TechKnowSurge
VideoSecurityFree

An Adversary’s Targets

Adversary targeting in cybersecurity is shaped by attacker motivation, available assets, and the relative ease of compromise. Understanding who is likely to attack and why is essential for determining how much security investment an organization actually needs.

Complete this video to capture a CTF flag worth 1 point.

About this video

Determining the right level of security investment requires a clear understanding of an organization's threat landscape, specifically who is likely to attack it, what assets make it a target, and what motivates potential adversaries. Security controls, whether encryption, monitoring, physical barriers, or access restrictions, all carry real costs in money, processing overhead, and implementation effort. Because no organization has unlimited resources, prioritizing those controls intelligently depends on an honest assessment of how attractive a target the organization actually is. Adversary motivation is a central factor in that assessment. Financially motivated attackers, for example, weigh potential payoff against the difficulty of a successful attack. A large enterprise with significant assets is an appealing target, but strong security pushes those attackers toward smaller, less-protected organizations or toward individuals, particularly demographics like the elderly who may be easier to exploit and still offer financial value. This dynamic is captured by the concept of low-hanging fruit: attackers, like anyone conserving effort, gravitate toward the easiest available option. An organization that invests enough in security to stop being the easiest option will redirect most opportunistic attackers elsewhere. That said, this approach has limits. Organizations in sectors such as government, defense, or financial services may face highly motivated, well-resourced adversaries who have specifically identified them as a target worth pursuing despite strong defenses. In those cases, the threat is no longer opportunistic but deliberate, and the security posture must reflect that elevated risk with correspondingly deeper and more layered controls.

What you'll learn

What's covered

Adversary Targets

Key terms

Threat Actor
An individual or group responsible for a security incident or attack.
Asset
Any resource of value to an organization, including hardware, software, data, and personnel.
Attack Surface
The total set of points in a system where an unauthorized user can attempt to enter or extract data.
Risk
The potential for loss or harm resulting from a threat exploiting a vulnerability.
Low-Hanging Fruit
A term describing easily exploitable targets or vulnerabilities that opportunistic attackers will pursue before attempting more difficult ones.
Defense-in-Depth
Defense-in-Depth is a security architecture strategy that layers multiple independent controls across technical, physical, and administrative domains so that the failure of any single control does not result in a complete security breach.

Topics

Threat Actors Adversary Targeting Attack Surface Risk Management Cybersecurity Fundamentals Opportunistic Attacks

Transcript

It's important to understand who the adversaries are going to target, or more importantly, the organization that you work for. What kind of target is it going to be, and who's going to try to attack it?

Security costs money

We want to practice defense in depth. Do we put a wall up? Well, probably. Do we encrypt our data? I hope so. Do we monitor it? Well, I hope so. Do we put guards in front of it? Maybe.

There are a lot of mechanisms, a lot of controls we can put into place, but they all cost money — either cost in implementation, or cost in processing power, or cost in whatever the materials are that go into making it. And so we've got to think about how much do we put into place. Ideally we put it all into place, but we have to think about the company's needs and how much cost it is to implement this.

To understand that, we need to understand how much of a target are we, what kind of assets we have, and who is targeting us. Much of that has to do with the motivation of the adversaries that are going to go after us. Is it some sort of emotional motivation — are they an employee that's left and now is vindictive against the company? Is there some sort of financial gain? By understanding that, we can better understand how much they're going to target us.

Financially motivated adversaries

Let's look at somebody who might be financially motivated. If somebody is financially motivated, they may target a big business. Why? Because they have lots of assets. There's lots of potential for them to attack this business. So what has to happen is that a big business has to put a lot of time and effort into security to make sure that it's guarded. That would force this attacker to go after maybe a smaller target, one that doesn't have as big of a payoff, but doesn't have as much security out in front of it. So this business still needs security — needs it to the point where they are no longer a target. And maybe this financially motivated person goes after a small business who might not have any kind of security in place, or very little security in place.

Another target could be individuals. Maybe they're targeting just anybody that's out there, or maybe they're targeting some sort of industry that's out there. A common one, because they're easy targets and a lot of times they have lots of money, are the elderly. We find that this is a big target for a lot of people who are financially motivated.

Low-hanging fruit

Some of you may have heard the term low-hanging fruit, and this works when it comes to security as well. What low-hanging fruit is, is the idea that a lot of adversaries and a lot of attackers are looking for something easy. If you're hungry and you want an apple and there's an apple tree around you, what you're going to do is look at the apple tree and figure out what is the low-hanging fruit — what is easy to reach up and grab and start eating. You don't want to necessarily climb up into the tree and grab the highest apple on there, that's dangerous to get at, that's going to take a lot of time and energy to get at. So you're going to ignore that as an option and you're going to go for that low-hanging fruit.

The same thing with cybersecurity. What we want to do is figure out how to not become the low-hanging fruit, and put enough security measures in place where people are really just going to move on.

Now, that doesn't eliminate it. There are times when, if we're maybe a business like the government or a financial institute or something where there's a big payoff for adversaries, you may become a very specific target. If you're a very specific target, then that makes it much harder to evade, because somebody's willing to go through the extra time and effort to come and get that apple. And so now we need much more security in place to help us guard against this type of adversary.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →