DOTSHIELD® RESOURCESRESEARCH PUBLICATIONS

Research that can be traced to the record.

A public register of research preprints, methodology papers and applied analyses supported by persistent identifiers, version history and independent repository records.

This page distinguishes what was published, where it was deposited, which version is being referenced, and what the publication itself actually claims.

ZENODODOIPREPRINTSVERSIONED RECORDSORCIDPUBLIC RESEARCH
RESEARCH REGISTER

Four independently deposited research records.

Each publication below has a persistent Zenodo DOI and an identifiable version record. Repository metadata is treated as the reference point for title, version and publication status.

01METHODOLOGY · PREPRINT
VERIFIED
CCMM FOUNDATION

Conditional Consequence Mapping and the 0.001% Problem: A Probabilistic Framework for Tail-Risk Prophecy Verification with Live Event Validation in the 2026 Iran War

Introduces the Conditional Consequence Mapping Model as a probabilistic framework using conditional branches, pre-assigned probability weights, observable confirmation markers and falsifiable revision conditions.

Version 2.0
Version date 7 Mar 2026
Repository Zenodo
DOI 10.5281/zenodo.19382186
OPEN RECORD ↗
02APPLIED ANALYSIS · PREPRINT
VERIFIED
CCMM-CYBER · SATELLITE COMMUNICATIONS

Prospective Threat Identification in Satellite Communications: A Conditional Consequence Mapping Methodology Demonstration Using the 2022 KA-SAT Cyberattack

Applies conditional, probability-weighted threat analysis to the KA-SAT case and examines timing signals, governance transition, civilian spillover, attribution ambiguity and cyber-to-electronic- warfare succession.

Version 1.0
Publication date 13 Apr 2026
Repository Zenodo
DOI 10.5281/zenodo.19548175
OPEN RECORD ↗
03INTELLIGENCE ANALYSIS · PREPRINT
VERIFIED
CCMM-CYBER INTELLIGENCE ANALYSIS SERIES

CCMM-Cyber Applied: The 2026 Instructure Canvas Breach — Attribution Confidence and Data-Destruction Verifiability Are Not the Same Analytical Question

Separates threat-actor attribution confidence from confidence that post-agreement data destruction can actually be verified, while developing the concept of shadow critical infrastructure.

Version 1.3
Publication date 13 May 2026
Repository Zenodo
DOI 10.5281/zenodo.20151323
OPEN RECORD ↗
04SECURITY THEORY · PREPRINT
VERIFIED
BLACKGLASS THEORY

BlackGlass Theory: A Framework for Evaluating Sealed Custody Architectures in Information Protection Systems

Introduces Asymmetric Custody, a five-degree sealed-custody model and a seven-dimensional framework for evaluating information protection architectures across commercial, institutional and sovereign environments.

Version 1.2
Publication date 26 May 2026
Repository Zenodo
DOI 10.5281/zenodo.20388612
OPEN RECORD ↗
DOI
Repository records are the publication anchors.

Titles, versions and publication states shown here correspond to the identified repository records. Later analysis, implementation work or website commentary should not be read as silently modifying the deposited publication.

PUBLICATION 01 · CCMM FOUNDATION

Conditional Consequence Mapping and the 0.001% Problem

A Probabilistic Framework for Tail-Risk Prophecy Verification with Live Event Validation in the 2026 Iran War

METHODOLOGICAL CONTRIBUTION

Turn an unlikely claim into something that can fail.

The paper introduces Conditional Consequence Mapping as a probabilistic framework for evaluating low-probability predictive claims using explicit conditions, weighted branches, observable confirmation markers and revision criteria.

0.001%

The analytical question is not whether an unusual prediction should be believed. It is whether a sufficiently explicit model can be established in advance and then tested against what actually occurs.

FRAMEWORK ELEMENTS

What the paper puts into the research record.

VERSION 2.0
01 CONDITIONS

Conditional branches

Alternative event pathways are expressed as explicit branches rather than reconstructed only after an outcome is known.

02 WEIGHTING

Probability assignments

Branches receive probability weights so that low-probability, high-consequence trajectories can be evaluated explicitly.

