Platform

Platform overview How it works Authorization testing Evidence & reports Private scanning Integrations

Solutions

Security agencies Product teams Regulated industries Partner programme

Learn

Blog Knowledge hub Compare

Resources

Pricing Documentation FAQ Security & data What we haven’t proved

Company

About Contact Careers Sign in to the platform Start a $199 pilot

Home / Knowledge hub / Threat actor

Knowledge hub

Threat actor

Whoever might attack you, described by capability and motive.

What it means

A threat actor is whoever might attack you, described by what they can do and what they want. Not a hooded figure, but a category. An opportunist scanning the whole internet. A criminal group after payment data. A competitor. A departing employee with a valid login.

Each brings a different budget, a different level of patience, and a different idea of what counts as success.

Why it matters

Naming them keeps a security conversation out of the abstract. Protecting against everything is not a plan. Protecting against somebody who scans every site for one known flaw is a plan. It looks nothing like protecting against somebody who already holds an account.

It settles arguments about spending too. A control that only stops an attacker nobody in your position attracts is one you can defer with a clear conscience. It also keeps the discussion proportionate, because most businesses never attract anybody patient or well funded.

How it shows up

For most businesses running an application, three actors cover almost everything. The automated scanner trying known flaws against every address it finds. The person who signs up for an account and starts changing identifiers in URLs. The insider, or former insider, whose access nobody removed.

Write those three down, which is where a threat model starts, then ask what each would get today. The answer usually redirects next quarter's work better than a tool would. Revisit the list when the business changes, because taking payments or winning a government customer changes who takes an interest. MITRE ATT&CK catalogues the named groups at the far end of the scale.

Questions people ask

Threat actor, answered

What is the difference between a hacker and a threat actor?

A hacker is defined by skill. A threat actor is defined by intent.

Reports use threat actor because it covers groups, insiders and automated operations, not only individuals with technical ability.

What are the main types of threat actor?

The usual grouping runs: opportunists and automated scanners, criminal groups chasing money, insiders, activists, and state backed operations.

MITRE ATT&CK catalogues named groups at the far end of that range, which is further than most businesses need to look.

Would anybody bother attacking a company our size?

The automated ones already are, because they attack every address they can reach. The patient, well funded ones almost certainly are not.

That difference should change what you spend money on, and it usually does not.

Are insiders a bigger risk than outsiders?

Not bigger, but cheaper to exploit and harder to see.

A former employee whose access nobody removed needs no exploit at all, and nothing in your logs looks unusual.

Do we need a threat intelligence feed?

Most application teams do not. Writing down the three actors that actually apply to you gets further than a feed of names you will never meet.

Cyberlop does not supply threat intelligence. It tests what an attacker, with an account or without one, can reach in your application.

Worried about the one with an account?

The attacker who signs up and starts changing identifiers is exactly what authorisation testing covers, and it is one of the ten classes Cyberlop runs. Get in touch.

Or start with a $199 pilot on one application: thirty days, success criteria agreed before day one, credited against the annual if you convert.