INVARIANCE | Arc
MenuClose
Cyberattack Consequences

Fracture the path from compromise to consequence.

An attacker can gain access, credentials, and new routes without gaining any authority over your organization. Authority Control can interrupt the attack path when progression requires a consequential result that is outside organizational authority.

Scale, scope, and pace

Compromise changes what an attacker can reach. It does not change what the organization has authorized.

What a compromise can do
What stays the same

Scale

Run many attempts in parallel across a large environment.

What stays the same

Each consequential result is evaluated against the authority that applies, however many attempts there are.

Scope

Move through identity, applications, vendors, and infrastructure toward the same result.

What stays the same

Different routes to one result meet one authority question.

Pace

Find new routes faster than controls can be redesigned around each one.

What stays the same

A new route does not create new authority. The result is checked against current authority.

The distinction

Reach and authority are different things.

Valid credentials, added privilege, and familiar workflows describe what an attacker can reach. The authority to create a consequential result on the organization's behalf comes only from the organization.

What compromise can produce
  • Valid credentials and sessions
  • Additional privilege or capability
  • Movement through connected systems
  • Use of familiar applications and workflows
What still requires organizational authority
  • Movement of value
  • Production and configuration changes
  • Release of sensitive information
  • Changes to trust, limits, or permissions

Compromise of a technical path does not establish authority for the consequential result.

Alongside the security stack

Two different questions about the same activity.

Security tools keep governing identities, access, endpoints, networks, detection, and response. Authority Control adds one question about the result.

Security tools ask

Is this activity compromised, anomalous, or unsafe?

Authority Control asks

Is this result within the organization's authority?

A determination says nothing about intent. The result is evaluated whether or not the activity looks malicious.

Coverage

Authority Control does not generally control network movement itself. It can interrupt attack-path progression when the next consequential result is one the organization has placed under Authority Control and the result is outside authority.

Results reached through other execution paths remain outside enforcement, so keeping integration current as systems, agents, vendors, and workflows change is part of the work. Authority Control does not detect intrusions, prevent initial access, remove malware, or revoke credentials.