SIRI Labs | Original Security Research — SIRI Security LLC
SIRI Labs

SIRI Labs — original research into where the attack surface is actually heading.

Most security research reacts to what's already been exploited. SIRI Labs researches emerging attack surfaces — autonomous systems, connected infrastructure, AI and blockchain — before they're the mainstream target, feeding findings directly into SIRI's testing and detection capabilities.

78% / 12%Of organisations ship AI to production; formally test its security
97%Of enterprises report at least one AI-related security incident already
ContinuousResearch feeding directly into SIRI Attack and SIRI MDR
Why research has to run ahead of the attack surface, not behind it
Live tracking · scroll to see what's driving the need for original research
Adoption vs. security research
78% / 12%
78% of organisations have deployed AI in production, but only 12% have a formal AI security testing programme — a gap original research is built to close before it's exploited at scale.
New categories, no playbook
EMERGING TECH
Autonomous systems, connected infrastructure, blockchain and agentic AI don't fit neatly into existing security testing categories — original research is what builds the methodology for testing them.
Already showing up
97%
97% of enterprises report having already had at least one AI-related security incident — evidence that the research gap has real, current consequences, not just theoretical ones.
Standardising slowly
OWASP & NIST
Frameworks like the OWASP Top 10 for LLM Applications and the NIST AI RMF are still maturing — original research is part of how the field's understanding of these risks develops in the first place.
Direct application
FEEDS TESTING
Research findings that stay in a paper change nothing — SIRI Labs is built to feed directly into SIRI Attack's testing methodology and SIRI MDR's detection logic.

Understanding a new attack surface and testing it are two different capabilities

By the time an attack technique is well-documented, it's usually already been used.

Emerging technology — autonomous systems, connected infrastructure, agentic AI, blockchain protocols — creates attack surfaces that don't fit cleanly into existing testing methodologies. Someone has to do the original work of understanding how these systems can actually be compromised before that understanding can be turned into a repeatable test. That's what SIRI Labs exists to do.

The gap this closes is measurable: 78% of organisations have already deployed AI into production, but only 12% have a formal AI security testing programme, and 97% of enterprises report having had at least one AI-related security incident already. Waiting for third-party research and mature frameworks to catch up means testing methodology lags years behind what's already been deployed — SIRI Labs is built to close that gap from SIRI's side directly, rather than wait for it to close on its own.

97% of enterprises have already had at least one AI-related security incident
Against only 12% with a formal AI security testing programme — original research into emerging attack surfaces isn't an academic exercise, it's addressing risk that's already materialising. (2026 enterprise AI security benchmarks.)

Research from SIRI Labs feeds directly into SIRI Attack's testing methodology for new categories of system, SIRI AI Security and Agentic Security's adversarial testing approach, and SIRI MDR's detection logic — so research findings become a testable methodology and a detection rule, not just a published paper.

What organisations get wrong

Four assumptions that leave emerging attack surfaces untested

Most emerging-technology security gaps come from assuming existing methodology already covers something genuinely new.

01 — METHODOLOGY

“We'll apply our standard testing approach”

Testing methodology built for conventional infrastructure doesn't automatically transfer to autonomous systems, agentic AI, or blockchain protocols — new categories need methodology built specifically for them.

02 — WAITING

“We'll wait for frameworks to mature”

Frameworks like the OWASP LLM Top 10 and NIST AI RMF are still developing — waiting for them to fully mature means deploying emerging technology with no current testing standard at all.

03 — THEORY VS. PRACTICE

“Research is interesting, but not directly useful”

Research that doesn't connect to a testing methodology or detection rule stays theoretical — the value is in the connection to what actually gets tested and detected.

04 — REACTIVITY

“We'll address new attack surfaces once they're well understood”

By the time an attack technique against emerging technology is well-documented publicly, it has typically already been used against early adopters.

What SIRI Labs researches

Original research, feeding directly into testing and detection

Research that becomes a methodology, not just a publication.

AUTONOMOUS SYSTEMS

Autonomous & Agentic Systems Research

Researching security implications of autonomous decision-making and agentic AI systems.

  • Autonomous-system attack research
  • Agentic AI methodology development
  • Feeds Agentic Security testing
See Agentic Security →
AI & MODEL SECURITY

AI & Model Security Research

Original research into LLM, RAG and model-security attack techniques.

  • Novel prompt-injection research
  • Model-integrity research
  • Feeds SIRI AI Security testing
See SIRI AI Security →
CONNECTED SYSTEMS

Connected Systems & IoT Research

Researching security of interconnected devices and connected infrastructure.

  • IoT protocol research
  • Connected-infrastructure attack research
  • Feeds SIRI Attack methodology
See SIRI Attack →
BLOCKCHAIN

Blockchain & Web3 Research

Smart-contract and blockchain-protocol security research.

  • Smart-contract vulnerability research
  • Protocol-level attack research
  • Original disclosure & publication
See SIRI Attack →
THREAT RESEARCH

Emerging Threat-Actor Research

Original research into new threat-actor tooling and techniques.

