The people using this product are paid to be skeptical.
CyberNest helps security teams find and use threat intelligence. If a profile is incomplete or a record is wrong, the software hasn't just made a bad first impression. It has given someone who evaluates risk for a living a reason not to trust the rest of it.
There was no product to redesign and no finished spec to follow. Ben had the idea. We had to work out what it should become while we built it.
Domain
Cybersecurity SaaS
Stage
Product Strategy and Build
Engagement
Working together since 2022
THE DECISIONSTHE DECISIONS
THE DECISIONS
THE DECISIONSTHE DECISIONS
The call
The scraper stayed. We built the work history it couldn't.
CyberNest used third-party scrapers to give new experts a head start on their profiles. The results were useful, but inconsistent: work history could arrive late, incomplete, or not at all.
We kept the scraper and built a first-in-class custom work history feature alongside it. The import filled what it could; experts had a guided way to add what it missed. That kept the head start without pretending the scrape was complete.
What we cut:The scraper as the full work history
01 · Start with the strategy
Work out the product while building it
There was no legacy code and no finished specification. Two engineers and a UX expert worked directly with Ben on the first flows, wireframes, designs, and features.
We stayed close enough to change the product as we learned instead of waiting for a perfect brief that wasn't coming.
02 · Work as part of the team
Join the standups and stay for four years
We joined standups, planning, retros, and the same Slack channels as the rest of the team. CyberNest's team got used to treating us like coworkers because that was how the work happened.
What began as one project kept going. The longer we stayed, the less time Ben had to spend re-explaining the product before we could make the next decision.
03 · Build what came next
The expert network was not in the original plan
CyberNest grew into a place where security professionals could connect with organizations that needed their help. That meant building the full consultation flow: requests, scheduling, and payouts.
This came out of years of working with Ben, not a feature list from the first month. By then we knew enough about the product to help decide what belonged in it.
Consultation requests, scheduling, and payouts for the expert network.
The system
The CyberNest now includes an intelligence workspace, team tools, publishing, onboarding, and the admin screens behind them.
What we built
01Intelligence workspaceSecurity teams could search, monitor, and work with threat intelligence in one place.
02CyberNest for TeamsTeams could share intelligence and keep track of their organization's security posture.
03Content publishing surfaceCyberNest could publish its own security research through a custom CMS.
04Custom work historyScraped profiles gave new experts a head start. The custom work history feature let them add what the import missed.
05Admin toolingCyberNest's team could manage customers, watch system health, and change security settings.
What it has to get right
Records
More than 4,000 intelligence documents are indexed. A search result only helps if the record behind it is complete enough to act on.
Onboarding
A new expert could start with scraped data, then finish the work history in CyberNest instead of waiting for the import to become complete.
Teams
Security teams share intelligence in one workspace so everyone isn't working from a different record.
Stack
Next.js · TypeScript · Prisma · Vercel
PROOFPROOF
PROOF
PROOFPROOF
Products in production
5
The intelligence workspace, team tools, publishing, onboarding, and admin tooling.
Working together
4 years
The first project turned into four years of ongoing work.
Intelligence documents indexed
4,000+
A searchable body of community-verified threat data.
They are the best team I've ever worked with regarding application development thus far.