Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Incident Operations

Incident Response Decision Support

This use case examines the role of KRYOS-XS during the first hour of a suspected account incident. The principal contribution is disciplined sequencing: evidence is preserved, authority is confirmed and containment is matched to consequence before irreversible action is taken.

Product
KRYOS-XS Console
Decision domain
Incident Operations
Organizational setting
Nonprofit responding to a suspected mailbox compromise
Related capability
Guided Incident and Response Workflows
Numbered sequence diagram running preserve evidence, assess exposure, revoke sessions, reset credentials, review third-party access, assess file exposure, notify leadership and verify outcome. Each stage carries a named owner, and revoke sessions, reset credentials, review third-party access and notify leadership require documented approval before they proceed. Approval gates precede high-impact action. Rollback paths are recorded where the source system supports them.
Figure 4. Ordered decision stages with named owners and approval gates before high-impact action, recorded continuously in the KRYOS Decision Ledger.

Abstract

This use case examines the role of KRYOS-XS during the first hour of a suspected account incident. The principal contribution is disciplined sequencing: evidence is preserved, authority is confirmed and containment is matched to consequence before irreversible action is taken.

Decision problem

Incident response frequently fails through omission, premature action or unclear ownership. Suspending an account may reduce risk but disrupt essential work. Delaying containment may permit further access. The organization must decide what to do first, who can authorize it and what evidence must be retained.

Evidence and Hypercube reasoning

Console assembles approved identity, login, application, file and alert evidence. Hypercube evaluates the likely cost of action and inaction under competing incident hypotheses. Organizational policies define the actions available to each role. Evidence age, completeness and provenance remain attached to the decision.

Governed workflow

Console guides the team through investigation, affected-asset identification, containment analysis, authority confirmation, approval, action, verification and rollback if necessary. Each stage produces a traceable decision record. The process does not assume that the first hypothesis will survive later review.

Evaluation design

The pilot should measure time to containment, evidence preserved, required steps completed, approval latency, inappropriate account suspensions, actions successfully verified and completeness of the final incident record.

Boundary condition

KRYOS-XS provides governed decision support. It should not execute high-impact containment unless bounded automation has been expressly approved.

Reading time 2 minutes. Every decision described here is recorded in the KRYOS Decision Ledger with its evidence, authority and verified outcome.

Related Use Cases

Protect the Systems Your Mission Depends On.

Eligible nonprofit organizations may apply for grant-funded access to ArtOfTheHack cybersecurity services powered by KRYOS-XS Hypercube.