03 OBSERVATION

Confirmation markers

Observable events are used as defined markers for confirming, weakening or revising branches as evidence develops.

04 SCORING

Quatrain Convergence Score

The paper introduces a scored convergence mechanism for comparing predefined analytical conditions with subsequent observed events.

05 REVISION

Falsifiable update path

The model is designed to expose disconfirmation and revision rather than preserve a claim regardless of later evidence.

06 COMPARISON

Null-model test

Version 2.0 includes comparison against randomly selected material to test whether the observed convergence exceeds a chance baseline.

VERSION 2.0 RECORD

The deposited version records both the model and its later correction.

The revised edition updates the live-event verification through Day 28 and corrects the denominator used for the earlier Day 6 convergence calculation.

DAY 6 83.3%

Corrected six-term, 120-point calculation for the primary quatrain.

DAY 28 87.5%

Revised convergence score recorded for Century II:62.

NULL MODEL ≈ 8.5σ

Reported distance above the mean result from randomly selected comparison quatrains scored against the same events.

!
RESEARCH BOUNDARY
The publication does not present prophetic validity as its intellectual contribution.

The paper frames its contribution as methodological: whether a rigorous probabilistic model applied to a historically marginalised predictive corpus can generate testable analytical structure for low-probability, high-consequence event trajectories.

WHAT FOLLOWED

The framework did not remain in its original domain.

01 Financial crime Investigation methodology
02 Homicide & serious crime Investigation methodology
03 Critical infrastructure cyber CCMM-Cyber development
04 Satellite communications KA-SAT methodology demonstration
PUBLICATION ANCHOR Zenodo · Version 2.0
10.5281/zenodo.19382186 VIEW REPOSITORY RECORD ↗
PUBLICATION 02 · CCMM-CYBER · SATELLITE COMMUNICATIONS

Prospective Threat Identification in Satellite Communications

A Conditional Consequence Mapping Methodology Demonstration Using the 2022 KA-SAT Cyberattack

CASE STUDY

The 2022 KA-SAT cyberattack.

The KA-SAT attack against Viasat's satellite communications network provides a documented case of hybrid cyber conflict, critical infrastructure disruption and cross-border civilian spillover.

24 FEB Cyber effects at the opening of a kinetic conflict.

The paper uses the case retrospectively to test whether a cross-domain conditional framework could have surfaced materially useful threat findings before the complete incident picture became visible.

ANALYTICAL POSITION

A layer above classification and control frameworks.

The paper does not argue that existing frameworks are ineffective. It distinguishes their purpose from the prospective problem CCMM is designed to address.

EXISTING FRAMEWORKS

Classify what is known.

Frameworks such as MITRE ATT&CK for Space, STRIDE and compliance-oriented control models are useful for describing techniques, weaknesses and controls once relevant evidence becomes available.

CCMM

Test what could happen next.

Conditional branching, historical analogues, probability weighting and explicit revision triggers are used to assess low-probability, high-consequence trajectories before the final outcome is known.

FIVE PROSPECTIVE THREAT CATEGORIES

What the methodology surfaced.

KA-SAT · v1.0
01 TIMING

Timing signals preceding kinetic escalation

Satellite communications disruption may operate as a precursor or enabling condition within a broader kinetic campaign rather than as an isolated cyber event.

02 GOVERNANCE

Governance transition as attack surface

Organisational, contractual or operational transition can create exploitable conditions even where the underlying technology has not materially changed.

03 SPILLOVER

Civilian exposure in dual-use architectures

Infrastructure serving both strategic and civilian functions can propagate effects far beyond the immediate operational target.

04 ATTRIBUTION

Attribution ambiguity as an operational vector

Delayed or uncertain attribution may itself create decision advantage by complicating response, escalation and accountability during the most consequential phase of an incident.

05 SUCCESSION

Cyber-to-electronic-warfare succession

Mitigation of one attack path does not necessarily end the threat. Adversarial pressure may transition into jamming, interference or other electronic-warfare effects.

METHOD USED

Evidence remains differentiated throughout the analysis.

01 Claim labelling Evidence and analytical claims are not treated as equivalent.
02 Conditional branching Alternative threat trajectories remain explicit.
03 Historical analogues Comparable conditions are used to inform, not determine, outcomes.
04 Revision triggers New evidence can weaken, strengthen or terminate a branch.
RESEARCH BOUNDARY
Retrospective methodology demonstration is not prospective proof.

