Catalogue
Cybersecurity Services
Eight flagship services are written out in full: what each is for, the decision it answers, what it needs, what it produces, and where it stops. Each belongs to one of the fourteen domains and carries its own classification, maturity label and authorization level.
Domain 1 · Adversarial Assurance
Enterprise Adversarial Assurance Baseline
Establish an evidence-grounded baseline of enterprise exposure, controls, dependencies, and assurance readiness.
COMPOSITE · DOCUMENTED_OPERATIONAL_HUMAN_REVIEW
Domain 2 · Attack-Path and Exposure Intelligence
Attack-Path and Crown-Jewel Intelligence
Reason over sequences from external exposure through identity weakness, privilege expansion and internal reachability to a sensitive asset, rather than over isolated findings.
COMPOSITE · DOCUMENTED_OPERATIONAL_HUMAN_REVIEW
Domain 3 · Identity and Privilege Intelligence
Privilege Escalation Path Discovery
Map effective privilege across human, machine, service and agent identities, and find where delegation bridges trust domains.
NATIVE · OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW
Domain 4 · Cloud, Application, API, and Infrastructure Security
Cloud, CI/CD and Secret Exposure Analysis
Trace what a compromised build worker, pipeline credential or misconfigured cloud control can actually reach.
COMPOSITE · OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW
Domain 5 · AI, RAG, Model, and Agentic Security
AI Agent Trust and Prompt-Injection Analysis
Model the agent trust graph — tool, data and model permissions, autonomy, persistence, approvals, external communication and code execution — and the path from untrusted input through the model and a tool to a privileged action.
NATIVE · RESEARCH_ONLY_AND_RESTRICTED_VALIDATION
Domain 6 · Supply-Chain and Third-Party Security
Vendor Concentration and Supply-Chain Exposure
Build simplified external dependency twins and surface latent shared dependencies between suppliers that appear independent.
DERIVED · DERIVED_VALIDATION_REQUIRED
Domain 8 · Security Control Assurance and Falsification
Control Validation and Claim Falsification
Attempt to defeat the organisation's own security claims, and check that expected state still equals actual state.
NATIVE · OPERATIONAL, REQUIRES QUALIFIED HUMAN REVIEW
Domain 13 · Executive, Board, and Capital-Allocation Intelligence
Cyber Capital Allocation and Decision Compression
Compress technical exposure into a board-legible decision: which portfolio of interventions gives the highest modelled marginal risk reduction under a stated budget.
DERIVED · HEURISTIC_OR_COMPARATIVE_ONLY
Remaining catalogue
The other domains
The full corpus catalogue spans eighty-five services across all fourteen domains. The domains not represented by a flagship service above are listed here with the questions they address; written definitions are added only as authoritative source text is confirmed.
Earlier cross-industry write-ups remain published in the cross-industry archive, covering nineteen non-cybersecurity sectors.

