Skip to content
Black Atlas — Powered by KRYOS V6

Catalogue

Cybersecurity Services


Eight flagship services are written out in full: what each is for, the decision it answers, what it needs, what it produces, and where it stops. Each belongs to one of the fourteen domains and carries its own classification, maturity label and authorization level.

Domain 1 · Adversarial Assurance

Enterprise Adversarial Assurance Baseline

Establish an evidence-grounded baseline of enterprise exposure, controls, dependencies, and assurance readiness.

COMPOSITE · DOCUMENTED_OPERATIONAL_HUMAN_REVIEW

Domain 2 · Attack-Path and Exposure Intelligence

Attack-Path and Crown-Jewel Intelligence

Reason over sequences from external exposure through identity weakness, privilege expansion and internal reachability to a sensitive asset, rather than over isolated findings.

COMPOSITE · DOCUMENTED_OPERATIONAL_HUMAN_REVIEW

Domain 3 · Identity and Privilege Intelligence

Privilege Escalation Path Discovery

Map effective privilege across human, machine, service and agent identities, and find where delegation bridges trust domains.

NATIVE · OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW

Domain 4 · Cloud, Application, API, and Infrastructure Security

Cloud, CI/CD and Secret Exposure Analysis

Trace what a compromised build worker, pipeline credential or misconfigured cloud control can actually reach.

COMPOSITE · OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW

Domain 5 · AI, RAG, Model, and Agentic Security

AI Agent Trust and Prompt-Injection Analysis

Model the agent trust graph — tool, data and model permissions, autonomy, persistence, approvals, external communication and code execution — and the path from untrusted input through the model and a tool to a privileged action.

NATIVE · RESEARCH_ONLY_AND_RESTRICTED_VALIDATION

Domain 6 · Supply-Chain and Third-Party Security

Vendor Concentration and Supply-Chain Exposure

Build simplified external dependency twins and surface latent shared dependencies between suppliers that appear independent.

DERIVED · DERIVED_VALIDATION_REQUIRED

Domain 8 · Security Control Assurance and Falsification

Control Validation and Claim Falsification

Attempt to defeat the organisation's own security claims, and check that expected state still equals actual state.

NATIVE · OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW

Domain 13 · Executive, Board, and Capital-Allocation Intelligence

Cyber Capital Allocation and Decision Compression

Compress technical exposure into a board-legible decision: which portfolio of interventions gives the highest modelled marginal risk reduction under a stated budget.

DERIVED · HEURISTIC_OR_COMPARATIVE_ONLY

Remaining catalogue

The other domains

The full corpus catalogue spans eighty-five services across all fourteen domains. The domains not represented by a flagship service above are listed here with the questions they address; written definitions are added only as authoritative source text is confirmed.

Domain 7

Cyber Risk, Causal Intelligence, and Simulation

Causal reasoning, Bayesian updating, Monte Carlo, temporal graphs, counterfactuals, and loss scenarios.

Domain 9

Resilience, Architecture, and Systemic Failure Analysis

Fragility, common-mode failure, defense independence, segmentation, recovery, and observability.

Domain 10

Threat Intelligence, SOC, Incident, and Forensic Intelligence

Threat contextualization, alert prioritization, incident reconstruction, forensic hypotheses, near misses, and terrain shaping.

Domain 11

Compliance and Regulatory Assurance

Continuous compliance, control mapping, privacy, currentness, audit replay, deficiency closure, and evidence governance.

Domain 12

Critical Infrastructure and Cyber-Physical Assurance

OT, ICS, critical infrastructure, healthcare, finance, defense, aerospace, robotics, and autonomous systems.

Domain 14

Continuous Security Operations

Twin operations, recurring adversarial assurance, laboratories, synthetic data, continuous learning, and model governance.

Earlier cross-industry write-ups remain published in the cross-industry archive, covering nineteen non-cybersecurity sectors.