Data Loss Prevention @ RBC

Design Engineering Intern

|

May - August 2025

|

Figma, ReactJS

This work is under NDA ˙◠˙

If you're interested in learning more, please contact me at ariciac@andrew.cmu.edu

PROJECT OVERVIEW

Reimagining the Data Loss Prevention (DLP) Dashboard

I joined RBC as a Design Engineer Intern on the Data Loss Prevention (DLP) team where I was tasked with the job of redesigning an internal dashboard that tracks all data loss incidents at RBC.

The current dashboard was created using Tableau, and the DLP team was looking to develop it from scratch internally. Along with three developers and a PM, I served as a front-end developer and sole designer on the team.

SOLUTION & IMPACT

Before & After

Previous Experience

01

Overwhelming information

Difficult for users to process all at once

02

Inefficient navigation

Convoluted user flows, confusing filtering system

Redesigned Experience

01

Clear hierarchy

Streamlined data visualization and UI redesign

02

Increased usability

Revised filtering and sorting system

480+

total users

140+

weekly users

74%

increased time efficiency

RESEARCH

Diving into data loss procedures

Whether or not employees realize the risks behind their actions, potential DLP incidents are flagged every day. My first challenge was to understand how RBC approaches cybersecurity and data protection as a whole.

To build a solid foundation, I initially turned to my manager for a high-level overview and then connected with several members of the DLP team to dive deeper. However, I soon realized the best way to truly understand all the nuances when it comes to DLP protocols is to interview employees in the cybersecurity space.

ANALYSIS

Better understanding DLP protocols through user research

Through user interviews, I strove to:

  1. Better understand DLP protocols

  2. Learn how employees use the DLP dashboard

I created an affinity map to synthesize my findings and help me better make sense of the dashboard.

70+ surveys

participants ranged from auditors, managers, IT staff, VPs, developers and more

participants ranged from auditors, managers, IT staff, VPs, developers and more

18 interviews

to truly understand paint points and iterate on potential solutions

to truly understand paint points and iterate on potential solutions

How migh we enable managers to efficiently obtain an accurate, high-level overview of the breadth and depth of data loss at RBC, while also providing internal auditors with access to the underlying details?

I mapped out the Data Loss Prevention flow, and the ways in which the DLP dashboard is used within the flow for both auditors and managers.

Wants the big picture: Managers
  • Understand the breadth and depths of data loss at RBC and within their jurisdiction

  • Prevent future incidents from occuring

Wants the details: Internal Auditors
  • Determine which incidents to audit

  • Obtain information about their assigned cases

KEY DESIGN EXPLORATIONS

Organizing data by category and frequency of use

The existing dashboard had 5 pages. 4/5 pages were reported by users to have seemingly arbitrary graphs that were not sorted or clearly defined.

Specialized filters for different auditors

A key pain point for auditors is that the dashboard did not have built-in filters for auditors to sift through the cases they need to asses. As a result, most auditors were manually exporting data from the dashboard as a CSV file.

I spoke with first, second, and third line auditors to identify the additional filters that should be added, sorting requirements between "must-have", "nice-to-have", and "bonus".

Using RIG, RBC's design system

RBC has a comprehensive design system called RIG. I spent hours parsing through the documentation to familiarize myself with the design system and to make sure my dashboard aligns.

Data visualization & micro-interactions to communicate concisely and reduce visual clutter

Many managers, especially ones that oversee data loss at a higher level, first focus on trends before examining numbers. The existing dashboard often had graphs that weren't cohesive with one another. I standardized all graph styles and displayed them based on most interacted with after looking at a heatmap of the existing dashboard.

REFLECTION & NEXT STEPS

This project was handed off to a team of developers

I made sure my design files were developer ready, front-end code was readable and properly structured, as well as created several screen recordings to explain my process and the functionality of the dashbord.

Make the most of interviews & surveys

I learned that asking open-ended questions and creating space for participants to share stories often revealed deeper motivations than surface-level responses. Pairing quantitative survey data with qualitative interview feedback allowed me to validate patterns while also uncovering nuances that shaped design decisions.

Designing for various (and often competing) use cases

The dashboard had many different users with different (and often contradicting goals) so it was a challenge to find ways to present both granular details and a high level overview. I had to get creative with interactions,

I found that the following were particularly useful

  • Microinteractions

  • More filters

  • Exporting data for auditors

Thanks for stopping by!

Care for some tea?

Thanks for stopping by!

Have a sip of tea