Grantee profile 02
Protect the research, the researchers, and the credibility of the finding.
Think tanks hold pre-publication research, donor relationships, and government contacts that adversaries want early. The overlay correlates identity, email, and cloud evidence into one decision layer so a small operations team can act with the confidence of a much larger security function.
Pressure
What is forcing the decision layer
- Pre-publication research and embargoed analysis are high-value targets
- Fellows and visiting scholars use personal devices and unmanaged accounts
- Influence operations attempt to discredit findings rather than steal them
- IT is often one or two generalists supporting the whole institution
- Funder and government relationships create sensitive correspondence with no special handling
First workflows
Where instrumentation starts
- Credential-phishing adjudication for fellows and scholars
- Unmanaged and personal-device access decisions
- Pre-publication document access review
- Suspicious external sharing decisions in cloud storage
- Impersonation and spoofed-domain response
- Event and convening infrastructure protection
Integration
Systems ArtOfTheHack reads from and instructs
ArtOfTheHack does not replace these systems. It reads their evidence, adjudicates against it, and returns a governed instruction to the same infrastructure.
Evidence sources
- Cloud identity and single sign-on logs
- Email security and message-trace data
- Cloud document storage and sharing audit logs
- Endpoint protection consoles
- Website, content management, and DNS records
- Open-source and shared threat-intelligence feeds
Action targets
- Identity systems for conditional access and session revocation
- Cloud storage for scoped sharing revocation
- Email security for quarantine and sender blocking
- Content management systems for takedown and lockdown workflows
- Internal ticketing for approval routing and record keeping
Authority
How authority is constrained
- Academic freedom preserved: no monitoring of research content, only security metadata
- Named internal approver for any action affecting a fellow's access
- Separation between the operations staff requesting an action and the officer approving it
- No ingestion of manuscript or interview content into the overlay
- Full audit record retained by the institution
ArtOfTheHack services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Access begins with a grant application. The overlay is non-intrusive: it reads from the systems the organization already runs and installs nothing.
First 90 days
A typical entry sequence
Days 1 to 15
Grant application and award. Inventory of identity, email, storage, and web systems in use across programs.
Days 16 to 40
Read-only connection and historical replay against past security incidents and access anomalies.
Days 41 to 70
Shadow evaluation. Red team of the publication workflow and the external-sharing policy.
Days 71 to 90
Advisory operation for the highest-volume workflow, with a plain-language report for the board and program directors.
Standard applied
What this profile can hold ArtOfTheHack to
- Security metadata is evaluated without reading research content
- Contradictory evidence stays on the record rather than being averaged away
- Findings are written for program directors, not only for engineers
Applicable
Products, services, and industry context
Products
- KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
- KRYOS-XS Edge
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Services
- Alert Triage and Incident Adjudication
KRYOS-XS Console
- External Sharing and Data-Movement Governance
KRYOS-XS Edge
