Skip to content
KRYOS V6

Directory

Apply It to Your Sector


Nine settings, described generically. Filter by audience type, then jump to the detail for the sector closest to your context. Cybersecurity appears as one example among many, not as the framework's home.

Knowledge work

Business & enterprise

Commercial decisions where evidence is uneven, incentives differ across teams, and the cost of a confident wrong answer is high.

Typical use cases

  • Supplier and third-party risk review
  • Market entry or exit option comparison
  • Build, buy, or partner assessments
  • Post-incident commercial reviews

Likely inputs

  • Contracts, audit findings, and supplier questionnaires
  • Internal performance and financial reporting
  • Vendor claims and third-party attestations

Likely outputs

  • A scoped mission statement with named decision owners
  • An evidence register ranked by source fitness
  • Scenario comparisons with explicit assumptions
  • A release class: proceed, qualify, constrain, escalate, or block

Governance considerations

  • Record who is authorised to accept residual risk
  • Separate the analysis owner from the decision owner
  • Log the evidence used at the moment of the decision

Must remain human-owned

Commercial commitment, risk acceptance, contractual obligations, and communication to boards or regulators.

Public sector

Government & public policy

Policy choices made under contested evidence, statutory limits, and public accountability requirements.

Typical use cases

  • Policy option comparison
  • Programme continuation or closure review
  • Cross-agency prioritisation of limited funds
  • Consultation evidence synthesis

Likely inputs

  • Statutory instruments and legal mandates
  • Administrative data and evaluation reports
  • Consultation submissions and stakeholder positions

Likely outputs

  • An auditable statement of scope and legal authority
  • Contradiction notes where evidence sources disagree
  • Option sets with distributional tradeoffs surfaced
  • An explicit list of unresolved questions before decision

Governance considerations

  • Authority limits must be documented before analysis begins
  • Publishable audit trail for scrutiny and review bodies
  • Distinguish official statistics from modelled estimates

Must remain human-owned

Political judgement, statutory interpretation, public consultation duties, and final policy adoption.

Mission-driven

NGO & nonprofit

Allocation decisions where mission fit, beneficiary impact, and constrained funding must be weighed openly.

Typical use cases

  • Grant prioritisation across competing programmes
  • Partner due diligence
  • Programme redesign after evaluation findings
  • Safeguarding and duty-of-care reviews

Likely inputs

  • Monitoring and evaluation data
  • Field reports and partner self-assessments
  • Donor conditions and restricted-fund rules

Likely outputs

  • A prioritisation rationale traceable to stated criteria
  • Named evidence gaps in beneficiary data
  • Scenario views of funding shortfall and surplus

Governance considerations

  • Trustee-level sign-off recorded against the release class
  • Beneficiary voice logged as a distinct evidence source
  • Conflicts of interest declared inside the evidence register

Must remain human-owned

Mission interpretation, ethical judgement, beneficiary relationships, and trustee accountability.

Knowledge work

Think tank & research institute

Synthesis work where competing explanations must be tested rather than reconciled by narrative.

Typical use cases

  • Research synthesis across conflicting literature
  • Structured expert elicitation
  • Pre-publication challenge of a headline finding

Likely inputs

  • Peer-reviewed and grey literature
  • Datasets with documented provenance
  • Expert interviews with stated positions

Likely outputs

  • A contradiction map of where sources disagree and why
  • Claim classification by directly supported, inferred, or unresolved
  • Scenario questions for future research

Governance considerations

  • Funder influence declared in the evidence register
  • Separate the synthesis role from the publication decision

Must remain human-owned

Scholarly interpretation, methodological choice, and responsibility for published claims.

Regulated

Healthcare & medtech

Service and pathway decisions where clinical safety, regulation, and resource limits interact.

Typical use cases

  • Service redesign option appraisal
  • Procurement of clinical technology
  • Incident and never-event review structuring

Likely inputs

  • Clinical guidelines and regulatory requirements
  • Service activity and outcome data
  • Safety incident reports

Likely outputs

  • A scope statement bounded by clinical governance
  • Contradiction checks between guidance and local data
  • Escalation triggers where safety evidence is insufficient

Governance considerations

  • Clinical accountability stays with named clinicians
  • Patient data handling governed outside the framework
  • Regulatory obligations override framework output

Must remain human-owned

Clinical judgement, patient consent, regulatory compliance, and duty of candour.

Knowledge work

Education

Curriculum, resourcing, and intervention decisions where evidence quality varies widely between contexts.

Typical use cases

  • Intervention selection and continuation
  • Resource allocation across sites
  • Evaluating vendor efficacy claims

Likely inputs

  • Attainment and attendance data
  • Independent evaluations and efficacy studies
  • Staff and learner feedback

Likely outputs

  • A record of which efficacy claims are supported and which are not
  • Scenario views of rollout at different scales

Governance considerations

  • Safeguarding and learner data rules sit outside the framework
  • Equity impacts recorded as an explicit tradeoff dimension

Must remain human-owned

Pedagogical judgement, learner welfare, and institutional accountability.

Operational

Infrastructure & operations

Time-pressured decisions where partial evidence is normal and failing closed matters.

Typical use cases

  • Incident review and corrective action selection
  • Maintenance prioritisation
  • Change approval under uncertainty

Likely inputs

  • Telemetry, logs, and asset condition records
  • Incident timelines and operator accounts
  • Standards and safety cases

Likely outputs

  • Ranked corrective options with residual risk stated
  • Explicit block or escalate signals when support is weak

Governance considerations

  • Operational authority levels defined per change class
  • Time-boxed reviews recorded with the evidence available at the time

Must remain human-owned

Operational command, safety authority, and live intervention.

Operational

Cybersecurity

One example domain among many: not the framework's boundary. Useful because adversarial evidence is contested by default.

Typical use cases

  • Incident attribution reasoning
  • Control investment prioritisation
  • Threat report credibility assessment

Likely inputs

  • Telemetry and detection output
  • Vendor and open-source threat reporting
  • Control coverage assessments

Likely outputs

  • Competing-hypothesis comparison with confidence bounds
  • Explicit statement of what the evidence cannot show

Governance considerations

  • Attribution statements require named authorisation
  • Source reliability tracked separately from claim confidence

Must remain human-owned

Response authority, disclosure, law-enforcement liaison, and attribution statements.

Map KRYOS V6 to your context


Start with the builder to generate a structured starting map, or request a guided mapping session with a person.