The paper uses a known historical incident to examine whether the methodology could structure prospective threat identification. Its contribution is methodological rather than a claim that the KA-SAT attack itself was predicted in advance using CCMM.

RESEARCH SEQUENCE Foundation → application
01 CCMM Foundation Probabilistic conditional methodology
02 KA-SAT Satellite communications demonstration
03 CCMM-Cyber Broader critical infrastructure application
PUBLICATION ANCHOR Zenodo · Version 1.0
10.5281/zenodo.19548175 VIEW REPOSITORY RECORD ↗
PUBLICATION 03 · CCMM-CYBER INTELLIGENCE ANALYSIS

CCMM-Cyber Applied: The 2026 Instructure Canvas Breach

Attribution Confidence and Data-Destruction Verifiability Are Not the Same Analytical Question

CENTRAL ANALYTICAL DISTINCTION

Two questions that should not collapse into one.

The paper applies CCMM-Cyber to the 2026 Instructure Canvas incident using public-source information current to 13 May 2026. Its central finding is that confidence in threat-actor attribution and confidence in post-agreement data destruction require separate analytical treatment.

Q1
ATTRIBUTION

Who was responsible?

Available evidence may support high confidence that a particular actor was responsible for an incident.

Q2
VERIFIABILITY

Was the data actually destroyed?

The same evidence may support only low confidence that a claimed deletion or destruction event can be independently verified.

RETROSPECTIVE ANALYSIS

Three analytical lenses.

PUBLIC-SOURCE EVIDENCE
01 RED-LINE CONDITIONS

CCMM-Cyber red lines

The incident is assessed against provisional CCMM-Cyber red-line conditions to examine which consequence signals were visible and how their significance changed as the incident developed.

02 ACI

Attribution Confidence Index

ACI is applied separately to actor attribution and to the verifiability of claimed post-agreement data destruction rather than allowing one confidence judgment to substitute for the other.

03 TCI

Threat Convergence Index

The analysis examines convergence signals visible before the incident escalated publicly and considers how prior threat-actor behaviour should influence subsequent risk assessment.

CONCEPT INTRODUCED

Shadow critical infrastructure.

The paper uses this term to describe large-scale SaaS platforms that can carry critical-infrastructure-like consequence profiles without consistently receiving consequence-equivalent regulatory classification or assurance obligations.

PLATFORM CLASSIFICATION SaaS
CONSEQUENCE PROFILE Potentially critical
ASSURANCE QUESTION Are controls proportional to consequence?
METHODOLOGY CONTRIBUTIONS

Three additions to the CCMM-Cyber development pipeline.

v1.3
01
CLASSIFICATION

SaaS shadow critical infrastructure

Formalises a category for platforms whose consequence profile may exceed the assurance expectations implied by their conventional service classification.

02
ATTRIBUTION

Dual-question ACI

Prevents confidence in actor attribution from being reused as confidence in a materially different claim such as destruction, deletion or post-extortion compliance.

03
CONVERGENCE

Prior-actor TCI weighting

Introduces prior threat-actor behaviour as a structured weighting input when evaluating the convergence of future incident signals.

CONFIDENCE SEPARATION One conclusion cannot inherit another conclusion's evidence.
CLAIM A Threat actor attribution Evidence set A
CLAIM B Data-destruction verification Evidence set B
REQUIREMENT Independent confidence assessment No confidence-by-association
!
RESEARCH BOUNDARY
The findings are provisional and retrospective.

The publication is an analytical methodology application based on publicly available information. It is not a final certification, forensic determination, regulatory compliance assessment, or legal opinion.

RESEARCH SEQUENCE Method → domain → operational distinction
01 CCMM Foundation Conditional probabilistic methodology
02 KA-SAT Critical infrastructure threat application
03 Canvas / CCMM-Cyber Confidence separation and SaaS consequence analysis
PUBLICATION ANCHOR Zenodo · Version 1.3
10.5281/zenodo.20151323 VIEW REPOSITORY RECORD ↗
PUBLICATION 04 · BLACKGLASS THEORY

BlackGlass Theory

A Framework for Evaluating Sealed Custody Architectures in Information Protection Systems

CENTRAL CONCEPT

What if the custodian cannot routinely read back what it holds?

