risk
Attacks by capable, motivated threat actors
Because capable, motivated threat actors - outsiders, privileged and non-privileged insiders, organized groups, competitors, malicious partners or suppliers, and nation-states - actively target the organization's cyber resources, deliberate attacks are attempted against its systems and data, resulting in compromise, disruption, or theft when defenses are outmatched.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Risk Assessment & Management
- Logging, Monitoring & Detection
- taxonomy
- nist-800-30-threat-source
- inherent_rating
- high
Details
- risk_id
- cyber-adversary-threat-sources
- category
- cyber_security
- likelihood
- high
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-source
Source
No record-specific source URL is provided.
Connections
- UC-LOG-06 — Evaluate events and declare incidents against defined criteria mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Declaring incidents when criteria are met triggers the response that contains and limits attack impact.
- UC-LOG-09 — Monitor providers and exchange audit data across organizations mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Monitoring provider security-relevant events detects the malicious or compromised supplier threat vector.
- UC-RISK-02 — Integrate risk management into enterprise processes and projects mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- GV.RM-03 member folds cyber risk into ERM, giving threats enterprise governance and resourcing, an enabler rather than the operative defense against attackers.
- UC-RISK-18 — Categorize systems and components by impact and criticality mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Impact/criticality categorization prioritizes protective and resilience investment on high-value systems: necessary context, not the operative defense (inventory-type enabler).
- UC-RISK-06 — Perform periodic enterprise risk assessments mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- NYDFS 500.9 member and explicit cyber scope make the assessment periodically surface evolving cyber threats for treatment, enabling context not the operative defense.
- UC-BCDR-13 — Operate continuous security protection services mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- Operating malware defense and network/endpoint security is a first-order preventive defense that stops attacks from succeeding.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- Continuous host/network/app monitoring to detect attacks and indicators of compromise is a first-order detective defense against active threat actors.
- UC-LOG-10 — Monitor the physical environment for adverse events mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Camera surveillance and badge/entry logs detect physical intrusion attempts by threat actors.
- UC-ASSET-10 — Assess and track changes and exceptions for risk impact mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Assessing and expiring exceptions to security requirements reduces lingering security gaps that attackers exploit, shrinking attack surface.
- UC-RISK-17 — Operate threat intelligence and threat hunting mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- Threat intelligence and proactive threat hunting for IOCs directly detect and counter attacks by motivated threat actors, including activity that evades existing detection.
- UC-ACCESS-18 — Log and monitor system activity, capacity, and incidents mitigates Attacks by capable, motivated threat actors
- strength
- related
- rationale
- Security-event monitoring with alert triage contributes to detecting attacks, though specialized detection sits in dedicated SIEM/IDS controls.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Attacks by capable, motivated threat actors
- strength
- primary
- rationale
- SIEM correlation and threat-intel enrichment detect attacks by matching observed activity to known adversary indicators.