  • New TTP identification
  • Tooling & technique analysis
  • Feeds Threat Intelligence & SIRI MDR
See Threat Intelligence →
PUBLICATION

Publication & Disclosure

Publishing original findings responsibly, contributing to the wider security community.

  • Responsible-disclosure practice
  • Original published research
  • Conference & community contribution
See SIRI Academy →

Evidence, not guesswork

No original research vs. third-party research feeds only vs. SIRI Labs — what actually differs

Consuming published research and producing it directly are different capabilities.

ApproachNo original research capabilityThird-party research feeds onlySIRI Labs
Original emerging-technology researchNoNo — consumed, not producedYes
Testing methodology built for new categoriesNoLags published researchBuilt directly from research
Research connected to detection logicNoManual, if at allDirect — feeds SIRI MDR
Time-to-coverage for new attack techniquesN/ADelayed by publication cycleImmediate — internal research
Original disclosure & publicationNoNoIncluded

Sources: 2026 enterprise AI security benchmarks; OWASP Top 10 for LLM Applications (2025); NIST AI Risk Management Framework. Summarised for comparison.

Numbers every board should know

Why original research closes a real, current gap

78%

Have AI in production

Of organisations — deploying faster than testing methodology has kept pace.

12%

Have formal AI testing

Of those organisations — a gap original research directly addresses.

97%

Had an AI incident already

Of enterprises report at least one AI-related security incident to date.

Direct

Research-to-methodology path

Findings feed directly into SIRI Attack and SIRI MDR, not just a publication.

Compliance alignment

Standards & frameworks we align to

Our methodology is built around publicly recognised frameworks — not a proprietary checklist. Where a specific certification or attestation is completed and verified, it will be named here explicitly.

ISO/IEC 27001:2022 SOC 2 (AICPA TSC) NIST CSF 2.0 MITRE ATT&CK OWASP Top 10 OWASP Top 10 for LLM Applications NIST AI RMF ISO/IEC 42001 ISO 22301 CERT-In Directions 2022

Framework references reflect publicly available versions as of publication and describe the standards our methodology is aligned to; they are not a claim of certification, attestation, or audit completion unless stated explicitly elsewhere on this site.

Why SIRI Labs specifically

Research that becomes a test, not just a publication

The value of original research is in what it changes downstream.

01

Built for emerging technology

AI, autonomous systems and connected infrastructure are core research areas, not an afterthought to conventional security research.

02

Connected to testing directly

Findings feed into SIRI Attack's methodology and SIRI AI Security's adversarial testing approach, not just a published report.

03

Connected to detection

New threat-actor and technique research feeds directly into SIRI MDR's detection logic and SIRI's threat-intelligence capability.

04

Responsible & published

Original findings are disclosed responsibly and contributed to the wider security community, not held purely proprietary.

Who SIRI Labs' research is relevant to

Organisations SIRI Labs' research directly benefits

AI Companies Technology & SaaS Organisations building on emerging technology Financial Services Critical Infrastructure & Energy The wider security research community

How research becomes methodology

From original research to testable capability

01

Research

Original investigation into an emerging attack surface or technique.

Ongoing
02

Validate

Confirming findings through practical, reproducible testing.

Ongoing
03

Operationalise

Turning validated findings into testing methodology and detection rules.

Ongoing
04

Publish

Responsible disclosure and publication to the wider security community.

Ongoing

Frequently asked

SIRI Labs, answered directly

Is SIRI Labs' research publicly available?

Findings are published responsibly where appropriate, contributing to the wider security community, alongside being operationalised internally into SIRI's own testing and detection capabilities.

How does this research reach the testing SIRI actually delivers?

Findings are translated into testing methodology used by SIRI Attack and SIRI AI Security, and into detection logic used by SIRI MDR — the research is built specifically to feed those capabilities, not to sit separately.

Can we commission specific research into a technology we're building?

Where scoped, yes — this is a common path for organisations building on genuinely novel or emerging technology with no established testing methodology yet.

Does SIRI Labs follow responsible-disclosure practices?

Yes — original findings involving specific vendors or products are disclosed responsibly and coordinated appropriately before any public publication.

How is this different from just reading third-party security research?

Third-party research reflects what others have already found and published; SIRI Labs conducts original investigation, particularly into categories — agentic AI, connected systems, blockchain — where established third-party research is still thin.

Building on something new? Let's understand it together

Talk to SIRI Labs about your emerging technology.

Start a conversation about original research, or move straight to testing what you've already built.

24/7 for active incidents: +91 79819 12046

Visit or contact us — two locations, one team

SIRI Security LLC — Hyderabad, India

HeadquartersHyderabad, Telangana, India
24/7 emergency line+91 79819 12046
Emailcontact@sirisecurity.com
WhatsAppMessage us on WhatsApp
ReachIndia & the United States · serving international organisations
Legal & regulatory counterpartSIRI Law LLP

SIRI Security LLC — Dallas, Texas, USA

U.S. operationsDallas, Texas, United States
24/7 emergency line+91 79819 12046
Emailcontact@sirisecurity.com
WhatsAppMessage us on WhatsApp
ReachServing U.S. & North American organisations
Exact office address[INSERT VERIFIED DALLAS OFFICE ADDRESS]
Scroll to Top