Abstract
This use case addresses ransomware as a sequence of interdependent decisions rather than a single containment event. KRYOS-XS organizes evidence, authority and recovery dependencies across the organization’s existing tools.
Decision problem
Premature restoration may reintroduce compromise, while delayed containment may expand damage. Backup availability does not establish backup integrity. The organization must determine the order in which isolation, preservation, credential action, backup protection and service restoration should occur.
Evidence and Hypercube reasoning
Console depends on approved EDR, identity, backup and related system evidence. Hypercube evaluates possible attacker persistence, affected dependencies, recovery-point integrity and mission consequence. Each recommendation states the evidence on which it relies and the uncertainty that remains.
Governed workflow
KRYOS builds a controlled response sequence from containment through verified restoration. Decision owners and approvers are explicit. The source systems remain responsible for enforcement. Console captures action status and tests whether the expected result occurred before the next recovery stage proceeds.
Evaluation design
Measures should include time to containment, recovery sequence adherence, systems restored without reinfection, recovery-point validation, service downtime, approval delays and completeness of the incident record.
Boundary condition
The service requires suitable endpoint, identity and backup integrations. KRYOS-XS should not declare a recovery point safe without evidence from the relevant systems and validation process.
Reading time 2 minutes. Every decision described here is recorded in the KRYOS Decision Ledger with its evidence, authority and verified outcome.




