SIRI Labs — original research into where the attack surface is actually heading.
Most security research reacts to what's already been exploited. SIRI Labs researches emerging attack surfaces — autonomous systems, connected infrastructure, AI and blockchain — before they're the mainstream target, feeding findings directly into SIRI's testing and detection capabilities.
Understanding a new attack surface and testing it are two different capabilities
By the time an attack technique is well-documented, it's usually already been used.
Emerging technology — autonomous systems, connected infrastructure, agentic AI, blockchain protocols — creates attack surfaces that don't fit cleanly into existing testing methodologies. Someone has to do the original work of understanding how these systems can actually be compromised before that understanding can be turned into a repeatable test. That's what SIRI Labs exists to do.
The gap this closes is measurable: 78% of organisations have already deployed AI into production, but only 12% have a formal AI security testing programme, and 97% of enterprises report having had at least one AI-related security incident already. Waiting for third-party research and mature frameworks to catch up means testing methodology lags years behind what's already been deployed — SIRI Labs is built to close that gap from SIRI's side directly, rather than wait for it to close on its own.
Research from SIRI Labs feeds directly into SIRI Attack's testing methodology for new categories of system, SIRI AI Security and Agentic Security's adversarial testing approach, and SIRI MDR's detection logic — so research findings become a testable methodology and a detection rule, not just a published paper.
What organisations get wrong
Four assumptions that leave emerging attack surfaces untested
Most emerging-technology security gaps come from assuming existing methodology already covers something genuinely new.
“We'll apply our standard testing approach”
Testing methodology built for conventional infrastructure doesn't automatically transfer to autonomous systems, agentic AI, or blockchain protocols — new categories need methodology built specifically for them.
“We'll wait for frameworks to mature”
Frameworks like the OWASP LLM Top 10 and NIST AI RMF are still developing — waiting for them to fully mature means deploying emerging technology with no current testing standard at all.
“Research is interesting, but not directly useful”
Research that doesn't connect to a testing methodology or detection rule stays theoretical — the value is in the connection to what actually gets tested and detected.
“We'll address new attack surfaces once they're well understood”
By the time an attack technique against emerging technology is well-documented publicly, it has typically already been used against early adopters.
What SIRI Labs researches
Original research, feeding directly into testing and detection
Research that becomes a methodology, not just a publication.
Autonomous & Agentic Systems Research
Researching security implications of autonomous decision-making and agentic AI systems.
- Autonomous-system attack research
- Agentic AI methodology development
- Feeds Agentic Security testing
AI & Model Security Research
Original research into LLM, RAG and model-security attack techniques.
- Novel prompt-injection research
- Model-integrity research
- Feeds SIRI AI Security testing
Connected Systems & IoT Research
Researching security of interconnected devices and connected infrastructure.
- IoT protocol research
- Connected-infrastructure attack research
- Feeds SIRI Attack methodology
Blockchain & Web3 Research
Smart-contract and blockchain-protocol security research.
- Smart-contract vulnerability research
- Protocol-level attack research
- Original disclosure & publication
Emerging Threat-Actor Research
Original research into new threat-actor tooling and techniques.
- New TTP identification
- Tooling & technique analysis
- Feeds Threat Intelligence & SIRI MDR
Publication & Disclosure
Publishing original findings responsibly, contributing to the wider security community.
- Responsible-disclosure practice
- Original published research
- Conference & community contribution
Evidence, not guesswork
No original research vs. third-party research feeds only vs. SIRI Labs — what actually differs
Consuming published research and producing it directly are different capabilities.
| Approach | No original research capability | Third-party research feeds only | SIRI Labs |
|---|---|---|---|
| Original emerging-technology research | No | No — consumed, not produced | Yes |
| Testing methodology built for new categories | No | Lags published research | Built directly from research |
| Research connected to detection logic | No | Manual, if at all | Direct — feeds SIRI MDR |
| Time-to-coverage for new attack techniques | N/A | Delayed by publication cycle | Immediate — internal research |
| Original disclosure & publication | No | No | Included |
Sources: 2026 enterprise AI security benchmarks; OWASP Top 10 for LLM Applications (2025); NIST AI Risk Management Framework. Summarised for comparison.
Numbers every board should know
Why original research closes a real, current gap
Have AI in production
Of organisations — deploying faster than testing methodology has kept pace.
Have formal AI testing
Of those organisations — a gap original research directly addresses.
Had an AI incident already
Of enterprises report at least one AI-related security incident to date.
Research-to-methodology path
Findings feed directly into SIRI Attack and SIRI MDR, not just a publication.
Compliance alignment
Standards & frameworks we align to
Our methodology is built around publicly recognised frameworks — not a proprietary checklist. Where a specific certification or attestation is completed and verified, it will be named here explicitly.
Framework references reflect publicly available versions as of publication and describe the standards our methodology is aligned to; they are not a claim of certification, attestation, or audit completion unless stated explicitly elsewhere on this site.
Why SIRI Labs specifically
Research that becomes a test, not just a publication
The value of original research is in what it changes downstream.
Built for emerging technology
AI, autonomous systems and connected infrastructure are core research areas, not an afterthought to conventional security research.
Connected to testing directly
Findings feed into SIRI Attack's methodology and SIRI AI Security's adversarial testing approach, not just a published report.
Connected to detection
New threat-actor and technique research feeds directly into SIRI MDR's detection logic and SIRI's threat-intelligence capability.
Responsible & published
Original findings are disclosed responsibly and contributed to the wider security community, not held purely proprietary.
Who SIRI Labs' research is relevant to
Organisations SIRI Labs' research directly benefits
How research becomes methodology
From original research to testable capability
Research
Original investigation into an emerging attack surface or technique.
OngoingValidate
Confirming findings through practical, reproducible testing.
OngoingOperationalise
Turning validated findings into testing methodology and detection rules.
OngoingPublish
Responsible disclosure and publication to the wider security community.
OngoingFrequently asked
SIRI Labs, answered directly
Is SIRI Labs' research publicly available?
Findings are published responsibly where appropriate, contributing to the wider security community, alongside being operationalised internally into SIRI's own testing and detection capabilities.
How does this research reach the testing SIRI actually delivers?
Findings are translated into testing methodology used by SIRI Attack and SIRI AI Security, and into detection logic used by SIRI MDR — the research is built specifically to feed those capabilities, not to sit separately.
Can we commission specific research into a technology we're building?
Where scoped, yes — this is a common path for organisations building on genuinely novel or emerging technology with no established testing methodology yet.
Does SIRI Labs follow responsible-disclosure practices?
Yes — original findings involving specific vendors or products are disclosed responsibly and coordinated appropriately before any public publication.
How is this different from just reading third-party security research?
Third-party research reflects what others have already found and published; SIRI Labs conducts original investigation, particularly into categories — agentic AI, connected systems, blockchain — where established third-party research is still thin.
Building on something new? Let's understand it together
Talk to SIRI Labs about your emerging technology.
Start a conversation about original research, or move straight to testing what you've already built.
Related