BlackGlass Theory introduces Asymmetric Custody as a framework for evaluating information protection systems that can accept, seal and govern sensitive information without retaining routine unilateral readback capability.

ASYMMETRIC CUSTODY
ACCEPT Receive protected information
SEAL Remove routine unilateral readback
GOVERN Controlled authorised recovery
SEALED CUSTODY MODEL

A five-degree model for evaluating custody.

5 DEGREES
01
Conventional custody

Custodian retains routine ability to access protected information.

02
Restricted custody

Access is constrained by controls, policy or additional authority.

03
Split custody

Recovery depends on authority or capability distributed across more than one component or actor.

04
Sealed custody

Routine unilateral readback is substantially removed from the normal custody path.

05
Asymmetric custody

Acceptance and governance remain possible without ordinary unilateral possession of equivalent readback authority.

EVALUATION MATRIX

Seven dimensions of sealed-custody assurance.

7 DIMENSIONS
01
CD

Custody degree

How much unilateral access authority remains with the custodian.

02
CR

Coercion resistance

Whether protected access can resist or expose compelled authorisation conditions.

03
FS

Forward secrecy

Whether compromise of later key material exposes earlier protected information.

04
QR

Quantum resistance

Whether the cryptographic architecture addresses credible post-quantum transition requirements.

05
NI

Network isolation

The degree to which protected custody depends on continuously reachable network infrastructure.

06
KC

Key ceremony assurance

How key generation, distribution, use and recovery authority are governed and evidenced.

07
DT

Data classification tier

Whether the custody architecture is proportionate to the sensitivity and consequence profile of the information.

ARCHITECTURAL QUESTIONS

Encryption alone does not answer the custody question.

The framework examines not only whether information is encrypted, but who retains authority over readback, what happens after key compromise, how recovery is governed, and whether protection remains appropriate under coercion or future cryptographic change.

01 Can the custodian read it? Routine authority
02 Can one compromised key expose history? Forward secrecy
03 Who can authorise recovery? Key ceremony
04 What happens under coercion? Human authority
FUTURE-RESILIENCE QUESTIONS

The paper extends custody analysis beyond today's cryptography.

FORWARD SECRECY

Asynchronous sealed custody

The paper considers how forward secrecy can be maintained where information is accepted and sealed without requiring a continuously interactive recipient.

POST-QUANTUM

Hybrid key encapsulation

A hybrid post-quantum key-encapsulation strategy is examined as part of the transition path for sealed-custody systems.

HUMAN AUTHORITY

Physiological coercion detection

The paper also addresses a physiological coercion-detection layer for biometric-bound authorisation flows where human approval is part of protected recovery.

CROSS-JURISDICTIONAL MAPPING

The framework is intended to operate across custody environments.

The publication maps the theory against national classification schemes and regulatory contexts rather than limiting it to one technology stack or one jurisdiction.

AU Australian PSPF
US Executive Order 13526
UK GSCP
EU EU classified information
PCI PCI-DSS v4.0.1
APRA CPS 234
RESEARCH BOUNDARY
BlackGlass Theory is an evaluation framework, not a certification of any particular custody implementation.

The publication provides a structured model for examining sealed custody architectures. Application of the framework to a specific system requires evidence about that system's actual cryptographic, operational, governance and recovery controls.

RESEARCH LINE Distinct from CCMM
CCMM Consequence and threat reasoning Conditional analysis · evidence · probability
BLACKGLASS Custody and authority architecture Access · sealing · recovery · coercion · cryptography
PUBLICATION ANCHOR Zenodo · Version 1.2
10.5281/zenodo.20388612 VIEW REPOSITORY RECORD ↗
REPOSITORY & RESEARCH IDENTITY

The publication record exists beyond this website.

DotShield presents these research records, but the publication anchors are the independently maintained repository records. Persistent identifiers, versions and repository metadata provide a reference point that does not depend on this webpage remaining unchanged.

