Skip to content

Free for nonprofits, NGOs, think tanks, and institutes. Grant funded by James Scott, administered by the Embassy Row Project.

ArtOfTheHack home

Grantee profile 01

Security decisions that protect field staff and sources, not just laptops.

Human rights and humanitarian organizations are targeted by well-resourced adversaries while running lean IT teams and donated tooling. The KRYOS-XS overlay adjudicates the evidence those tools already produce and returns a governed decision that names the risk to people, not only to devices.

Pressure

What is forcing the decision layer

  • Nation-state and contractor adversaries target staff, partners, and sources directly
  • Security tooling is donated, mismatched, and rarely correlated across products
  • There is no twenty-four-hour security operations center and often no full-time security hire
  • A containment action can cut off a field team in a place where connectivity is the safety line
  • Beneficiary and source data carries physical consequence if exposed

First workflows

Where instrumentation starts

  • Phishing and targeted-message adjudication for staff and partners
  • Suspicious sign-in and impossible-travel decisions for field accounts
  • Device compromise triage for travelling staff
  • Access decisions for shared partner and consortium systems
  • Account recovery decisions when a staff member is unreachable
  • Incident escalation and legal notification routing

Integration

Systems ArtOfTheHack reads from and instructs

ArtOfTheHack does not replace these systems. It reads their evidence, adjudicates against it, and returns a governed instruction to the same infrastructure.

Evidence sources

  • Cloud identity providers and multi-factor systems
  • Email and collaboration security logs
  • Endpoint protection consoles, including donated licences
  • Mobile device management, where present
  • Cloud file storage audit logs
  • Public and shared threat-intelligence feeds

Action targets

  • Identity systems for scoped, time-bound session revocation
  • Email security tooling for retraction and quarantine
  • Endpoint tooling for reversible isolation with a documented restore path
  • Ticketing or shared inbox workflows for approval routing
  • Internal communications for staff notification

Authority

How authority is constrained

  • No automated action against a device carrying field-critical connectivity
  • Named internal approver required for any action affecting a staff member in the field
  • Data-residency limits set by the organization and its legal counsel
  • Validity windows that force re-evaluation rather than standing authorization
  • Immediate disconnection available at any time with no operational impact

ArtOfTheHack services are provided at no cost through grants funded by James Scott and administered by the Embassy Row Project. Access begins with a grant application. The overlay is non-intrusive: it reads from the systems the organization already runs and installs nothing.

First 90 days

A typical entry sequence

  1. Days 1 to 15

    Grant application, eligibility review by the Embassy Row Project, and award. Systems inventory and threat context captured with the organization's point of contact.

  2. Days 16 to 40

    Read-only API connection to identity, email, and endpoint systems. Adversarial red team of the current architecture and access policy.

  3. Days 41 to 70

    Shadow evaluation against live decisions. Digital twin built so containment options can be tested before they touch a field device.

  4. Days 71 to 90

    Advisory operation with named internal approvers. Board-readable report on findings, residual risk, and the recommended next workflow.

Standard applied

What this profile can hold ArtOfTheHack to

  • Every determination carries supporting and contradictory evidence, not a score alone
  • Simulation shows the operational cost of a containment action before it is taken
  • The organization owns and can export the full decision record at any time

Applicable

Products, services, and industry context

Products

  • KRYOS-XS Console

    A centralized Cyber Decision Operations Hub that converts alerts, identity risks, access questions, data exposures and response requirements into one prioritized decision queue.

  • KRYOS-XS Edge

    A browser-based security decision assistant that helps users evaluate suspicious messages, external data sharing, OAuth approvals and other consequential actions at the moment they occur.