Reporting on cyber attacks almost always turns on the tool. Which malware, which vulnerability, which system fell. That is rarely the illuminating question. Tools are replaced in weeks, while motives and working methods hold for years. An organisation that builds its defence against last month's malware is defending against something already superseded, while the one that understands who is coming and why can anticipate roughly how.
The chapter opens with why the actor perspective is more useful than the tool perspective, then divides attackers into four main categories by driver and resources. The difference between them is practical rather than academic. It determines how persistent the attacker is, what triggers their interest and what makes them give up. From there the chapter moves to how the criminal ecosystems are organised, how access, malware and extortion have become separate services bought from one another in a division of labour resembling any other industry. The dark web is treated as the marketplace it is, and the tool market with its grey zone of dual use gets a section of its own. Then comes the attack chain, from initial foothold through reconnaissance and privilege escalation to extortion, and three Swedish cases showing the same pattern in different guises. The closing sections turn the perspective around and ask what your own organisation looks like from the outside, which is the starting point for the work covered in chapter 16 on detection and response.
Why this matters now has less to do with the threat being new and more with the threshold having dropped. Attack tools no longer demand deep technical skill, and anyone lacking the competence can buy it as a service, with support. At the same time, Swedish organisations have become interesting for reasons outside themselves, through who they supply and what function they serve in something larger. A small company with one critical customer is a more attractive target than its size suggests, and that is an assessment the attacker makes before the organisation has made it.
This page shows what the chapter covers and why the picture of the actors governs the defence. The four categories, the Swedish cases and the attack chain in detail are in chapter 2 of the book.
You do not defend against tools. You defend against people with motives.
Key insights
- Motive determines an attacker's persistence. A criminal group that meets resistance changes target, a state-sponsored actor with a mission does not.
- Ransomware is an industry with a division of labour and specialised roles, not a lone attacker doing everything.
- Access to Swedish organisations is bought and sold. The market exists whether or not anyone in the organisation knows about it.
- The attack chain is predictable, and for exactly that reason it can be broken in several places before the damage is done.
- Your organisation looks different from the outside than from within, and the outside view is the one the attacker works against.
Tools that belong to this chapter
The templates and interactive tools are in the Toolbox, free of charge.
Glossary and resource catalogue
Look up terms such as dark web, initial access broker and ransomware as a service.
Read on
Next step
Where does your organisation stand?
The self-assessment gives you a maturity profile against the ten requirement areas of the Cybersecurity Act in a few minutes, right on screen.