Fortress Information Security

A single product can carry 300 vulnerabilities and only 20 that matter. We turned Fortress’ three siloed tools into one platform built to surface the 20.

PLATFORM
Web App
SIZE
Series C
goal

UI/UX Design

MPL Gaming
·
Real-money Platform
·
U.S. Market
At a glance

Fourteen weeks from discovery to boardroom.

01
Discovery · Both ends of the assessment.
Twenty-one conversations: twelve internal sessions across Fortress’ product, assessment, and account teams, seven interviews with security officers at the utilities that use the platform, and two industry SMEs, including the co-leader of the US Department of Commerce’s Energy Sector SBOM Proof of Concept.
02
Definition · One architecture for three products.
The existing platform was flat, with no hierarchy and heavy duplication. The new information architecture grouped everything into a cascade of discovery, organized around the three things users actually track: risk, progress, and compliance
03
Design · Six flows, lo-fi to hi-fi.
Adding a vendor, adding a product, reviewing a vendor assessment, reviewing a product assessment including SBOMs and HBOMs, working alerts and to-dos, and reviewing continuous monitoring, each taken through low, mid, and high fidelity with feedback at every stage.
04
System · Fortress Fusion.
The unified concept got a name, a high-fidelity prototype built to win internal investment, and an atomic design system to carry the work forward.
Drag / scroll →
RESEARCH
21
User interviews: 12 internal sessions, 7 customer interviews, 2 industry SMEs
CUSTOMERS
6
Utilities: AEP, Exelon, PSEG, Xcel Energy, Southern Co, and PJM
SCOPE
3 → 1
Three siloed internal tools folded into one platform
DELIVERY
14 wks
From Discovery to a high-fidelity prototype
The Client

The company securing the grid nobody thinks about.

MPL Gaming player base

Fortress Information Security is a supply chain cybersecurity company built for one job: protecting the vendors, products, and software that critical infrastructure runs on. From Orlando, Florida, it assesses supplier risk, analyzes software and hardware bills of materials, monitors products continuously, and tells utilities and federal agencies which of their thousands of suppliers is the one worth worrying about.

7 of 10
Largest publicly owned U.S. utilities protected
3 of 6
U.S. military branches served
$125M
Strategic investment from Goldman Sachs Asset Management
The Challenge

Customers had quietly stopped opening the platform.

A company protecting the nation’s power grid was delivering its findings as a 200-page PDF assembled from three separate tools, and the security officers it was written for had decided it was not worth reading. The work had moved to email.

Problem 01

Three tools, flat structure, endless duplication.

Vendors, products, and assessments each lived in a separate platform, and within each one the information map was flat: no hierarchy, everything surfaced at once, the same content repeated in multiple places. Clicking a link often landed you somewhere unrelated. The basics of UX were simply absent.

Problem 02

A sea of red with no priority.

A single software product analysis could surface 300 vulnerabilities of which roughly 20 were genuine threats. Customers described navigating a sea of red findings with no way to tell which ones mattered, and the platform offered no ranking to help them.

Problem 03

Reports too big for the staff who had to read them.

Monthly reports ran to 200 pages, were regenerated from scratch each cycle, and called out no deltas against a baseline. One customer had stopped using the continuous monitoring service outright, not because it was wrong, but because they had nobody to sift through it.

Problem 04

The product could not work without Fortress in the loop.

If Fortress did not spot something, the customer could not either. Assessments closed, results were emailed to the line of business and the vendor, and nobody logged in. White-glove service was covering for a product that offered no self-service path, and collaboration ran through inboxes where it could not be tracked.

Problem 05

Four audiences with four mental models.

Internal account handlers, vendors submitting evidence, customers making risk decisions, and insurance carriers pricing that risk all needed the same data for entirely different jobs. Not everyone even cared about the same pillar of it.

Drag / scroll →
Before / After

Same risk data, finally in one place.

Drag the handle to see the shift: three separate internal tools a customer had to stitch together themselves, beside Fortress Fusion, a single platform that assembles the picture for them.

Before redesignBefore redesign
After redesignAfter redesign
Before
After WANDR
Our Role

Brought in for a module. Stayed to design the platform.

01
Problem definition and refinement with internal stakeholders
02
Twelve internal stakeholder sessions across product, assessment, and account teams
03
Seven customer interviews with security officers and risk assessors at six utilities
04
Two industry SME interviews on where the SBOM and HBOM standard was actually heading
05
Secondary research into SBOM and HBOM formats, standards, and use cases
06
Vendor, product-verification, and find-vendor lifecycle mapping across the current platform
07
A new information architecture replacing a flat structure with layered disclosure
08
User flows and journey mapping across four audiences
Research

We asked the customers who had stopped logging in.

Research ran on both ends of the assessment: twelve internal sessions across Fortress’ siloed teams, seven interviews with security officers and risk assessors at AEP, Exelon, PSEG, Xcel Energy, Southern Co, and PJM, and two industry SMEs on where the SBOM standard was actually heading. In a sector where almost everything sits behind a wall, those SME conversations were the only way to see the ground we were designing on. Three findings shaped the platform.

01
300 → 20   ·   Signal and noise

The product was delivering the haystack, not the needle.

