Vol. 01 · Story 13 · Domain 2

THE ROGUESGALLERY.

Threat Actors

Cipher Lane police station pinboard · 2 min read

Five faces on a pinboard. Government spy, gang, protester, angry ex-employee, teenager with a YouTube tutorial. Different motivations. Different capabilities. All coming for Cipher Lane.

Reading Progress
00 / 22
Story 13 · Domain 2 · Threat Actors

The Rogues Gallery.

Cipher Lane police station has a pinboard of known troublemakers. Each one is different. Understanding who they are changes everything about how you defend.

The police inspector pins five photos on the board. "Know your enemies," he says. "Not just who they are — what they want, how patient they are, and how much they're willing to spend."

The government spy — dressed in an expensive suit, unlimited budget, team of fifty behind him. He's not after Gary's money. He wants Gary's secret recipes to give to his own country's coffee industry. He's patient — he'll spend months getting in. That's a Nation-State / APT. Highest sophistication, government-funded, motivated by espionage. Most dangerous threat actor.

The gang — three blokes in a van. They want the cash register. They'll smash, grab, and vanish. If they can't get cash, they'll padlock Gary's shop and demand ransom to give the key back. That's Organised Crime. High skill, financially motivated, ransomware and fraud.

The protester — marches up to Gary's shop with a megaphone because Gary uses non-recyclable cups. She spray-paints the window and posts it online. She doesn't want money — she wants attention and change. That's a Hacktivist. Medium skill, ideologically motivated, public disruption.

The angry ex-employee — Gary sacked him last week. He still knows the alarm code, the wifi password, and where the spare key is. He doesn't need to break in — he already has access. That's an Insider Threat. Varying skill, motivated by revenge or money, already inside the perimeter. The hardest to detect.

The teenager — found a YouTube video called "how to pick locks" and is trying it on every door on Cipher Lane. Doesn't really know what he's doing. Using someone else's tools. That's a Script Kiddie. Low sophistication, uses public tools, curiosity-driven.

The police describe each troublemaker with four attributes.

Internal or external? — the ex-employee is internal. Everyone else is external. Sophistication? — nation-state is highest, script kiddie is lowest. Resources? — government spy has unlimited budget. The teenager has none. Intent? — the teenager is mostly accidental. The gang is fully intentional. The insider could be either.

The insider threat is the hardest to defend against — not because they're the most sophisticated, but because they already have access. The perimeter that stops everyone else means nothing to them. — Story 13 · Threat Actors
// ON THE EXAM

Nation-state actors have the highest sophistication and resources. Organised crime is primarily financially motivated — ransomware is their tool. Insider threats are uniquely dangerous because they already have access. Script kiddies are low-skill and use existing tools. Match the motivation to the actor.

Check Yourself · Question 13

A threat actor encrypts Gary's accounts and demands Bitcoin. Motivated by profit, using high technical skill. Which actor type is most likely responsible?

Terminology · Story 13

The Pinboard.

// Term · 01 / 04
Nation-State / APT
Tap to reveal
// Definition
Government-funded, highest sophistication, unlimited resources, patient (months/years). Motivated by espionage, strategic intelligence, disruption.
Domain 02
// Term · 02 / 04
Insider Threat
Tap to reveal
// Definition
Already has legitimate access. Motivated by revenge, financial gain, or ideology. Varying skill. The perimeter doesn't stop them — they're already inside.
Domain 02
// Term · 03 / 04
Hacktivist
Tap to reveal
// Definition
Ideologically motivated — political, environmental, social causes. Medium skill. Wants visibility and disruption rather than financial gain. Website defacement, DDoS.
Domain 02
// Term · 04 / 04
Script Kiddie
Tap to reveal
// Definition
Low sophistication, uses publicly available tools without deep understanding. Curiosity-driven rather than strategic. The teenager with a YouTube tutorial.
Domain 02