BUSINESS 04 — R&D

Repetition to the machine, judgement to the human

More than half of assessment work is repetition. Our research institute automates that half so the remaining judgement gets the time it needs.

Active research

  • Detection rule generation

    Drafting SIEM rules from written attack scenarios, to cut the time spent reviewing and tuning by hand.

  • Contextual code analysis

    Reducing static analysis false positives by judging call paths and input trust together rather than pattern alone.

  • SBOM impact tracing

    Automatically determining which services a newly published CVE actually affects. Matching on version alone produces far too much noise.

How the institute works

Recognised as a corporate research institute in October 2023. Eight resident researchers sit in the same space as the assessment division and take their subjects from repetitive work observed on real projects. The output is a tool usable on the next engagement, not a paper.

Validation

Every project is validated on live assessment work. We measure recall and false-positive rate against human results, and a tool is not released if the false-positive rate exceeds the threshold. Bad automation is more dangerous than manual work.

Publication

Tools that contain no client data and carry low abuse potential are cleaned up and published, after internal security review.

Institute at a glance

Resident researchers
8
Active projects
3
Repetitive work automated
41 %