Home All Projects About Resume Get In Touch
← All Projects
Case Study 02 / 04
Cybersecurity · Gamification · Certification UX

MITRE
ATT&CK

A certification program with a 20-click signup and no clear path forward. We turned it into an experience people actually wanted to complete.

Clicks to Sign Up (Before)
20+
Reduced significantly in redesign
My Role
UX Lead
Research + Gamification + Design
Industry
Cyber
Gov-adjacent · Security Professionals
Outcome
↑ Engage
Increased engagement, reduced friction
Overview

MITRE Engenuity is the tech foundation arm of MITRE Corporation — one of the most respected names in U.S. cybersecurity. Their ATT&CK program is an industry-standard framework for understanding adversary tactics used by security teams worldwide.

The problem: the program's digital experience didn't match its reputation. Getting into the system was painful, and once inside, users had no clear direction on what to do, where to go, or how to progress. The result was drop-off, disengagement, and a certification journey that felt more like a chore than an achievement.

The Brief

Find new and innovative ways to bring the ATT&CK program to the masses — reducing friction, creating a clear path, and using gamification to make users actually want to earn that certification.

ClientMITRE Engenuity
IndustryCybersecurity / Gov-Adjacent
PlatformWeb Application
My RoleUX Lead — Research, Gamification, Design
Engagement via3Pillar Global
AudienceSecurity Professionals, Researchers
Compliance ScopeGov-adjacent security standards
ResultDecreased effort · Increased engagement
The Problem

A WORLD-CLASS
PROGRAM WITH A
BROKEN DOOR

20+

Clicks Just to Sign Up

The onboarding flow required over 20 clicks before a user was inside the system. First impressions matter — this one said "turn back."

0

Clear Next Steps

Once inside, users faced a wall of content with no guided path, no progression system, and no obvious "right" way to complete the course.

High
Drop

Engagement Drop-Off

Without direction or motivation loops, users abandoned mid-journey. A premium certification program was leaking its most valuable users.

MITRE's ATT&CK framework has genuine authority in the cybersecurity world. Security teams reference it daily. The brand didn't need to be built — it needed to be matched by the experience.

The irony: a program designed to help security professionals navigate complex threat landscapes couldn't guide its own users through a certification flow. The UX was actively working against one of the most credible names in the industry.

Onboarding Was a Gauntlet

20+ clicks to get started. Each additional step was another chance to lose a user permanently.

No Navigation Hierarchy

Content existed but had no sequence, priority, or guidance. Users didn't know what they were supposed to do first.

No Sense of Progress

Without checkpoints or milestones, users couldn't gauge how far they'd come or how far was left.

No Motivational Loop

Nothing rewarded participation, encouraged return visits, or celebrated completion. The experience was purely transactional.

Process

RESEARCH FIRST,
GAMIFICATION SECOND

We didn't assume we knew what security professionals wanted. We asked them — and then we built around what they told us.

📎 Artifact Placeholder

Insert research plan, affinity map, or journey map here
Step 01

USER & EXPERT INTERVIEWS

Engaged both active users of the ATT&CK program and cybersecurity industry experts. We asked them what experiences they valued in other platforms and what was missing here.

  • Moderated interviews with security practitioners
  • Competitive analysis of certification platforms (e.g. Coursera, SANS, Cybrary)
  • Stakeholder workshops with MITRE program team
  • Synthesis of common friction patterns and motivation gaps
Step 02

FRICTION MAPPING

Documented every step of the existing onboarding and course journey. Every click, every decision point, every moment of ambiguity was catalogued and scored by effort and drop-off risk.

  • Click-count audit of existing signup flow
  • Task analysis across core certification paths
  • Effort/impact matrix for all identified pain points
  • Priority ranking with MITRE product stakeholders
Step 03

GAMIFICATION ARCHITECTURE

Applied Octalysis framework principles to design motivation into the core experience — not as decoration, but as structural scaffolding that guided users forward naturally.

  • Progress visualization with clear milestone markers
  • Achievement system tied to certification stages
  • Validation checkpoints that felt like wins, not gates
  • Onboarding quest narrative framing the certification journey
Step 04

DESIGN & VALIDATION

Designed a streamlined flow from landing to certification with clear wayfinding and a gamified progression layer. Tested against the existing experience with target users.

  • Wireframe flows tested with security professionals
  • A/B comparison against existing onboarding
  • Iterative refinement based on usability sessions
  • Handoff with full annotation and component specs
Before & After

WHAT CHANGED

📎 Artifact Placeholder

Insert wireframes or side-by-side before/after screens here
Before
  • 20+ clicks to complete signup
  • No guided path once inside the platform
  • Content presented as a flat, unstructured list
  • No milestones, checkpoints, or progress indicators
  • No reward for engagement or completion
  • High drop-off at onboarding and mid-course
After
  • Dramatically reduced signup friction
  • Quest-style narrative framing the certification journey
  • Structured progression with clear next steps at every stage
  • Visible milestones and achievement checkpoints throughout
  • Gamified rewards tied to real learning objectives
  • Decreased user effort, increased engagement metrics
Outcomes & Learnings

WHAT WE
DELIVERED

Reduced Friction

Signup flow redesigned from 20+ clicks to a streamlined, guided onboarding. Users reached the core content faster and with higher confidence.

📈

Increased Engagement

Clear progression, milestone rewards, and structured paths led to measurably higher engagement and course completion in post-launch tracking.

🎯

Quest-to-Cert Framework

A reusable certification UX pattern — gamified journey framing that can be applied to future MITRE programs without reinventing the wheel.

Lesson 01

Expert users still hate unnecessary friction

Security professionals are sophisticated — but that doesn't mean they have patience for a 20-click onboarding. Expertise and friction tolerance are not correlated.

Lesson 02

Gamification earns credibility when it's earned, not layered on

This audience would reject cosmetic gamification instantly. Tying rewards to real certification milestones gave the system legitimacy.

Lesson 03

The "quest" metaphor was a deliberate choice

Security professionals think in terms of missions, threats, and objectives. Framing certification as a quest resonated because it matched their mental models.

Lesson 04

Stakeholder credibility accelerates compliance

Working within a gov-adjacent organization meant every design decision needed a rationale. That discipline improved the quality of our documentation significantly.

Next Case Study
3PILLAR
GLOBAL
View Case Study →

LIKE WHAT
YOU SEE?

Open to senior/lead UX roles and director-level engagements.

Get In Touch → ← All Projects