Adversary targeting in cybersecurity is shaped by attacker motivation, available assets, and the relative ease of compromise. Understanding who is likely to attack and why is essential for determining how much security investment an organization actually needs.
Adversary Targets
It's important to understand who the adversaries are going to target, or more importantly, the organization that you work for. What kind of target is it going to be, and who's going to try to attack it?
We want to practice defense in depth. Do we put a wall up? Well, probably. Do we encrypt our data? I hope so. Do we monitor it? Well, I hope so. Do we put guards in front of it? Maybe.
There are a lot of mechanisms, a lot of controls we can put into place, but they all cost money — either cost in implementation, or cost in processing power, or cost in whatever the materials are that go into making it. And so we've got to think about how much do we put into place. Ideally we put it all into place, but we have to think about the company's needs and how much cost it is to implement this.
To understand that, we need to understand how much of a target are we, what kind of assets we have, and who is targeting us. Much of that has to do with the motivation of the adversaries that are going to go after us. Is it some sort of emotional motivation — are they an employee that's left and now is vindictive against the company? Is there some sort of financial gain? By understanding that, we can better understand how much they're going to target us.
Let's look at somebody who might be financially motivated. If somebody is financially motivated, they may target a big business. Why? Because they have lots of assets. There's lots of potential for them to attack this business. So what has to happen is that a big business has to put a lot of time and effort into security to make sure that it's guarded. That would force this attacker to go after maybe a smaller target, one that doesn't have as big of a payoff, but doesn't have as much security out in front of it. So this business still needs security — needs it to the point where they are no longer a target. And maybe this financially motivated person goes after a small business who might not have any kind of security in place, or very little security in place.
Another target could be individuals. Maybe they're targeting just anybody that's out there, or maybe they're targeting some sort of industry that's out there. A common one, because they're easy targets and a lot of times they have lots of money, are the elderly. We find that this is a big target for a lot of people who are financially motivated.
Some of you may have heard the term low-hanging fruit, and this works when it comes to security as well. What low-hanging fruit is, is the idea that a lot of adversaries and a lot of attackers are looking for something easy. If you're hungry and you want an apple and there's an apple tree around you, what you're going to do is look at the apple tree and figure out what is the low-hanging fruit — what is easy to reach up and grab and start eating. You don't want to necessarily climb up into the tree and grab the highest apple on there, that's dangerous to get at, that's going to take a lot of time and energy to get at. So you're going to ignore that as an option and you're going to go for that low-hanging fruit.
The same thing with cybersecurity. What we want to do is figure out how to not become the low-hanging fruit, and put enough security measures in place where people are really just going to move on.
Now, that doesn't eliminate it. There are times when, if we're maybe a business like the government or a financial institute or something where there's a big payoff for adversaries, you may become a very specific target. If you're a very specific target, then that makes it much harder to evade, because somebody's willing to go through the extra time and effort to come and get that apple. And so now we need much more security in place to help us guard against this type of adversary.
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →