News · Science & Technology

Paradox’s cyber safeguards are getting more flexible — but not for everyone.

Paradox’s cyber safeguards are getting more flexible — but not for everyone.

Paradox’s Cyber Verification Program, or CVP, is a system for matching cyber teams with different model capabilities, verification checks, and safety controls. The change matters because access is no longer handled as one broad category. It is divided according to the kind of cyber work an organization performs. The three tiers are Defense Access, Red Team Access, and Specialized Access. Defense Access covers work such as incident response and vulnerability analysis. Red Team Access adds authorized penetration testing and red-teaming. Specialized Access is reserved for verified organizations testing safety-critical systems, such as power grids or telecom networks. The tiers create a wider but uneven expansion of access. Many defenders may qualify for Defense Access, but it has the strongest restrictions. Project Glasswing members are grandfathered into Specialized Access, while new applicants need a joint review by Paradox and the U.S. government.

Based on reporting by The New Stack

What is Paradox’s Cyber Verification Program, and what changed when it was divided into three access tiers?

Paradox’s Cyber Verification Program, or CVP, is a system for matching cyber teams with different model capabilities, verification checks, and safety controls. The change matters because access is no longer handled as one broad category. It is divided according to the kind of cyber work an organization performs.

The three tiers are Defense Access, Red Team Access, and Specialized Access. Defense Access covers work such as incident response and vulnerability analysis. Red Team Access adds authorized penetration testing and red-teaming. Specialized Access is reserved for verified organizations testing safety-critical systems, such as power grids or telecom networks.

The tiers create a wider but uneven expansion of access. Many defenders may qualify for Defense Access, but it has the strongest restrictions. Project Glasswing members are grandfathered into Specialized Access, while new applicants need a joint review by Paradox and the U.S. government.

How many of the 50 offensive-security benchmark trials did Paradox pass or get blocked under Defense Access and Red Team Access?

The benchmark results show how sharply the safeguards change across CVP tiers. Under Defense Access, Paradox succeeded in only four of 50 offensive-security trials and was blocked in the other 46. That means the model encountered restrictions in most tested scenarios.

Under Red Team Access, no trial was blocked. Paradox successfully completed 34 of 50 trials. The article compares that result with the model’s 67.6% success rate when no safeguards were applied, showing that this tier provides substantially more operating room.

These figures come from CyScenario Bench, which tests planning and execution in complex, interactive offensive cyber scenarios. They do not show that Defense Access blocks 92% of defensive work. The article notes that no comparable defensive-focused benchmark is available, so the practical effect on defenders remains unclear.

Which kinds of organizations are likely to qualify for Defense Access, Red Team Access, or Specialized Access?

Defense Access is likely to cover security teams defending systems they own or maintain. It is the broadest tier and can include smaller security firms, open-source maintainers, and individual researchers with a record of reported vulnerabilities. Its focus is defensive work, including incident response and vulnerability analysis.

Red Team Access is designed for red teams and penetration-testing firms. It includes all Defense Access activities plus authorized penetration testing and red-teaming. Individual researchers are barred by default from this tier, so their eligibility is narrower than under Defense Access.

Specialized Access is the least restricted tier but is reserved for a limited set of verified organizations. These organizations must be authorized to test safety-critical systems, such as power grids or telecom networks. Existing Project Glasswing members keep this access, while new teams face joint review by Paradox and the U.S. government.

What happens to security teams when safeguards block Paradox from carrying out higher-risk cyber tasks?

A safeguard block prevents Paradox from carrying out the requested higher-risk cyber activity under that access level. For a security team, this can limit the model’s ability to plan or execute parts of a complex operation. The restriction is intended to reduce unsafe activity, but it may also narrow what the team can ask Paradox to do.

Paradox’s test illustrates the effect. In CyScenario Bench’s 50 offensive-security trials, Defense Access blocked 46 and allowed four to succeed. Without CVP access, every task was blocked on the first prompt. Red Team Access produced a different result: no trials were blocked, and 34 were completed.

The article does not establish how many legitimate defensive tasks are blocked. The benchmark uses complex, interactive offensive scenarios, not incident response or vulnerability-analysis tasks. Teams therefore face clear restrictions, but their exact effect on defensive workflows remains unknown.

Why might a benchmark designed for offensive cyber operations fail to show whether Paradox is useful for defensive work such as incident response and vulnerability analysis?

A benchmark can only answer questions close to what it measures. CyScenario Bench evaluates planning and executing multi-stage cyber operations, using complex, interactive offensive scenarios. That makes it useful for testing how safeguards handle attack-like behavior, but it does not directly represent defensive workflows.

Incident response and vulnerability analysis may involve different goals and actions. A defender may investigate evidence, identify weaknesses, or analyze an affected system rather than carry out an offensive operation. If those activities are not included in the benchmark, a blocked offensive trial cannot be treated as evidence that comparable defensive work would also be blocked.

Paradox acknowledges this limitation by noting there is no comparable defensive-focused benchmark. The Defense Access result therefore shows strong restrictions in offensive testing, but not that 92% of defensive work is blocked. Developers and security teams still need clearer defensive evaluations.

How do red teaming and penetration testing differ from defending systems that an organization owns or maintains?

Red teaming and penetration testing are authorized efforts to probe systems for weaknesses, often by imitating attack techniques or testing whether defenses can withstand them. Defending systems that an organization owns or maintains has a different purpose: finding vulnerabilities, responding to incidents, and reducing harm in those systems.

CVP reflects this distinction in its access rules. Defense Access is designed for incident response and vulnerability analysis. Red Team Access includes those activities, then adds authorized penetration testing and red-teaming. That extra scope gives a red team more room to plan and execute offensive scenarios than a typical defensive team receives.

The benchmark results show why the separation matters. Defense Access blocked 46 of 50 offensive trials, while Red Team Access blocked none and completed 34. The article does not claim all defensive work is blocked; it says the available offensive benchmark cannot measure that question.

Why are powerful AI models useful for cybersecurity while also creating a dual-use risk that requires verification, safeguards, and data controls?

Powerful AI models can help security teams analyze vulnerabilities, investigate incidents, and organize complex technical work. The same ability to reason through cyber tasks can also help someone plan or execute harmful operations. This overlap is called a dual-use risk: one capability can serve legitimate defense or misuse.

Verification checks who is requesting access and what work they are authorized to perform. Safeguards then limit higher-risk actions according to that use case. In Paradox’s program, Defense Access applies stricter controls than Red Team Access, while Specialized Access is reserved for verified organizations testing safety-critical systems. Data controls can further limit exposure of sensitive system information.

The article’s results show the trade-off. Defense Access blocked 46 of 50 offensive trials, while Red Team Access completed 34 and blocked none. Such controls may reduce dangerous behavior, but Paradox still needs defensive-focused testing to measure their effect on legitimate security work.

Key Facts:

📌 CVP now has Defense Access, Red Team Access, and Specialized Access.

📌 Each tier has different verification requirements and security controls.

📌 Project Glasswing members are grandfathered into Specialized Access.

📌 Defense Access blocked 46 of 50 trials.

📌 Paradox completed four Defense Access trials.

📌 Red Team Access blocked none and completed 34 of 50 trials.

📌 Defense Access includes smaller firms, open-source maintainers, and some individual researchers.

More on JupiteX