Cybersecurity research topics
Every cybersecurity discipline eventually reaches a decision about whether an action may proceed.
The disciplines differ in purpose, evidence, controls, and consequence. They share a boundary: a protected action must be permitted or refused. This library examines the separate current existence condition the organization can observe when that decision is made.
The shared boundary
Necessary facts do not become the same fact merely because they are all valid.
Cybersecurity protects systems and operations. Network security protects communication and access paths. Authentication evaluates presented evidence. Zero Trust repeatedly evaluates access. Identity and access management governs who may receive and use authority.
Each discipline establishes necessary facts. None should be asked to stand in for a different fact: whether the governed existence relationship currently returns present at the organization’s decision point.
Begin with the discipline you know
Five foundational paths into the same unresolved condition.
Where prevention, detection, response, identity, devices, sessions, and protected actions meet.
Network securityWhy the network observes the current existence condition but does not create existence or replace credentials and authorization.
AuthenticationWhat credentials and factors establish, what persists afterward, and what remains current.
Zero TrustHow a separate present-tense existence result may become one input to repeated policy decisions.
Identity and access managementThe distinction between governing who may act and establishing whether that known participant is present now.
Continue through a control or attack path
Eight additional subjects reveal where trusted authority becomes operational consequence.
Why several valid factors strengthen an authentication event without independently maintaining the participant’s present existence afterward.
Session securityHow a session inherits prior trust, how that trust continues, and where a current external condition may govern continuation.
Privileged access managementThe distinction between controlling powerful authority and proving that the authorized administrator is present at a consequential action.
Endpoint securityWhy device health, telemetry, and policy compliance remain different from current human participation.
RansomwareWhere presence may constrain selected human-authorized actions, and why it does not independently stop malicious software or automated execution.
PhishingWhat presence changes when assertions are stolen, and what it cannot change when the genuine participant is present but deceived.
Account takeoverHow stolen credentials, sessions, or recovery authority differ from a separately maintained existence relationship.
Cloud securityHow human presence can become one bounded input to distributed cloud policy without replacing workload identity or shared responsibility.
Follow authority into consequence
Eight decision paths examine where credentials, policy, and current existence must remain separate.
Why the EAID cannot replace access evidence and why a found identification must never authorize entry.
Access controlHow policy determines permission while existence remains a separate current condition consumed by the application.
Protected actionsWhere valid authority becomes consequence and where a current present-or-absent result can be required.
Transaction authorityWhy execution may require both valid approval and the maintained existence of the assigned participant.
Account recoveryWhy recovery must preserve independent identity and credential evidence rather than treating possession as authority.
Insider threatWhat current existence can make observable when a properly authorized participant may still act harmfully.
Data loss preventionHow selected data-release actions may consume existence without replacing classification, policy, or custody.
Supply chain securityHow a bounded current condition may cross organizational relationships without claiming to validate the entire chain.
The research question
What must be true before historical authority may support a present action?
A valid identity, credential, device, role, network path, and session may all be required. The EAID is not an access credential, and finding or possessing an identification does not authorize entry into the organization’s application. The research asks whether a separately maintained existence condition must also be observed before selected protected consequences occur.
The protected decision continues under the organization’s existing policy.
The organization applies the other result before the protected action executes.
A separate input
Existence does not replace the discipline that receives it.
The organization still determines identity, credentials, authority, privilege, device posture, network policy, application behavior, and business consequence. Existence establishment completes when the Rendering Agent is released and the organization’s page loads. The organization’s page still applies its own credential and authorization requirements.
From that arrival forward, existence maintains itself through recurring heartbeat. The network is the place where the organization observes the current binary result and decides what must happen when it is absent.
A bounded claim
This is not a claim that one factor solves cybersecurity.
Presence does not independently establish attention, intent, endpoint integrity, freedom from coercion, correct authorization, safe software, secure configuration, or harmless content. It does not replace prevention, detection, response, recovery, or governance.
The claim is narrower: the governed existence condition can be established through private arrival, maintained through recurring renewal, observed at a protected decision, and made consequential when the condition ends. It is not continuous authentication and is not a substitute for a credential.
How to use this library
Each topic begins with what the discipline already does correctly.
The analysis then separates that established fact from current presence, identifies the point where the distinction matters, describes how an existence result may be used, and states what the method does not claim to solve.
The pages are entry points into one research project. They are not independent product claims or substitutes for the standards, controls, and expertise already governing each field.
Continue the examination