Applied Research

Incident-grounded research supporting the framework lifecycle.

ODA3 Institute's research programme identifies observed threats, incident patterns, implementation limitations, and open questions — publishing findings tiered by evidence quality, with an equal and explicit account of what the data does not support. Research is not a marketing function here; it is the input that every control specification, crosswalk mapping, and training module is built from.

Research programme established: March 2026 · Source window and evidence cutoff disclosed per publication
Research Programme

What the programme does — and does not — claim.

ODA3 Institute research identifies observed threats, incident patterns, implementation limitations, and open questions, and flags where current evidence is insufficient to support a normative control. Every output is classified against the same evidence tier standard used across the Institute — Primary Verified, Secondary Verified, Reported, or Estimate — with Notably Absent disclosure applied to every report.

Incident forensics

Original reconstruction of AI-mediated breach chains from public disclosures, regulatory filings and vendor advisories. The public research set does not claim proprietary telemetry, client data or an internal incident dataset.

Normative control development

Research findings may inform SHALL/SHOULD/MAY control specifications where the rationale is supported by cited sources, framework requirements, and documented scope.

Regulatory crosswalk research

Each control is mapped to established frameworks at the article and subcategory level — not framework level — and validated against the published framework text.

Public Incident Research Set

Six incidents. Six evidence tiers assessed independently.

Six publicly documented incidents are currently indexed, with the evidence basis assessed per publication. Each entry links to its full analysis in ODA3 Insights. This research set does not represent proprietary telemetry, client data, or a comprehensive incident dataset.

IDIncident analysisEvidence basisCase study
ODA3-2026-06-INC-001Context AI OAuth-token and tool-supply-chain incidentPrimary source reviewedRead analysis
ODA3-2026-06-INC-002Mythos model zero-day reporting claimsSecondary source reviewedRead analysis
ODA3-2026-06-INC-003MCP protocol and SDK remote-code-execution researchPrimary source reviewedRead analysis
ODA3-2026-06-INC-004Identity-bound execution and credential exposureSource basis disclosed in publicationRead analysis
ODA3-2026-06-INC-005Agentic deployment validation-gate analysisSource basis disclosed in publicationRead analysis
ODA3-2026-06-INC-006AI incident taxonomy gap analysisSource basis disclosed in publicationRead analysis

Full evidence tier definitions, confidence interval methodology, and validation protocols are published on the About page — Research Integrity section.

Publication Types

Six formats, one evidence standard.

Every format is held to the same tiering and Notably Absent discipline. Reports and briefs are always published as a coordinated pair — never a single document serving both a technical and executive audience.

Technical Report

25–40 pages. Inline evidence tier tags throughout the analytical sections. The full forensic reconstruction, MITRE mapping, and control derivation.

Executive Brief

4–10 pages. No inline evidence tier tags — a single Methodology Note at the opening instead. Financial and governance framing first, for board and CISO audiences.

Incident Analysis

Analysis of a publicly documented incident — including source basis, attack chain where supported, technique mapping, limitations, and relevant control considerations.

Practitioner Cheat Sheet

Single standalone document (never a report pair). Slimmed metadata block, inline evidence tags, and a mandatory Notably Absent section.

Regulatory Intelligence

Deadline and obligation briefings mapping specific articles or rules to the ODA3 controls and courses that address them.

Control Framework Update

Revision notes covering research-set additions, evidence-basis changes, and crosswalk updates — versioned and not silently revised.

Methodology

Research publications state what was not observed.

Every ODA3 Institute research publication documents what data was unavailable, which expected threats were not observed in the reviewed public-source material during the reporting period, and which conclusions remain provisional. This is a mandatory publication standard, not an optional disclosure — a research organization that only publishes what is alarming is a marketing operation.

Latest Research

All research is published in ODA3 Insights.

Research Reports, Incident Analyses, Regulatory Intelligence, Control Framework Updates, and Practitioner Guides are indexed, filterable, and searchable in one place.