Research notesVRP-002 / Research protocol

Studying trust transitions during cyber incidents

A pre-registrable protocol for device loss, role change, key rotation and controlled recovery.

11 minutesBIBTEXRIS

Proposed research protocol without participant data or claimed efficacy. Institutional use requires ethics and data-protection review.

01

Problem

Security assessments often focus on steady-state sign-in. Real failures occur during transitions: a device is lost, a role changes, a key is replaced or a team returns after compromise.

02

Hypotheses

H1: Visible pre- and post-states reduce misinterpretation. H2: Targeted revocation causes less operational interruption than global sign-out. H3: A documented abort path reduces insecure workarounds during incomplete transitions.

03

Scenarios

Four standardised scenarios are tested separately: a lost secondary device, expiry of a temporary role, planned key rotation and recovery after assumed endpoint loss. Production incidents are not simulated.

04

Measures

Measures include time to safe state, correct decisions, assistance, residual old access, cross-device consistency and perceived certainty. Technical state and user belief are recorded separately.

05

Security and ethics boundaries

The protocol uses isolated accounts, synthetic data and pre-defined stop criteria. Participants can withdraw without penalty. Security findings follow responsible disclosure before publication.

06

Expected artefacts

The protocol produces a state diagram, scenario scripts, anonymised timelines, deviation register and replication guide. It promises no positive outcome; disproven hypotheses remain publishable.