LHINOS CYBER RESILIENCE LAB · FOUNDING RESEARCH

We research how cyber signals become responsible decisions.

The Cyber Resilience Lab is the independent research and validation initiative behind LHINOS Cyber Commander. Together with cybersecurity practitioners, researchers and students, we study how technical evidence, organizational context, uncertainty and human authority can be combined into robust cyber decisions.

FOUNDING COHORT 2026APPLICATIONS OPENSHADOW-FIRST
WHY A CYBER RESILIENCE LAB

Detection is not yet a decision.

Security stacks produce signals. Organizations must turn them into meaning, priority and responsible action under time pressure. We want to test those transitions scientifically and practically — without replacing existing security systems.

Evidence before automation

Confirmed facts, inferences and unknowns remain separate. Automation comes only after evidence, boundaries and failure risks are understood.

Human Authority

Capability ≠ Authority. Analysis and recommendations can be machine-supported; consequential approvals remain with authorized humans.

Adversarial Realism

Cybersecurity is adversarial. Models and workflows must withstand manipulation, missing data, false positives and conflicting evidence.

RESEARCH PROGRAM

Six research tracks. One central question.

How should humans and AI agents collaborate in high-stakes cyber decisions without surrendering human authority?

01 · Human-AI Cyber Decision Intelligence

How can AI help people understand faster and decide better under pressure without increasing automation bias?

02 · Incident Reasoning & Evidence

How can multiple signals become a defensible incident while facts, inferences and unknowns remain separate?

03 · AI Agent Security

How should agent identity, tools, data access, memory, communication and action limits be secured?

04 · Cyber Authority & Governance

Which actions may AI observe, recommend or simulate, and where must human approval remain mandatory?

05 · Resilience & Organizational Learning

How do Incident, Decision, Outcome, Lesson and Control Improvement become auditable cyber memory?

06 · Human Factors & Social Engineering

How do stress, deepfakes, impersonation, uncertainty and cognitive bias affect cyber decisions?

LAB → AEGIS → PRODUCT

Three layers. One learning loop.

Research, engineering and product remain deliberately distinct. The Lab asks questions and falsifies assumptions. AEGIS is the controlled research and engineering testbed. Cyber Commander is the emerging enterprise product.

LHINOS Cyber Resilience Lab

Independent Research Initiative: research questions, experiments, Fellow contributions and publishable Research Notes.

AEGIS

Research & Engineering Testbed: synthetic scenarios, Shadow tests, evidence, governance and technical validation.

LHINOS Cyber Commander

Emerging Enterprise Product: Decision Intelligence for Cyber Resilience with controlled, human-governed introduction.

Current Engineering Boundary

The current cyber approach operates in controlled Shadow Mode. LHINOS analyses and structures information but does not execute autonomous cyber actions.

LAB BRIEF 001 · SYNTHETIC SCENARIO

From alert to a decision-ready situation.

This example shows how technical signals can be turned into a clearer decision situation. It uses no live customer data.

FACTS

Privileged finance account · unusual sign-in pattern · access to critical finance context.

INFERENCES

Account compromise is possible. Lateral movement is conceivable. Business impact could be high — not yet confirmed.

UNKNOWNS

Legitimate travel? MFA context? Device trust? Data access after sign-in? Other affected identities?

HUMAN GATE

Before a consequential action, evidence, business impact, reversibility and authority must be clarified.

DECISION CHAIN

A controlled chain instead of an autonomous leap.

Signal
Context
Situation
Options
Authority
Controlled Action
Outcome & Learning
Designed to complement existing security tools – not replace SIEM/EDR or your team’s authority.
FOUNDING FELLOW CALL 2026

We are looking for people who will challenge LHINOS.

We welcome cybersecurity researchers, security engineers, incident responders, SOC and identity specialists, CISOs, students and human-factors experts from the German-speaking region and beyond.

Not an unpaid operational role

Founding Fellows do not operate LHINOS infrastructure, provide on-call services or accept mandatory weekly hours.

Bounded Research Contributions

A Fellow may contribute to one Research Challenge, architecture review, threat-model test or Research Note.

Recognition & Research Access

Meaningful contributions may, with consent, be recognized as Founding Fellow work and receive access to selected AEGIS research artifacts.

Research Integrity

If an assumption is wrong, that is a result. Findings are not changed to support a commercial narrative.

FOUNDING RESEARCH CHALLENGES

Four questions for the first cohort.

001 · Human vs. Human + AI

Can an AI-assisted Commander improve incident understanding without reducing decision quality or increasing automation bias?

002 · Facts, Inferences & Unknowns

Can a system reliably distinguish verified security evidence from hypotheses and missing information?

003 · Red Team the Cyber Authority Model

Where can AI accidentally gain more authority than intended through tools, egress, agent identity, prompts or approvals?

004 · The Identity Compromise Decision

What evidence should exist before recommending containment such as session revocation for a privileged identity?

WHAT WE WANT EXPERTS TO TELL US

Not: “Do you like the idea?” But: Where does it break?

What evidence is missing before an alert may become a situation?
Which inferences are useful in a SOC — and which are dangerous?
Which actions should always retain a Human Gate?
How should confidence be shown so it is not mistaken for certainty?
Which failure modes arise from AI agents, tool access or unclear authority?
Which metrics demonstrate real improvement over existing workflows?
ENTERPRISE + INSTITUTIONS + PUBLIC SECTOR

One research architecture for different domains of responsibility.

Cyber Commander is intended to make the same governance logic usable for companies, institutions and the public sector. The Lab explicitly studies how authority, public accountability, critical-infrastructure dependencies and cross-organization coordination differ.

RESEARCH DEAL ROOM

The protected space for Cyber Research Collaboration.

For deeper collaboration we use the existing LHINOS Research Deal Room. After review, research questions, architecture critiques, test plans, evidence status and pilot proposals can be shared there. Access is reviewed and may require NDA, privacy, ethics or data-sharing rules depending on the project.

Please do not submit credentials, secrets, exploit materials, personal live-incident data or confidential customer data through public website forms.
Ask LHINOS