Home / Knowledge hub / Threat actor
Knowledge hub
Threat actor
Whoever might attack you, described by capability and motive.
What it means
A threat actor is whoever might attack you, described by what they can do and what they want. Not a hooded figure, but a category. An opportunist scanning the whole internet. A criminal group after payment data. A competitor. A departing employee with a valid login.
Each brings a different budget, a different level of patience, and a different idea of what counts as success.
Why it matters
Naming them keeps a security conversation out of the abstract. Protecting against everything is not a plan. Protecting against somebody who scans every site for one known flaw is a plan. It looks nothing like protecting against somebody who already holds an account.
It settles arguments about spending too. A control that only stops an attacker nobody in your position attracts is one you can defer with a clear conscience. It also keeps the discussion proportionate, because most businesses never attract anybody patient or well funded.
How it shows up
For most businesses running an application, three actors cover almost everything. The automated scanner trying known flaws against every address it finds. The person who signs up for an account and starts changing identifiers in URLs. The insider, or former insider, whose access nobody removed.
Write those three down, which is where a threat model starts, then ask what each would get today. The answer usually redirects next quarter's work better than a tool would. Revisit the list when the business changes, because taking payments or winning a government customer changes who takes an interest. MITRE ATT&CK catalogues the named groups at the far end of the scale.
Questions people ask
Threat actor, answered
What is the difference between a hacker and a threat actor?
A hacker is defined by skill. A threat actor is defined by intent.
Reports use threat actor because it covers groups, insiders and automated operations, not only individuals with technical ability.
What are the main types of threat actor?
The usual grouping runs: opportunists and automated scanners, criminal groups chasing money, insiders, activists, and state backed operations.
MITRE ATT&CK catalogues named groups at the far end of that range, which is further than most businesses need to look.
Would anybody bother attacking a company our size?
The automated ones already are, because they attack every address they can reach. The patient, well funded ones almost certainly are not.
That difference should change what you spend money on, and it usually does not.
Are insiders a bigger risk than outsiders?
Not bigger, but cheaper to exploit and harder to see.
A former employee whose access nobody removed needs no exploit at all, and nothing in your logs looks unusual.
Do we need a threat intelligence feed?
Most application teams do not. Writing down the three actors that actually apply to you gets further than a feed of names you will never meet.
Cyberlop does not supply threat intelligence. It tests what an attacker, with an account or without one, can reach in your application.
Sources
Where this comes from
Related
Terms that sit next to this one
Threat model
Asking what is worth taking, who wants it, and how they would try.
Red team
A simulated adversary given a goal and left to reach it however they can.
Phishing
Persuading someone to hand over credentials by posing as a trusted sender.
Bug bounty
Paying outside researchers for vulnerabilities they report responsibly.
Worried about the one with an account?
The attacker who signs up and starts changing identifiers is exactly what authorisation testing covers, and it is one of the ten classes Cyberlop runs. Get in touch.
Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.