GRC Careers

HomeResourcesThreat Actors

CS-006 · Foundations

Threat Actors

Who attacks, what motivates them, and how their goals shape the defenses you need.

Executive Summary

Threat actors are the people and groups that attempt to compromise systems and data. They range from opportunistic criminals and organized ransomware crews to insiders, hacktivists, and well-resourced nation-state groups. Understanding who is likely to target an organization, and why, helps teams prioritize the right defenses.

What It Is

A threat actor is any individual or group that carries out or intends to carry out malicious cyber activity. Common categories include cybercriminals motivated by money, nation-state groups pursuing espionage or disruption, hacktivists driven by a cause, insiders who misuse legitimate access, and unskilled attackers who rely on tools built by others. Actors differ widely in skill, funding, patience, and goals. The most capable groups, sometimes described as advanced persistent threats, can stay hidden inside a network for a long time. Threat intelligence is the practice of studying these actors, their motives, and their methods.

Why It Matters

Defense is not one size fits all. A small business worried about opportunistic ransomware faces different risks than a defense contractor targeted by a nation-state group. Knowing the likely adversary shapes where to invest, what to monitor, and how to respond. It also helps teams communicate risk to leadership in concrete terms rather than vague fear. For professionals, the ability to describe threat actors and map them to realistic scenarios is expected in security operations, threat intelligence, and risk roles, and it makes an incident response far more focused.

How It Works

Analysts profile threat actors by capability, motivation, and typical behavior. They study the tactics, techniques, and procedures an actor uses, often mapping them to a common framework so patterns can be recognized across incidents. This profiling feeds into threat modeling, where teams ask which actors would want their assets and how those actors tend to operate. The output guides prioritization: an organization likely to face financially motivated ransomware focuses on backups, segmentation, and email defense, while one facing espionage invests more in detection of stealthy, long-term intrusions. Threat intelligence keeps these profiles current as actors evolve.

Architecture Diagram

Cybercriminals: money, ransomware and fraud
Nation-state groups: espionage and disruption, high capability
Hacktivists: ideology and attention
Insiders: misuse of legitimate access
Low-skill attackers: rely on others' tools
Threat actors vary by capability and motivation, and each profile points to different defensive priorities.

Visual Workflow

Identify the assets that are valuable and to whom they would be valuable.Determine which threat actor types would plausibly target the organization.Study those actors' typical motivations and methods.Map likely tactics to a common framework to recognize patterns.Prioritize defenses and monitoring against the most likely actors.Update the picture as threat intelligence and the environment change.

Common Attacks

Common Mistakes

Best Practices

Quick Checklist

Recommended Tools

Threat intelligence platforms and feeds
Provide current information on actors and their methods
MITRE ATT&CK knowledge base
Common language for actor tactics and techniques
SIEM and detection tooling
Surfaces behavior consistent with known actor tactics
User and entity behavior analytics (UEBA)
Helps detect insider and anomalous account activity

Industry Standards

MITRE ATT&CK
Widely used taxonomy of adversary tactics and techniques
NIST SP 800-30
Guidance on risk assessment including threat sources
NIST Cybersecurity Framework (CSF) 2.0
Identify and Detect functions cover understanding threats

Career Relevance

Threat actor knowledge is core to threat intelligence analysts, SOC analysts, incident responders, and risk professionals. GRC analysts use it to justify controls and describe risk to leadership. Penetration testers and red teams emulate specific actors to test defenses. Framing threats in terms of realistic adversaries is a skill valued across security and governance roles.

Interview Questions

Related Certifications

CompTIA Security+ GIAC Cyber Threat Intelligence (GCTI) ISC2 Certified in Cybersecurity (CC)

Further Reading

Key Takeaways

Download PDFDownload PNG

FAQ

Is a small organization really a target for threat actors?

Yes. Much criminal activity is automated and opportunistic, hitting whatever is vulnerable rather than a chosen target. Small organizations are also attacked as a path to larger partners in a supply chain.

What is an advanced persistent threat?

It is a well-resourced, often nation-state actor that gains access and stays hidden for a long time to pursue espionage or strategic goals. The name reflects their capability, patience, and persistence rather than a single technique.

How do insiders fit into threat actors?

Insiders are people with legitimate access, such as employees or contractors, who misuse it intentionally or cause harm through negligence. They are a distinct category because they start with trust that outsiders must work to obtain.

Get all 116 reference sheets
The complete AGJ Cybersecurity Professional Reference Library, print-ready PDFs and PNGs.
Browse the library

Related Careers

Related certifications

CompTIA Security+GIAC Cyber Threat Intelligence (GCTI)ISC2 Certified in Cybersecurity (CC)

Current openings

Live openings appear on the web version. Browse the job board for current GRC and security roles.
Browse all jobs

Suggested learning path

  1. Ground the basics with CS-001 Cybersecurity
  2. Study this sheet: Threat Actors
  3. Go deeper: Cybersecurity
  4. Go deeper: Attack Surface
  5. Validate it: work toward CompTIA Security+
  6. Find the role: browse current openings

Related sheets

More in Foundations

Share this LinkedIn Facebook X Email