Translating customer insight into direction

Security Experience Map for F-Secure


  • Company: F-Secure Corporation
  • Industry: Consumer cybersecurity, B2C/B2B2C
  • Role: Service Designer
  • Team involved: Design Function, Threat Intelligence, Product Marketing
  • Duration: August 2025 - December 2025
A snapshot of Security Experience Map
A snapshot of Security Experience Map

The Problem

F-Secure's UX Research team had just completed the company's first comprehensive strategic research into how consumers actually experience security by covering mental models, emotional needs, and expectations of protection across three markets (US, UK, Japan). It was rich, foundational work in service of F-Secure’s vision of becoming the No. 1 Security Experience Company in the world.

F-Secure delivers security across multiple product formats: standalone products, feature-level solutions, and SDK integrations, which meant research insight needed a way to travel across formats rather than being locked to any single one. That raised the real question behind this project: how might we turn foundational research insight into opportunities that are centered on experience, independent of product, solution type, or technical implementation?

The research covered: What was missing wasn't more research. It was an artifact that could sit between insight and product strategy. Something that kept opportunities tied to evidence without locking them prematurely into a specific solution.



The Method

I designed a four-layer system to convert research insight into strategic opportunity: Foundation → Coverage → Gap → Opportunity.

Foundation

Because this was the first experience-focused journey map at F-Secure, there was no existing template or standard to follow. We first needed to decide what the security experience should be built around.

One insight from the research stood out clearly: People don’t experience security through product flows. They experience it in moments when something feels risky or uncertain. These are the moments when the need for security becomes real.

So, rather than building around personas or product flows, the map is built around digital moments:. This choice also aligned directly with F-Secure’s mission: F-Secure exists to make every digital moment secure, for everyone.

The Foundation of the map

For this purpose, we used an existing input from the Product Marketing team: an annual large-scale survey conducted in Europe and the United States. The survey identifies digital moments that consumers find both important and worrying from a security perspective. These moments are analyzed using a matrix that combines:

How important and worrying the moment is for consumers

A threat score based on impact, probability, and how many people are affected

This meant digital moments alone were not enough. To make the map useful for identifying opportunities, we also needed to understand where people are actually at risk within each moment.This helped us extend the foundation to digital moments with potential vulnerabilities.

For each moment, we identified vulnerabilities that describe how consumers may be at risk (technically, emotionally, or through their behavior). In the first version of the map, we focused mainly on scam-related and malicious vulnerabilities, as these are among the most common and impactful risks in everyday digital life.



Coverage Layer

The Coverage Layer shows how well F-Secure currently protects consumers in each digital moment against the vulnerabilities identified in the foundation. Its purpose is not only to check whether protection exists, but to understand how that protection is experienced by consumers. The layer looks at coverage from two perspectives:

The coverage layer of the map

F-Secure's Reaction: This examines whether F-Secure’s existing products, features, or capabilities address the identified vulnerabilities at all. At this level, the question is simple: Is there any protection in place for this moment and its risks?

Principle Connection: Having protection is not enough. This part evaluates how well the protection aligns with F-Secure’s seven Security Experience Principles. These seven principles are one of the main outcome of the Security Experience research that has been conducted earlier which helps us assess the quality of the experience, not just technical effectiveness. For example Is the protection understandable?, Does it feel supportive or intrusive? or Does it reduce anxiety or create new friction?

By combining these two views, the Coverage Layer makes it possible to see where protection is missing entirely and where protection exists but delivers a poor or inconsistent experience. This clarity is essential for identifying meaningful gaps in protection and shaping experience-led product opportunities.


An overview of Security Experience Map
An example [The Security Experience Principle are confidential to the company]

Gap Layer
The Gap layer of the map

The Gap Layer shows where F-Secure is falling short in protecting consumers during specific digital moments. It highlights gaps that matter from a consumer perspective, either because protection is missing, or because the experience of that protection does not feel right.

This layer helps move the conversation from what exists to what is missing or not working well. Two types of gaps are identified:

Capability/Product Gaps: A capability or product gap exists when a potential vulnerability in a digital moment is not covered, or only partially covered, by any current product, feature, or capability. These gaps point to areas where F-Secure’s current offering does not fully address real consumer risk.

Principle Gaps: A principle gap exists when technical protection is in place, but the overall security experience fails to reflect F-Secure’s Security Experience Principles. Here, the issue is not the absence of protection, but how it is delivered. The experience may feel unclear, stressful, intrusive, or disconnected from the consumer’s needs in that moment.

These gaps affect how safe, supported, and in control the consumer feels, and can undermine trust even when the underlying protection works.


An overview of Security Experience Map
An example [The Security Experience Principle are confidential to the company]

Opportunity
The opportunity layer

The Opportunity Layer brings everything together by turning identified gaps into clear opportunity themes that can guide product discovery and roadmap planning.

Instead of treating gaps in isolation, this layer clusters related gaps across digital moments to reveal broader patterns and areas of opportunity. This makes it easier for Product teams to reason about where to invest, rather than reacting to individual issues.

The Opportunity Layer does not define specific solutions. Its role is to frame where meaningful value can be created, giving Product teams a strong, experience-led starting point for prioritization and planning.


Measuring the Security Experience
The negative/positive experience elements

To make the Security Experience Map actionable, we needed a way to measure the security experience, not just describe it.

The way experience is measured depends on the tool used. In this project, we used TheyDo. In TheyDo, each insight includes an experience impact score , ranging from –2 to +2:

–2 to 0 indicates a negative impact on the consumer’s experience (e.g. pain points, pressures, unresolved gaps)

0 to 2 indicates a positive impact on the experience (e.g. gains, effective protections, principle-aligned experiences)

Each digital moment in the map includes a mix of:

Positive elements (for example, protections that work well or principles that are reflected in the experience)

Negative elements (such as capability gaps or principle gaps)

By accumulating the positive and negative experience impacts across all insights within a moment, we can understand the overall Security Experience score for that moment.

The Security Experience score makes experience comparable across moments. This score represents how safe, supported, and confident consumers are likely to feel in that specific context. Moments with a lower score clearly signal higher experience risk and greater unmet consumer needs. This allows teams to:

Identify which digital moments need the most attention

Prioritize opportunity themes connected to those moments

Focus product and discovery efforts where they can have the greatest experience impact


The Security Experience curve
Why the Security Experience Map matters

The Security Experience Map was designed to solve a structural problem, not just a tactical one: F-Secure had invested in strategic, foundational research, but had no mechanism to ensure those insights consistently reached product decisions. Without an artifact like this, research risks staying a one-off report rather than becoming a reusable customer signal for portfolio strategy.

The map was built to function as research and innovation governance (a recurring practice, not a single deliverable) giving Product Managers a direct translation layer from insight to opportunity, and giving the organization a standing mechanism for keeping research embedded in product strategy rather than relying on individual interpretation each time.

Like much of the infrastructure work in CX transformation, the value of an artifact like this depends on organizational adoption as much as on the artifact itself, which is part of what makes governance and embedding, not just frameworks, central to this kind of work.

Case Study

My other Case studies

Contact me