PUBLIC WEBSITE Presentation Research context and navigation
REPOSITORY Publication record Deposited version and metadata
DOI Persistent identifier Stable reference to the record
RESEARCH RECORD Independently inspectable Beyond a website assertion
PRIMARY REPOSITORY RECORDS

Four Zenodo publication anchors.

CURRENT REGISTER
01
CCMM FOUNDATION Conditional Consequence Mapping and the 0.001% Problem
VERSION 2.0
VERSION DATE 7 Mar 2026 Zenodo upload: 2 Apr 2026
DOI 10.5281/zenodo.19382186 OPEN ↗
02
CCMM-CYBER · KA-SAT Prospective Threat Identification in Satellite Communications
VERSION 1.0
PUBLICATION DATE 13 Apr 2026 Zenodo upload: 13 Apr 2026
DOI 10.5281/zenodo.19548175 OPEN ↗
03
CCMM-CYBER · CANVAS CCMM-Cyber Applied: The 2026 Instructure Canvas Breach
VERSION 1.3
PUBLICATION DATE 13 May 2026 Zenodo upload: 13 May 2026
DOI 10.5281/zenodo.20151323 OPEN ↗
04
BLACKGLASS THEORY A Framework for Evaluating Sealed Custody Architectures
VERSION 1.2
PUBLICATION DATE 26 May 2026 Zenodo upload: 26 May 2026 Repository publisher: NOMATEQ Research
DOI 10.5281/zenodo.20388612 OPEN ↗
Historical publisher names are preserved.

Some repository records retain the publisher or organisational identifiers recorded at the time of deposit, including NOMATEQ Research. These historical identifiers form part of the publication provenance and are not retroactively replaced. DotShield® presents the current research register while preserving the metadata of the original repository records.

RESEARCH IDENTITY

Creator attribution remains attached to the repository record.

The publications are attributed to Prasanna Abeysekera. Repository records for the later publications also associate the research identity with an ORCID identifier, providing a persistent researcher reference independent of organisational branding.

CONTRIBUTOR Prasanna Abeysekera
ORCID 0009-0005-1720-0601 VIEW ORCID ↗
DATE DISCIPLINE

Publication date and repository upload date are not silently merged.

VERSION / PUBLICATION DATE The date associated with the deposited research version.

This identifies the version being referenced and preserves the chronology expressed by the publication record.

REPOSITORY UPLOAD DATE The date the artefact was uploaded to the repository.

Where these dates differ, both are shown rather than replacing one with the other.

REPOSITORY HISTORY

Earlier submission history is preserved without displacing the primary repository.

Some CCMM research also has an SSRN submission or abstract history. These identifiers can help reconstruct publication chronology, but this page uses the confirmed Zenodo records above as the primary public repository anchors.

CCMM FOUNDATION SSRN Abstract ID 6364078 Additional publication-history identifier
KA-SAT SSRN Abstract ID 6566478 Historical submission identifier · Zenodo is the primary public publication record used here
WHAT “VERIFIED” MEANS ON THIS PAGE
Verified refers to the publication record — not endorsement of every conclusion in the paper.

A verified repository record means that the identified title, version and DOI can be traced to the referenced public repository. It does not mean that Zenodo, DOI infrastructure, DotShield or any other repository service independently validates the scientific conclusions, operational claims or methodology contained in the publication.

VERSION PRINCIPLE A later website explanation does not silently rewrite a deposited publication.
v1.x / v2.x Deposited record
WEBSITE Explanation
NEW VERSION Requires an explicit publication event
RESEARCH & IP BOUNDARY

Publication makes the research inspectable. It does not erase the boundaries around it.

The records on this page are public research publications. Publication establishes an inspectable research record, but it should not be read as creating rights, approvals or assurances that the deposited work itself does not provide.

01 PUBLICATION STATUS

Public does not mean peer-reviewed.

The publications identified on this page are presented as preprints. A persistent repository record establishes that a version was publicly deposited; it does not by itself establish journal peer review, institutional endorsement or scientific consensus.

PUBLIC RECORDPEER-REVIEW ENDORSEMENT
02 REPOSITORY STATUS

A DOI identifies the record.

