Grantee profile 01
Security decisions that protect field staff and sources, not just laptops.
Human rights and humanitarian organizations are targeted by well-resourced adversaries while running lean IT teams and donated tooling. The KRYOS-XS overlay adjudicates the evidence those tools already produce and returns a governed decision that names the risk to people, not only to devices.
Pressure
What is forcing the decision layer
- Nation-state and contractor adversaries target staff, partners, and sources directly
- Security tooling is donated, mismatched, and rarely correlated across products
- There is no twenty-four-hour security operations center and often no full-time security hire
- A containment action can cut off a field team in a place where connectivity is the safety line
- Beneficiary and source data carries physical consequence if exposed
First workflows
Where instrumentation starts
- Phishing and targeted-message adjudication for staff and partners
- Suspicious sign-in and impossible-travel decisions for field accounts
- Device compromise triage for travelling staff
- Access decisions for shared partner and consortium systems
- Account recovery decisions when a staff member is unreachable
- Incident escalation and legal notification routing
Integration
Systems ArtOfTheHack reads from and instructs
ArtOfTheHack does not replace these systems. It reads their evidence, adjudicates against it, and returns a governed instruction to the same infrastructure.
Evidence sources
- Cloud identity providers and multi-factor systems
- Email and collaboration security logs
- Endpoint protection consoles, including donated licences
- Mobile device management, where present
- Cloud file storage audit logs
- Public and shared threat-intelligence feeds
Action targets
- Identity systems for scoped, time-bound session revocation
- Email security tooling for retraction and quarantine
- Endpoint tooling for reversible isolation with a documented restore path
- Ticketing or shared inbox workflows for approval routing
- Internal communications for staff notification
Authority
How authority is constrained
- No automated action against a device carrying field-critical connectivity
- Named internal approver required for any action affecting a staff member in the field
- Data-residency limits set by the organization and its legal counsel
- Validity windows that force re-evaluation rather than standing authorization
- Immediate disconnection available at any time with no operational impact
ArtOfTheHack services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Access begins with a grant application. The overlay is non-intrusive: it reads from the systems the organization already runs and installs nothing.
First 90 days
A typical entry sequence
Days 1 to 15
Grant application, eligibility review by the Embassy Row Project, and award. Systems inventory and threat context captured with the organization's point of contact.
Days 16 to 40
Read-only API connection to identity, email, and endpoint systems. Adversarial red team of the current architecture and access policy.
Days 41 to 70
Shadow evaluation against live decisions. Digital twin built so containment options can be tested before they touch a field device.
Days 71 to 90
Advisory operation with named internal approvers. Board-readable report on findings, residual risk, and the recommended next workflow.
Standard applied
What this profile can hold ArtOfTheHack to
- Every determination carries supporting and contradictory evidence, not a score alone
- Simulation shows the operational cost of a containment action before it is taken
- The organization owns and can export the full decision record at any time
Applicable
Products, services, and industry context
Products
- KRYOS-XS Console
A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.
- KRYOS-XS Edge
A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.
Services
- Suspicious Message Adjudication
KRYOS-XS Edge
- Account-Compromise Assessment
KRYOS-XS Console
- Access and Entitlement Review
KRYOS-XS Console
- Guided Incident and Response Workflows
KRYOS-XS Console
