Context
Every enterprise network is guarded by firewalls — usually from several vendors at once, in dozens of models, each speaking its own configuration syntax. And inside each one, security policies accumulate like sediment: hundreds or thousands of rules, years old, nobody remembers why a rule was opened, and nobody dares delete it. The rules only grow. Meanwhile the change requests accelerate — a security admin who once handled a few tickets a month now faces a hundred a week, across heterogeneous devices, in networks that cloud and virtualization have made harder to see into.
We called the problem the policy jungle, and NSPM was the product that managed it: unify heterogeneous firewalls under one abstract policy model; continuously analyze rules for redundancy, shadowing, conflicts, expiry and looseness; automate the change ticket end-to-end — topology pathfinding to locate devices, policy generation per device dialect, simulated command-lines, one-click push, verification, expiry tracking, one-click recycling; and make “who can reach what” a visual query instead of tribal knowledge. Gartner’s line anchored our pitch: more than 95% of security issues are avoidable by better managing what you already have — starting with deleting useless firewall rules.
I spent four years on this product, and it gave me my platform-PM education in four chapters.
Chapter 1 · Rebuild — and a written promise to myself (2018–19)
I joined the line for the v1.0 rebuild, owning the homepage, intelligent operations (ticket processing and topology management), health check, and device management modules. We shipped. And then I wrote something that shaped the rest of my career more than the release did: a candid end-of-project self-review. What went well — logic held up in reviews, risks got spotted early. And three named gaps, each with a fix: I had designed modules without first mapping the whole architecture; I had under-covered edge cases in flows; I hadn’t tracked whether engineering and QA actually understood the requirements after sign-off.
I still have that document. Three years later, “model first, screens later” was the opening decision of my secure-DNS build. The habit was born here, as a written promise to myself.
Chapter 2 · Carry the flagship (2019–20)
The line’s defining project was a national power-grid enterprise’s security-device monitoring and management platform — two tiers, headquarters and provincial subsidiaries, co-delivered with a partner vendor. I did the overall requirements design: 24 epics under three principles I held constant through every client-leadership review cycle — scenario-driven, process-driven, transparent. The platform went through the client’s institute testing into delivery and a second phase, and became the reference case on NSPM’s own pitch deck.
The lesson wasn’t the delivery. It was the tension: a flagship client pulls the product toward their bespoke reality, and the PM’s real job is to keep harvesting the generalizable core back into the standard product — I kept a running analysis of which change requests were the client and which were the market.
Chapter 3 · Write the story yourself (2020)
In 2020 I wrote the product’s flagship pitch deck — solo. The revision log reads v0.1 to v1.0, five tracked revisions over two months, one author. It set the narrative I still consider the template for B2B security products: open with the operational pain (the jungle, the ticket load), structure the solution as four pillars (unified management, policy analysis, ticket automation, access visualization), then two slides that did the heavy commercial lifting — a regulatory mapping table tying each core feature to specific clauses of China’s Classified Protection standard (等保 2.0), and an adaptation-speed promise born from real engineering capability: a new firewall brand supported within a week, a new model within three days, cluster deployment past two thousand devices.
Writing the deck yourself is not a marketing chore. If the PM can’t tell the whole story solo, the product definition isn’t actually done.
Chapter 4 · Redefine it (2021–22)
By 2021 the market had matured and so had I. I ran a systematic competitive study across nine NSPM players — including the global leaders, Tufin, FireMon, AlgoSec and Skybox — built capability matrices, and used them to drive the NSPM 2.0 redefinition, closing my time on the line with a fresh product prototype in 2022. Alongside it I kept a habit that became my quiet superpower: formal domain modeling. The same policy-group-task abstraction I first built for firewalls, I later re-modeled for an endpoint-security console and a sensor-management platform — same bones, different bodies. By then I was also screening the team’s incoming product interns.
Results
- A shipped, commercially real platform product: white paper, user manual through its third major version, acceptance handbook — the artifact set of a product that actually ships to enterprises.
- A national flagship deployment delivered through institute testing into a second phase, and onto the product’s own case slide.
- A market story with one author: the five-revision pitch deck, plus the compliance-mapping table that turned regulation into a sales asset.
- A 2.0 definition grounded in evidence: nine-competitor capability matrices and a new prototype, not opinions.
- A PM who grew in writing: every gap named in the 2019 self-review had a corresponding habit by 2022 — architecture first, edge cases enumerated, alignment tracked past sign-off.
What I learned
- B2B platforms are won in the domain model. The abstract ACL model that unified a dozen vendor dialects was the product; every screen was commentary on it.
- Flagship projects are product R&D disguised as delivery. Harvest the generalizable core deliberately, or the standard product quietly becomes one client’s custom build.
- Regulation is a product surface. The compliance-mapping table did more selling than any feature slide — a lesson I reused years later in a very different market.
- Growth compounds when you write it down. The most valuable document I produced in four years might be the self-review with three named gaps — because everything afterward was the closing of them.