SQUALIFY
The BOM Suite
How do you design for executives you can't interview, and decisions that haven't been made yet?
Squalify.io · Senior Product Designer · 2023 to present
Strategy · Systems · Data

7 / 8
customers signed deals citing BOM + the Squalify model as the reason
12 / 14
BOM roadmap topics, shifting product direction in 2025-26
13 / 20
Enterprise prospects validated the prototype
2
Dashboards named in Squalify's US launch press release: Executive Report + Subsidiary Steering
CONTEXT
In 2023, Squalify's product was really a calculator, and the Delivery team built the actual story in PowerPoint, one screenshot at a time. 📊
Squalify is a cyber risk quantification platform, wholly owned by Munich Re. It models the financial impact of cyber incidents for large enterprises.
-
When I joined in late 2023, the product excelled at exactly one job: calculating financial numbers. Input in, output out.
-
The Delivery team hand-built every executive presentation in PowerPoint: their own narrative context wrapped around chart screenshots pulled from Squalify.
-
The platform extracted the data. Humans built the conviction.
THE REAL PROBLEM
-
Executives needed more than the numbers to lead with; they needed easy explanations and convincing storylines to back them.
-
Big organisations were already drowning in analytical dashboards. Their boards needed a flow that explained cyber risk quantification, still new to most of them.
THE REFRAME
From reporting to storytelling. From output to decision conversations.
So what questions do the board want answered about their cyber risk financial losses, their improvement plans, and what to look at across the group?
IN 1 YEAR (2025): DESIGNED, VALIDATED, GROWN
8 dashboards sharing one shell, each one built for a different board conversation. 🗂️
-
Question → Data → Description → Insight became the story-first structure inside every dashboard. Each section carried a specific board question with data, explanation, and context underneath. It grew into Squalify's design language.
-
The CSO's decades of customer conversations became our user research. C-level users were contractually inaccessible, so I ran live Figma brainstorming and wireframing sessions with the CSO, drilling in with framing questions to translate his customer knowledge into product structure. By the 8th dashboard, our rhythm ran on 2 brainstorms + 1 cleaning session, down from 6.
-
Prototypes became the discovery and testing layer. Each dashboard shipped as a prototype into sales demos and POV sessions. Consulting observations turned into product hypotheses. When the same pattern showed up across 3+ customers in different industries, that became the design brief.
WHAT WE BUILT
-
Each of the 8 dashboards supports a different strategic decision: setting a risk baseline, approving security investment, steering subsidiaries, meeting DORA obligations, managing third-party exposure, buying insurance, planning strategic moves, and managing live incidents.
-
Demo builds expanded from 1 industry to 3: a Banking Group, an Insurance Group, and a Manufacturing Group. Growth tracked our reach from DACH to the UK to the US.
-
Prototypes were also translated into German and Spanish as demand grew.
EACH DASHBOARD,
AT A GLANCE
Executive Report
-
Use case: regular cyber risk reporting to C-level and the board.
-
For: the starting page for every audience. Introduces Squalify's output metrics to CEOs, CFOs, CISOs, and CROs.
-
Key features: status metrics, balance sheet comparisons, YoY comparison, peer benchmark, monitoring.
-
One of 2 publicly named US-launch capabilities.

Budget Approval
-
Use case: securing C-level approval for additional cyber security investment.
-
For: on demand, but the top-feedback dashboard across every audience.
-
Key features: Risk Balance targets, 3 simulation options, risk-reduction modelling, ROSI calculation.
-
Started as 3 improvement-plan tabs, grew to 7 as customers stacked more plans, and opened to a flexible n-tab pattern at implementation.

Subsidiary Steering
-
Use case: a Group CISO steering across differently exposed entities or subsidiaries.
-
For: Group CISOs at large, global companies.
-
Key features: subsidiary selection and ordering, comparison-metric selection, 2 steering modes (different targets vs. same target).
-
One of 2 publicly-named US-launch capabilities.

CIF Dashboard (Critical & Important Functions)
-
Use case: DORA compliance. EU financial institutions must show board-level focus on their top Critical & Important Functions.
-
For: EU financial institutions regulated under DORA.
-
Key features: compare and rank top CIFs by Worst-Case-Loss metrics and Worst-Case scenarios.
%20comparison%20Dashboard.png)
Supplier Risk Management
-
Use case: manage the most-exposing IT providers as a current top risk-management focus.
-
For: on demand. Applicable across every audience.
-
Key features: compare and rank top IT suppliers by Worst-Case-Loss metrics and Worst-Case scenarios.

Large Incident Assessment
-
Use case: materiality assessment and monitoring of large cyber incidents over time.
-
For: on demand. Very specific for US-listed companies filing under SEC rules.
-
Key features: status of a live large incident by key information, comparisons with KPIs, incident history.
-
Spun off into a standalone sub-product: CIQ (Cyber Incident Quantification). Its own demo environment, partner and direct-customer sales decks, press release, and distribution across tier-1 IR partners in DACH and US (SECUINFRA, Mandiant, Unit 42, Kroll, MOXFIVE, InfoGuard, and others). Public launch materials in draft. Links to be swapped in once published.

Squalify experience
My first startup experience was a design leadership challenge: introducing product design thinking to a corporate startup where 90% of the team came from a consulting background.
Design system as AI-native scaffold.
Built the Squalify DS so components are readable by Claude Skills and Figma AI. Team can prototype without breaking pattern consistency. Detail on the Practice landing (coming soon).
Cross-functional alignment and sales enablement
Ran CSO / CEO / SME alignment workshops that landed a product-first framing. Enabled prototype-native selling: Sales moves live from platform to Figma prototype in the same pitch.
Introducing the product lifecycle to the company.
Designed two process flows: the company-wide collaboration between Product, Academy, and Sales, and the internal product development cycle. Ran workshops with the Academy team, SME and CSO included.