DOI and repository infrastructure provide persistent identification and access to deposited research. They should not be interpreted as independent validation by Zenodo, DOI infrastructure or any other repository service of the conclusions contained in the publication.

PERSISTENT IDENTITYVALIDATION OF CONCLUSIONS
03 INTELLECTUAL PROPERTY

Public disclosure is not a blanket licence.

Making research publicly available does not, by itself, grant an unrestricted right to reproduce, commercialise, implement or derive protected material. Any licence attached to a deposited artefact should be read from the applicable repository record or publication itself.

PUBLIC DISCLOSUREUNRESTRICTED IMPLEMENTATION RIGHTS
04 IMPLEMENTATION

A research framework is not a certified system.

A methodology, analytical model or architectural theory may inform later engineering, but publication of the research does not certify a particular software product, security architecture, provider, deployment or operational implementation.

RESEARCH METHODIMPLEMENTATION ASSURANCE
RESEARCH → ENGINEERING

Research may inform a system. The system must still prove itself.

Concepts developed in these publications may later influence software, security architectures, analytical services or other implementations. Once that occurs, claims about the implementation require their own evidence, testing and assurance rather than inheriting authority from the research publication.

RESEARCH Theory · Method · Analysis
ENGINEERING Design · Build · Integration
ASSURANCE Test · Evidence · Decision
§
LICENCE DISCIPLINE
This webpage does not broaden the licence attached to a deposited publication.

Where a repository record or deposited artefact specifies licence terms, those terms should be examined directly for that publication. Summary text on this page is provided for navigation and research context and is not intended to replace, extend or reinterpret the licence associated with the deposited work.

SEPARATE PROTECTION PATHS

Research publication and protected implementation can coexist.

PUBLIC RESEARCH Published concepts and analysis Repository record · version · DOI
IMPLEMENTATION IP Separate technical embodiments May have independent protection or application status
COMMERCIAL AUTHORISATION Rights to deploy or reproduce Must be established independently
CLAIM DISCIPLINE

Follow the claim back to the evidence that supports it.

01 Research claim Inspect the deposited publication.
02 Publication claim Inspect the repository record.
03 Implementation claim Require implementation evidence.
04 IP-status claim Verify against the relevant legal or registry record.
Research record, not legal advice.

This page provides research, publication and provenance information. It does not constitute legal advice, patent advice, a freedom-to-operate opinion, regulatory certification or an assurance statement about a specific implementation.

HOW TO INTERPRET THIS REGISTER

The record should answer the obvious questions.

This page is intended to make the publication history easier to inspect without replacing the deposited research itself. Where precision matters, the repository record and the publication version remain the reference points.

01

What does “verified” mean on this page?

It means that the identified publication title, version and DOI can be traced to the referenced public repository record. “Verified” does not mean that the repository independently endorses the methodology or conclusions.

02

Does a DOI mean the research has been peer reviewed?

No. A DOI provides a persistent identifier for a publication record. The publications listed here are identified as preprints unless the relevant repository record states otherwise.

03

Why can the version date differ from the repository upload date?

A research version may carry an earlier publication or version date than the date on which that artefact was deposited in a repository. Where those events differ, this register keeps them separate rather than collapsing them into one date.

04

Why does NOMATEQ Research still appear in some records?

Historical repository metadata is preserved as recorded at the time of deposit. DotShield® presents the current research register without retroactively replacing publisher or organisational identifiers that form part of the original provenance.

05

Does publication grant permission to implement the research?

Not automatically. Publication makes the research publicly inspectable, but applicable licence terms, intellectual property rights and implementation permissions must be determined from the relevant publication, repository record and any separate rights that may apply.

06

Which record should be treated as authoritative?

For the content of a research publication, inspect the deposited publication version. For publication identity and repository metadata, inspect the DOI-linked repository record. This webpage provides context and navigation but does not silently amend either.

DOI
RECORD PRINCIPLE Do not rely on the summary when the underlying record is available.

Follow the DOI, inspect the deposited version, identify the version being cited, and distinguish the publication record from later interpretation, implementation or commentary.

DOTSHIELD® RESEARCH PUBLICATIONS Four research records. Persistent identifiers. Inspectable provenance.
CCMMCCMM-CYBERKA-SATCANVASBLACKGLASS