Skip to content
Black Atlas — Powered by KRYOS V6

Operating model

How the Assurance Loop Runs


Nine steps in the loop, ten phases in an engagement, five authorization levels governing what may be touched. Nothing executes because the analysis found it interesting.

The loop

Nine steps, run continuously

  1. Observe

    Take in what existing tooling already reports: vulnerability management, endpoint detection, identity, cloud posture, log platforms, governance systems, threat intelligence, red-team findings.

  2. Normalize

    Translate every source into one common security ontology: principals, assets, services, resources, credentials, controls, data, trust, actions, threats.

  3. Model

    Assemble the adversarial digital twin: a living graph of assets, relationships, access, controls, trust and business consequence.

  4. Infer

    Reason over sequences rather than isolated findings, and mark what is known, inferred, simulated, hypothesised or unknown.

  5. Simulate

    Run scenarios against the twin: credential compromise, vendor compromise, cloud control failure, CI/CD abuse, agent misuse, insider action.

  6. Validate

    Test hypotheses using the safest method that can answer them, inside the authorization level that has actually been granted.

  7. Prioritize

    Rank by consequence and structural position, not by severity score alone. Choke points and high-centrality dependencies come first.

  8. Remediate

    Propose the smallest set of interventions that disconnects untrusted sources from crown jewels, with the expected risk reduction stated.

  9. Verify

    Recompute the attack surface after the change, confirm the pathway is actually broken, and record residual risk.

The ninth step returns to the first. After remediation the surface is recomputed under environmental change, new exposures and revised threat behaviour, which is what makes the state continuous rather than a report with a date on it.

Engagement

The ten-phase assurance lifecycle

  1. Phase 01

    Authorization and scope

    Named accountable authority, named environments, permitted execution level, action budget, stop conditions and rollback recorded before any analysis begins. Missing authorization is not a delay; it is a blocked state.

  2. Phase 02

    Evidence intake and acceptance

    Each source is registered with provenance, effective date and fitness for this question. Stale, unreproducible or unattributable evidence is labelled as such rather than quietly used.

  3. Phase 03

    Normalisation into the ontology

    Findings from different tools become one vocabulary of principals, assets, credentials, controls, data and trust relationships, so cross-vendor reasoning is possible at all.

  4. Phase 04

    Twin construction

    The adversarial digital twin is assembled: topology, state, threat context, control coverage and business consequence, with gaps marked as gaps.

  5. Phase 05

    Threat modelling

    Plausible adversary objectives are mapped against the twin, including lawful failure modes that no current finding has yet surfaced.

  6. Phase 06

    Hypothesis generation

    Each hypothesis carries evidence, assumptions, confidence, preconditions, affected systems, estimated impact, a safe validation method, and its remaining uncertainty.

  7. Phase 07

    Safe validation

    The hypothesis is tested with the least invasive method capable of answering it, at the authorization level actually granted, never at the level that would be convenient.

  8. Phase 08

    Counterfactual optimisation

    Candidate interventions are compared: privilege removal, credential rotation, segmentation, trust-policy change, vendor-access removal, dependency replacement, agent approval gates.

  9. Phase 09

    Remediation and retest

    After the change, the twin is recomputed and the pathway is retested. A closed ticket is not evidence that a path is gone.

  10. Phase 10

    Release decision and residual risk

    One of the five release states is issued with the evidence behind it, plus an explicit residual-risk statement and an audit-ready decision packet.

Authority

Five authorization levels

Each level is agreed in writing before work starts, with named systems, named windows and a named accountable authority. A level is a ceiling, not a default.

Level 0

Passive analysis of supplied artifacts and authorized evidence. No target interaction.

Level 1

Digital-twin, graph, or synthetic simulation. No production interaction.

Level 2

Safe non-invasive validation using approved queries, read-only checks, dry runs, stubs, synthetic users, or equivalent controls.

Level 3

Controlled authorized security testing in explicitly named environments using an approved test plan, monitoring, rate limits, stop conditions, and rollback.

Level 4

Preauthorized reversible containment by policy. No irreversible action and no authority inferred from general testing permission.

What stays human

Decisions the model never makes

  • Granting authorization, or widening an agreed scope
  • Accepting residual risk on behalf of the organisation
  • Deciding to contain, isolate or disconnect a production system
  • Breach determination, disclosure and regulatory notification
  • Legal interpretation and statements to a regulator
  • What the organisation tells its customers, board or insurer

The full list of things this work does not claim is on the limits and non-claims page.