Understanding who threatens an organization—and how they think, operate, and choose their targets—is foundational to building effective defenses. This content introduces threat actors, their motivations and capabilities, and the role of threat modeling in identifying and assessing organizational risk.
Understanding Adversaries
As security professionals, we need to take a look at our organization and what are the risks to that organization. But a lot of the risks that come into play when it comes to the organization is going to be carried out by some sort of adversary, some sort of threat agent, somebody that's going to be attacking our systems, or trying to get into our systems, or trying to steal data, or trying to do something malicious to our organization. But to really understand what they would be doing and how they would approach that, we have to get into the minds of an adversary. What are their thinking and what are their capabilities?
The first thing to understand about adversaries is it could go by many different names: threat actors, threat agents, bad actors, malicious actors, hackers, cyber criminals. These are some of the different names that you'll see out there. Now, some of these really essentially have the same meaning behind it and really have the same definition behind it, and we could use them interchangeably. Some of these mean something a little bit different. Just understand, as we go through this curriculum I'm going to use all of these terms probably throughout this curriculum, and essentially we just mean the adversary who's carrying out the attack on our organization.
So what is the definition? A threat agent or threat actor is an individual or entity — so it could be a whole organization as well — that has the intent to do harm. So the adversary is going to be somebody who is trying to do harm to our company, to carry out some sort of malicious behavior to our company.
There are many different threat actors that are out there. If I'm in charge of security for a government organization, the threat actor that's going to attack that government organization is probably going to look quite a bit different than somebody that's going to attack maybe a school, or maybe it's going to be a financial institute, or maybe it's going to be some individual. Those threat actors look very different. So by understanding the threat actors, we can better understand who their targets are and better equip ourselves to protect against those threat actors.
By understanding who is the threat actor, the processes that they use, objectives that they have, their targets that they may target, the skills that they have, and the motivations they have — by fully understanding this, we can get in the minds of the actor and then prepare our organization to protect itself against these threat actors.
As an example, maybe I have a small business and maybe I have just a small office with just a few users. Well, I don't really maybe have that much money invested into this business and I'm not going to be a high target. Maybe it's going to be just some sort of threat agent that really is just looking for the low-hanging fruit, somebody that's an easy target. But now step it up. Maybe I'm a financial institute and there is lots of money to be had for hacking my network. Well, now I'm going to have a much more complex target, and there's going to be a lot more threat actors and a lot more advanced threat actors that are going to try to get into my network.
So what we're going to do is we're going to go through a process using threat modeling. The idea behind threat modeling is that we're going to assess what is the threat to our systems and evaluate what the threat is to our systems. And we do that by really understanding what the threat agents are, what their motivations are, and how they would go about attacking our network. So threat modeling is identifying and enumerating potential threats to our organization. There's a lot of different threat models that are out there. We're not going to get real in-depth into this at this point in time, but just understand that we are going to be going through this threat modeling process to identify risks to our organization.
Not all threats are intentional. We have people within the company that pose a threat to the company, and their actions, and how much experience they have, and how much understanding around security they have, and old processes and old systems within our organization all can pose a threat to our organization. We may cover that to a certain degree within this course. But the intention of this course is really to understand more of adversaries and how adversaries are going to carry out attacks against an organization. So we're going to be taking a deep dive into adversaries, those who are really intentionally going after our network, and how they're going to go about doing that.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →