Skip to content
Black Atlas — Powered by KRYOS V6

Definition

What Black Atlas Is, and What KRYOS V6 Is


A reasoning, simulation and assurance layer that sits above the security stack. It consumes what your existing tools already produce, builds an adversarial model of the enterprise from it, and computes how that enterprise could be defeated — before anyone attempts it.

Manual

K6-CYBER-MANUAL-001

Version

1.0

Corpus snapshot

2026-09-04

Governing doctrine

Adversarial creativity with strictly authorized execution. KRYOS may reason aggressively about lawful failure modes, but no analytical capability creates operational authority.

In plain English

What it is, and what it is not

Black Atlas is a governed cybersecurity reasoning and assurance layer powered by KRYOS V6. It sits above your existing security stack, works from approved evidence, tracks provenance, tests for contradiction, and supports defensible decisions with human review where needed. It is evidence-bounded, explicit about what is known, inferred, simulated and unknown, governed by authorization levels agreed in advance, and designed to fail closed when permission or evidence is missing.

What it is

  • a reasoning, simulation and assurance layer above the security stack
  • evidence-bounded and provenance-tracked
  • explicit about known, inferred, simulated and unknown
  • governed by authorization levels agreed in advance
  • designed to fail closed when permission or evidence is missing

What it is not

  • not a single installed all-in-one product
  • not autonomous judgment
  • not a certainty engine
  • not a prevention guarantee
  • not a substitute for required human review

Position

Above the stack, not beside it

Vulnerability management, EDR, identity governance, cloud posture, SIEM, GRC, threat intelligence and red teaming each produce a truthful partial view. None of them holds the whole system. The layer that reasons across all of them is the one that can answer whether the organisation is actually defensible.

What it consumes

Asset and identity inventories, vulnerability and posture findings, endpoint telemetry, cloud and CI/CD configuration, network reachability, data-location records, control claims from GRC, threat intelligence, and prior red-team and incident material.

What it produces

Ranked material attack paths, crown-jewel exposure, choke points and minimal cut sets, falsified control claims, systemic and concentration risk, agent trust exposure, and a defensible record of what was assumed, simulated and verified.

Core concepts

The ideas the model runs on

Adversarial digital twin
A living model of the enterprise as an attacker experiences it: assets, identities, trust relationships, network reachability, cloud posture, code and build paths, data location, and the controls claimed over each. The twin is where attacks are rehearsed so they are not rehearsed in production.
Attack-path intelligence
Individual weaknesses are treated as edges, not verdicts. What matters is whether a chain of them connects an entry point to something that would actually hurt. A critical-severity finding on an unreachable host can rank below a medium one that completes a path.
Crown-jewel inversion
Reasoning runs backwards from the assets whose loss would be material — payment authority, customer data, safety systems, the ability to operate — to every route that reaches them, rather than forwards from whatever the scanners happened to find.
Security hypercube
Exposure is evaluated across simultaneous dimensions — identity, network, cloud, application, data, supply chain, human, and agentic AI — so risk that only appears at an intersection of two domains is not lost between two teams.
Minimal cut sets
The smallest set of changes that severs the largest number of material pathways. This is the difference between a remediation backlog of thousands of items and a short list of interventions that measurably alters the graph.
Evidence ledger and provenance
Every input carries its origin, age and confidence. Conclusions inherit the weakest evidence beneath them. Where an input is stale, partial or unverified, the output says so instead of averaging the doubt away.

Every term above is also defined in two registers in the glossary.

Modules

The eight Black Atlas modules

ATLAS GRAPH

The enterprise adversarial knowledge graph: entities, relationships, attributes, and the institutional memory of past exposures.

ATLAS TWIN

A dynamic security digital twin updated by events rather than nightly snapshots, so short-lived infrastructure is represented honestly.

ATLAS PATH

Attack-path reasoning over sequences: external exposure, identity weakness, privilege expansion, internal reachability, sensitive asset.

ATLAS SIM

The adversarial simulation environment, producing reachable assets, escalation paths, blast radius, containment points and confidence.

ATLAS OPTIMIZER

Counterfactual remediation: which single change removes the most risk, and what the graph looks like once it is made.

ATLAS AGENT

AI-agent and autonomous-system security: trust graphs, tool and data permissions, autonomy, approvals, and maximum blast radius.

ATLAS ASSURE

Continuous control and compliance assurance, mapping control to technical evidence to validation to assurance.

ATLAS EXEC

Executive cyber decision intelligence: risk compression, capital allocation, and traceability from board risk down to control evidence.

Release

How conclusions are allowed to leave

Released

Evidence, scope, review, and acceptance criteria are satisfied.

Released with qualifications

Material limitations or uncertainty remain but are explicitly bounded and accepted by the accountable authority.

Insufficient evidence

Evidence is incomplete, stale, non-reproducible, or too weak for the requested conclusion.

Out-of-distribution

The system, data, or use case materially differs from validated conditions.

Blocked

Authorization, safety, competency, evidence, or release criteria are not satisfied.

Directly supported

Doctrine, module structure, authorization levels and release states are reproduced from the source manual.

Supported inference

Where cybersecurity capability is carried over from validated work in other fields, it is labelled derived or composite and requires validation before operational reliance.