alone should not be presented as proof of exploitability.

Actionable output: asset context and prioritization needed to help a security team decide what to investigate or fix next.

Delivery and public evidence

The product reached launch. Invia’s public videos introduce its capabilities and positioning; the Invia product page provides the wider product context.

This work extended my role from conducting assessments to building the system through which teams discover, understand, and track exposure.

← All case studies Discuss this work →