2 Threats and Attacks
Learn how cyber threats and attacks work, recognize common actors and methods, and assess risk to choose practical defenses.
Threats and attacks
Cybersecurity planning begins by distinguishing a possible source of harm from an attempt to cause harm. A cyber threat is a person, group, event, or condition that could harm information or systems. An is an attempt to exploit a weakness to gain access, steal or alter information, disrupt services, or cause damage. Considering who might act, how events could unfold, and what could be affected helps an organization choose relevant defenses.
Who may cause harm?
Threat actors differ in goals, resources, access, and willingness to take risks. Common categories include:
Cybercriminals, who seek financial gain through activities such as fraud, data theft, or ransomware.
Nation-state actors, who may pursue intelligence, strategic advantage, or disruption, sometimes through long-running operations.
Hacktivists, who use cyber activity to promote a political or social cause.
Insiders, such as employees and contractors, who may misuse legitimate access intentionally or cause harm through error or deception.
Other actors, including competitors and opportunistic attackers, who may target systems they believe are vulnerable.
These categories can overlap. Rather than relying only on an actor’s label, consider capability, intent, and targeting. Harm can also arise from accidental or environmental sources, not only deliberate adversaries.
Takeaway: Identify plausible sources of harm in context, including trusted users and non-adversarial events.
How attacks unfold
methods describe how an actor tries to achieve an objective. A single incident may use several methods: an attacker might trick a user into sharing credentials, access the account, explore connected systems, and then steal information.
Common methods include:
Credential attacks: stealing, guessing, or reusing passwords or other authentication material.
Exploitation: taking advantage of a software flaw or insecure configuration to gain access or privileges.
Denial of service: overwhelming or disrupting a service so legitimate users cannot use it.
Data theft or tampering: accessing, copying, changing, or destroying information without authorization.
Supply-chain compromise: abusing a trusted supplier, service, or software update to reach downstream organizations.
: manipulating people into disclosing information, transferring money, opening a harmful file, or granting access.
MITRE ATT&CK organizes observed adversary behavior into tactics, the goal; techniques, the method; and procedures, a specific implementation. It is a reference for defenders, not a checklist that every organization must fully implement.
Takeaway: Focus on how methods can connect, rather than treating each technique as an isolated event.
and its effects
is software intended to perform unauthorized or harmful actions. Common types differ in how they spread or affect systems:
A virus attaches to files or programs and spreads when they are run.
A worm spreads between systems, often without requiring someone to run an infected file.
A Trojan appears legitimate or useful but performs hidden malicious actions.
Spyware secretly gathers information about a user or system.
Ransomware blocks access to data or systems, commonly by encrypting files, and demands payment. Some attackers also steal data and threaten to publish it, a tactic often called double extortion.
Botnet turns infected devices into remotely controlled members of a network that may send spam or disrupt services.
can arrive through deceptive messages or downloads, compromised websites, stolen credentials, or exploited vulnerabilities. An incident may combine with other methods, so defenses need to address both initial entry and what an attacker might do afterward.
Recognizing
exploits trust, urgency, authority, curiosity, or fear to influence a person’s actions. is a common form: an attacker impersonates a trusted person or organization to induce someone to disclose sensitive information, visit a deceptive site, or run malicious content.
Related forms are distinguished by their target or channel:
Spear targets a particular person or organization.
Whaling targets a senior or otherwise high-value individual.
Smishing uses text messages.
Vishing uses voice calls.
Warning signs can include unexpected requests, pressure to act quickly, unusual payment or credential requests, and sender or web addresses that do not match the claimed source. Because convincing messages can be difficult to recognize, verify sensitive requests through a separate, trusted channel and report suspicious messages using your organization’s process.
Takeaway: When a request is unexpected or urgent, verify it through a trusted route rather than relying on the message itself.
Assessing and reducing risk
A connects plausible harmful events to the assets and activities they could affect. It estimates likelihood and consequences to help prioritize risk reduction; it is not a prediction that an will certainly occur.
A practical assessment can proceed in six steps:
Identify important assets and activities. Consider sensitive data, user accounts, devices, services, and the business functions that depend on them.
Identify relevant threat sources and events. For example, a message might lead to account compromise, or ransomware might interrupt a critical service.
Find weaknesses and existing safeguards. Consider exposed services, unpatched software, excessive access, weak recovery arrangements, and gaps in monitoring or user reporting.
Estimate likelihood and impact. Use available evidence and organizational context. Consider effects on confidentiality, integrity, availability, operations, finances, and people.
Prioritize and reduce risk. Focus on significant risks and safeguards that reduce likelihood or limit harm.
Review and update. Reassess as systems, threats, business needs, and safeguards change. Use incident reports and exercises to improve the assessment.
For example, an organization that relies on email and shared files might assess the risk of a convincing message leading to a compromised employee account. It could require -resistant multifactor authentication for important accounts, limit access to what each role needs, keep software updated, maintain protected backups, and train staff to verify unusual requests and report suspicious activity. Monitoring and a tested response plan can help limit damage if prevention fails.
Effective risk management is ongoing: understand risk, protect systems, detect incidents, respond, and recover. Revisit assessments as conditions change.
Takeaway: Link threats to real assets and weaknesses, then select safeguards according to likely consequences and review them over time.