We research how cyber signals become responsible decisions.
The Cyber Resilience Lab is the independent research and validation initiative behind LHINOS Cyber Commander. Together with cybersecurity practitioners, researchers and students, we study how technical evidence, organizational context, uncertainty and human authority can be combined into robust cyber decisions.
Detection is not yet a decision.
Security stacks produce signals. Organizations must turn them into meaning, priority and responsible action under time pressure. We want to test those transitions scientifically and practically — without replacing existing security systems.
Confirmed facts, inferences and unknowns remain separate. Automation comes only after evidence, boundaries and failure risks are understood.
Capability ≠ Authority. Analysis and recommendations can be machine-supported; consequential approvals remain with authorized humans.
Cybersecurity is adversarial. Models and workflows must withstand manipulation, missing data, false positives and conflicting evidence.
Six research tracks. One central question.
How should humans and AI agents collaborate in high-stakes cyber decisions without surrendering human authority?
How can AI help people understand faster and decide better under pressure without increasing automation bias?
How can multiple signals become a defensible incident while facts, inferences and unknowns remain separate?
How should agent identity, tools, data access, memory, communication and action limits be secured?
Which actions may AI observe, recommend or simulate, and where must human approval remain mandatory?
How do Incident, Decision, Outcome, Lesson and Control Improvement become auditable cyber memory?
How do stress, deepfakes, impersonation, uncertainty and cognitive bias affect cyber decisions?
Three layers. One learning loop.
Research, engineering and product remain deliberately distinct. The Lab asks questions and falsifies assumptions. AEGIS is the controlled research and engineering testbed. Cyber Commander is the emerging enterprise product.
Independent Research Initiative: research questions, experiments, Fellow contributions and publishable Research Notes.
Research & Engineering Testbed: synthetic scenarios, Shadow tests, evidence, governance and technical validation.
Emerging Enterprise Product: Decision Intelligence for Cyber Resilience with controlled, human-governed introduction.
The current cyber approach operates in controlled Shadow Mode. LHINOS analyses and structures information but does not execute autonomous cyber actions.
From alert to a decision-ready situation.
This example shows how technical signals can be turned into a clearer decision situation. It uses no live customer data.
Privileged finance account · unusual sign-in pattern · access to critical finance context.
Account compromise is possible. Lateral movement is conceivable. Business impact could be high — not yet confirmed.
Legitimate travel? MFA context? Device trust? Data access after sign-in? Other affected identities?
Before a consequential action, evidence, business impact, reversibility and authority must be clarified.
A controlled chain instead of an autonomous leap.
We are looking for people who will challenge LHINOS.
We welcome cybersecurity researchers, security engineers, incident responders, SOC and identity specialists, CISOs, students and human-factors experts from the German-speaking region and beyond.
Founding Fellows do not operate LHINOS infrastructure, provide on-call services or accept mandatory weekly hours.
A Fellow may contribute to one Research Challenge, architecture review, threat-model test or Research Note.
Meaningful contributions may, with consent, be recognized as Founding Fellow work and receive access to selected AEGIS research artifacts.
If an assumption is wrong, that is a result. Findings are not changed to support a commercial narrative.
Four questions for the first cohort.
Can an AI-assisted Commander improve incident understanding without reducing decision quality or increasing automation bias?
Can a system reliably distinguish verified security evidence from hypotheses and missing information?
Where can AI accidentally gain more authority than intended through tools, egress, agent identity, prompts or approvals?
What evidence should exist before recommending containment such as session revocation for a privileged identity?
Not: “Do you like the idea?” But: Where does it break?
One research architecture for different domains of responsibility.
Cyber Commander is intended to make the same governance logic usable for companies, institutions and the public sector. The Lab explicitly studies how authority, public accountability, critical-infrastructure dependencies and cross-organization coordination differ.
The protected space for Cyber Research Collaboration.
For deeper collaboration we use the existing LHINOS Research Deal Room. After review, research questions, architecture critiques, test plans, evidence status and pilot proposals can be shared there. Access is reviewed and may require NDA, privacy, ethics or data-sharing rules depending on the project.