A single software analysis could return 300 vulnerabilities against roughly 90% of a product’s components, of which about 20 were genuine threats. As one SME put it, out of a hundred vulnerabilities, ninety-seven are not anything you need to worry about. Customers were being handed all one hundred and left to find the three.

02
200 pages   ·   Report burden

The deliverable was too big for anyone to act on.

Reports were regenerated monthly with no deltas called out and no baseline to compare against, so assessors had to re-read the whole thing to find what moved. One customer had dropped the continuous monitoring service entirely, saying they lacked the personnel to sift through it. Monitoring only works if something tells you when to act.

03
3 pillars   ·   What users track

Risk, progress, and compliance, and nobody wanted all three.

The research resolved into three things users actually track: risk across files, products, and vendors; progress, meaning what is open, in flight, and assigned to me; and compliance against internal and industry standards. Critically, not every client cared about all three, and people inside the same company cared about different ones.

One platform, 4 very different asks.

Persona 01
Casual gamer persona

The information security officer.

Sits at a utility, owns the risk decision, and has stopped opening the platform because the output does not arrive in a form she can use.

Customer
Decision-maker
Needs deltas
Persona 02
Committed player persona

The risk assessor.

Runs assessments day to day and needs streamlined, actionable reports with change callouts and baselines, not another 200-page document to read end to end.

Internal
Triage-first
Needs baselines
Persona 03
Office-context player persona

The vendor.

On the supplying side of the assessment, asked to upload the same evidence into multiple platforms multiple times, with no visibility into what happens to it next.

Supply-side
Evidence-heavy
Needs status
Persona 03
Office-context player persona

The insurance carrier.

Underwriting risk across the same supply chain and reading the same data for an entirely different purpose: comparability across a portfolio

Third-party
Risk-pricing
Needs comparability
The Strategy

Clarity over complexity.

The subject matter was never going to get simpler, so the interface had to. Every decision pushed toward the same outcome: turn a volume of security data no one could read into a short list of actions someone could defend.
01

Replace the flat structure with a cascade of discovery.

The old platform put everything on the surface at once. The new architecture leads with what matters most and lets a user go a level deeper only when they need to, then deeper again, grouped around the three pillars rather than around Fortress’ org chart.

02

Customer-first workflows, not business workflows.

The old product modeled how Fortress runs an assessment. The new one models how a security officer thinks about risk: my ecosystem, my vendors, my products, my outstanding items.

03

Lead with the delta, not the document.

Customers and assessors independently asked for the same thing: call out what changed and against what baseline. Reports had to surface movement since the last assessment rather than reprint 200 pages each cycle.

04

Score for trend, not for verdict.

Static scores read as ambiguous and rarely drove action. What mattered was the trend line: is this vendor responsive, are findings actually getting remediated, is the number moving and why. Score changes had to be explained, not just displayed.

05

Visibility at a glance.

Severity colour coding, portfolio scoring, and status indicators so a user can read pass or fail without parsing a paragraph. In a product built almost entirely from tables and charts, that is the difference between scanning and reading.

Principle 01 of
→ Continue scrolling
THE KEY INSIGHT

By week fourteen, the outsiders understood the business better than the insiders.

In information security, compartmentalizing information is a discipline. At Fortress it had become an accidental product strategy. Three tools existed because three teams did, and each team held one piece of a story nobody was telling end to end. People knew their own step and not how it affected the process around it.
The clearest evidence of that was uncomfortable. By the close of the engagement, the person who best understood what Fortress does end to end was our product strategist, because she was the only one who had spoken to everybody. That is not a compliment to us, it is a diagnosis. A product organized around an org chart will always hand the integration work to the customer, and the fastest way to see it is to send someone from outside to walk the whole floor and write down what they hear. The prototype was the visible output. Getting four internal teams to agree, for the first time, on one customer and one product was the thing that made it possible.

MPL redesign surface
MPL redesign surface
MPL redesign surface
MPL redesign surface
MPL redesign surface
MPL redesign surface
MPL redesign surface
MPL redesign surface
Screen 01 of 08
→ Scroll horizontally
Outcomes

What the work produced.

Fortress came in asking for a module and came out with a named product, a unified architecture, and the prototype it took to its own leadership.

01 · ARCHITECTURE
3 → 1
Siloed tools unified into one platform
vendors, products, and assessments in one structure
02 · SCOPE
6
Core flows Designed end to end and prototyped
vendors, products, SBOMs, assessments, alerts, monitoring
03 · SYSTEM
1
Design System delivered with the concept
Fortress Fusion, built to carry the products that follow
04 · DECISION
Green-lit
The concept cleared leadership review
and moved into Fortress’ next phase of development

Research figures are drawn from WANDR’s internal and external findings reports for Fortress, delivered 2023. Outcome 04 reflects Fortress’ decision at WANDR’s project close-out in May 2023, when the concept moved into Fortress’ internal development.

Client Voice

In their words.

“
The WANDR team impressed us right away, quickly understanding a complex business, engaging our stakeholders, and delivering value. It was refreshing and a joy to work with WANDR.
Replace · First Last
Title · MPL Gaming
Up next

Another story worth reading.

Buildbox case study preview
Next Case Study

Fortress

‍

No code gaming
·
SAAS
Read next case