Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

KRYOS-XS Hypercube method

Adversarial Red Teaming

The organization's own architecture, policy, and response plan are attacked analytically across eight dimensions before a real adversary attempts it.

What it is

The method in plain terms

Every proposed determination and every existing control is pressure-tested across evidence, logic, legal, operational, financial, human, reputational, and future dimensions. The objective is to find the combination of small weaknesses that produces a material failure.

The output is an exploit-chain map: not a list of findings, but an ordered description of how an adversary would move from an initial foothold to the outcome the organization most needs to prevent.

Why it matters

Adversaries targeting civil society are patient and well resourced. They do not exploit the single worst finding on a report; they assemble three ordinary ones. Red teaming the chain is the only way to see what a findings list cannot show.

Applied

How it is used in a nonprofit environment

  • Privilege escalation paths that start with a volunteer account and end at the mail tenant
  • Response plans that fail because the only person who can approve an action is the person who is travelling
  • Assurance claims that would not survive a board or funder challenge

Limits

Where the method stops

  • Analytical red teaming models the environment as described by the evidence available to it
  • It does not substitute for authorized penetration testing where an organization requires it

Analytical and simulated by default. Any active technical testing is separately authorized, scoped, logged, and reversible under written rules of engagement.