This was one of the most challenging projects I led at Fortinet not for its design complexity, but for the resistance it met.
User research revealed that IT administrators found the existing EMS events feature nearly useless. The reason was simple yet critical: it didn’t show the exact file path for detected events.
Without that detail, admins were forced into a painful workaround asking end users to open their FortiClient console, capture screenshots, and send them back. Each request could take hours or even days, depending on user response times.
At scale, the impact was massive. An admin managing 10,000+ endpoints could spend entire days chasing screenshots instead of resolving threats. EMS offered visibility, but not the information needed for action.
When I presented these findings, reactions were mixed. Stakeholders felt consolidating events into one view was enough. Challenging that assumption and proving why it wasn’t required patience, evidence, and reframing the problem around lost time, inefficiency, and business risk.