Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Identity and Access

Account Compromise and Identity Risk Decisioning

This use case addresses a common source of false positives in identity security. KRYOS-XS evaluates whether unusual activity is malicious, legitimate or unresolved by combining technical evidence with institutional context.

Product
KRYOS-XS Console
Decision domain
Identity and Access
Organizational setting
International program staff traveling across jurisdictions
Related capability
Account-Compromise Assessment
Three-part diagram. On the left, sign-in location and network, device posture, authentication method, role and project need, declared travel context and file download activity form the authorized evidence. In the centre the Hypercube Decision Engine compares legitimate travel, credential sharing and account compromise and marks missing or contradictory evidence. On the right the governed verdict is one of verified legitimate activity, step-up verification, restricted access and containment with approval, and the result is written to the KRYOS Decision Ledger.
Figure 5. Evidence available on the approved surface, the competing explanations tested by the Hypercube Decision Engine, and the governed verdict preserved in the KRYOS Decision Ledger.

Abstract

This use case addresses a common source of false positives in identity security. KRYOS-XS evaluates whether unusual activity is malicious, legitimate or unresolved by combining technical evidence with institutional context.

Decision problem

Rules that treat every new location or device as hostile can disrupt field operations and train users to ignore warnings. Conversely, contextual explanations can be used to excuse genuine compromise. The decision must therefore account for both behavior and consequence without allowing either to dominate the assessment.

Evidence and Hypercube reasoning

Console retrieves approved login, device, authentication, role, file and alert evidence. Where the organization supplies valid travel or operational context, Hypercube treats it as one source rather than a conclusive explanation. Competing hypotheses are scored against the whole evidence set, and missing facts are translated into specific verification requests.

Governed workflow

Console detects the identity-risk case and frames the exact decision. Hypercube tests legitimacy, credential sharing and compromise. The output may recommend no action, step-up authentication, restricted access, session revocation or human investigation. The final disposition and subsequent outcome are recorded.

Evaluation design

Measures should include confirmed compromises, false account suspensions, time to resolution, cases resolved through targeted verification, repeated user friction and the rate at which the initial conclusion changed after new evidence.

Boundary condition

Travel context should reduce neither evidentiary standards nor the need for protective action when the technical record supports compromise.

Reading time 2 minutes. Every decision described here is recorded in the KRYOS Decision Ledger with its evidence, authority and verified outcome.

Related Use Cases

Protect the Systems Your Mission Depends On.

Eligible nonprofit organizations may apply for grant-funded access to ArtOfTheHack cybersecurity services powered by KRYOS-XS Hypercube.