Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Grantee profile 03

Laboratory, data, and collaboration security decided on one geometry.

Nonprofit research institutes run instrument networks, shared compute, and external collaborations that sit outside normal organization controls. The overlay reasons across those environments together instead of leaving each one to its own console.

Pressure

What is forcing the decision layer

  • Instrument and laboratory networks cannot tolerate arbitrary isolation
  • Collaborations grant external researchers standing access to internal systems
  • Research data is valuable to both criminal and state actors
  • Grant compliance requires evidence of controls without a compliance department
  • Shared compute and code repositories accumulate credentials over years

First workflows

Where instrumentation starts

  • External collaborator access review and revocation
  • Credential exposure in code repositories and notebooks
  • Instrument and laboratory network anomaly adjudication
  • Research-data exfiltration triage
  • Cloud compute misconfiguration prioritization
  • Grant-required control evidence assembly

Integration

Systems ArtOfTheHack reads from and instructs

ArtOfTheHack does not replace these systems. It reads their evidence, adjudicates against it, and returns a governed instruction to the same infrastructure.

Evidence sources

  • Identity providers and federated research identity systems
  • Cloud control planes and compute audit logs
  • Code repository and secret-scanning output
  • Network telemetry from laboratory and instrument segments
  • Endpoint protection consoles
  • Vulnerability and asset inventories

Action targets

  • Identity systems for scoped collaborator access changes
  • Cloud control planes for reversible configuration correction
  • Repository platforms for credential rotation workflows
  • Ticketing systems for approval routing and evidence capture
  • Reporting systems for funder-ready control evidence

Authority

How authority is constrained

  • Safety gate: no automated action against instrument or laboratory control networks
  • Principal investigator approval required for actions affecting active experiments
  • Blast-radius limits defined per network segment and per action class
  • Rollback path validated before any action class becomes eligible for automation
  • Every determination replayable with the policy and model versions in force

ArtOfTheHack services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Access begins with a grant application. The overlay is non-intrusive: it reads from the systems the organization already runs and installs nothing.

First 90 days

A typical entry sequence

  1. Days 1 to 15

    Grant application and award. Mapping of research environments, instrument segments, and collaboration agreements.

  2. Days 16 to 40

    Read-only connection to identity, cloud, and repository systems. Evidence-quality baseline for each source.

  3. Days 41 to 70

    Digital twin of the research environment. Monte Carlo scenario ranges for containment options against active experiments.

  4. Days 71 to 90

    Advisory operation on collaborator access, plus a funder-ready control evidence package.

Standard applied

What this profile can hold ArtOfTheHack to

  • Instrument networks are modeled before any containment option is recommended
  • Control evidence is produced as a byproduct of deciding, not as a separate reporting exercise
  • Collaborator access decisions carry named authority and an expiry

Applicable

Products, services, and industry context

Products

  • KRYOS-XS Console

    A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

  • KRYOS-XS Edge

    A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.