sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · risks.sgit.ai · llms-full

Reading room / risks.sgit.ai / llms-full.txt · section 24 of 58

The 2FA instance graph

The founding scenario, and the graph the whole register model was first worked through on. One missing second factor on admin accounts produces nine risks across three CIA branches, two data classifications, an attack mapped to MITRE, an interval resolution with a rung struck off — and the corpus's canonical governance failure, sitting in the middle of it as a risk in its own right.

51 · 53nodes and edges in the instance graph26 Jun 2026

24 · 34node classes and edge types in the ontologyincluding Acceptance and Interval

9risks from one vulnerabilityR1–R9

T1110.004MITRE ATT&CK technique — credential stuffingATK-1

The chain, from configuration to board

E1: configuration shows no MFAbacksF: admin accounts lack 2FAgives_rise_toV1exposesATK-1: credential stuffing (T1110.004)performed_byTA-1 And from V1 upward, nine risks in three directions — confidentiality, integrity and availability — each with its own owner, its own altitude and its own interval.

The nine risks