Knowing who attacks and how helps you defend the right things.
Threat Actors
Who attacks, and why — from nation-states to insiders.
Tap or hover a part to learn more.
Well-resourced, stealthy.
Government-backed groups (APTs) with significant resources, pursuing espionage or disruption. Patient, sophisticated and hard to detect — motivated by strategy, not money.
Check your understanding
1. Which actor is typically the most financially motivated?
2. Why are insiders especially dangerous?
Who and how
- Threat actors: nation-state (well-resourced, stealthy), organised cybercrime (financially motivated, ransomware), hacktivists (ideological), insiders (malicious or negligent) and script kiddies.
- Threat intelligence turns raw data into decisions — IOCs (indicators of compromise like malicious IPs/hashes) and TTPs (tactics, techniques and procedures).
- MITRE ATT&CK is the shared language for adversary behaviour, complementing the cyber kill chain.
This feeds directly into Security Operations and threat hunting.
