Table 2

Cyber-attacker types and their influence on CSaaS

#Attacker typeMain target (consumers or organizations)DescriptionAttack motivationsBusiness model/skill levelTypical tactics, techniques, and proceduresImpact on supplier-consumer relationships (value sabotage)Impact on CSaaSExamples of impact on CSaaS
1State-nexus actorsOther states and organizations (ENISA, 2024)State or military-sponsored actors typically with significant time, funding, and resources available to gather intelligence and cause interference (ENISA, 2024)Undermine geopolitical rivals, gather intelligence, disrupt critical infrastructure, exert political or military pressureAdvanced and expert skills (de Bruijne et al., 2017); associated with existing state or military operationsSpear-phishing password attacks, social engineering, direct compromise, data exfiltration, remote access trojans, and destructive malware (Center for Internet Security, 2024)Introduce systemic shocks: commercial logic insufficient to guide cybersecurity service configurationsThe potential damage from state-nexus actors can make cyber-insurance services unapplicable (Mascellino, 2022).Cyber-insurance coverage reduced for acts of war (Cremer et al., 2024)
2Private Sector Offensive actorsOrganizations“Commercial entities that engage in the cyber-surveillance industry” (ENISA, 2024, p. 20)Conduct espionage, collect sensitive corporate data, offer surveillance or sabotage services for paying clientsAdvanced and expert skills; act like a typical professional services business (ENISA, 2024)Phishing, social engineering, business email compromise (BEC) scams, botnets, password attacks, exploit kits, malware, ransomware (Center for Internet Security, 2024)Focus on intelligence-related information, expansion of associated cybersecurity servicesCollaboration amongst defenders is critical to combat the significant expertise and skills of these actors (Ackerman, 2021)MITRE ATT&CK Framework: a collaborative, open-source taxonomy of adversary tactics and techniques (MITRE, n.d.)
3HacktivistsOrganizations (often governments or critical infrastructures)Motivated by the desire for political or social change to disrupt organizations to make an ideologically driven statement (ENISA, 2024; Hald and Pedersen, 2012)Raise awareness, protest perceived injustices, embarrass or expose organizations, promote ideological agendasVarying levels of skills and business model sophistication (ENISA, 2024); tends to function on a smaller scaleDDoS, doxing, website defacements (Center for Internet Security, 2024)Act as institutional entrepreneurs (Tiberius et al., 2020) to reshape norms and expectations within service ecosystemsUnregulated “white hat” hacking has led organizations to set clear boundaries and rules around disclosure (HackerOne, 2021)Bug bounty programs (Zhang et al., 2024)
4Script kiddiesConsumers/organizationsAn attacker with limited experience relying on pre-made scripts for hacking; may have various motivations (Hald and Pedersen, 2012)Experiment, gain peer recognition, demonstrate skills, cause disruption for personal satisfaction or entertainmentTypically, have little experience and knowledge on attack tools; not a clear business modelSQL injections and various scripts (Center for Internet Security, 2024)Expose eminent vulnerabilities to contribute to shaping the cybersecurity service ecosystemScript kiddies' activities have raised awareness on the ease-of-use of off-the-shelf attack tools and techniques (Temple-Raston, 2022). Gen AI has powered this furtherIndividual cybersecurity solutions to counter the increased availability of hacking scripts
5Cybercrime actors/Hacker-for-hire actorsConsumers/organizationsMotivated by financial gain to develop opportunistic attacks (i.e. extortion or monetization of information gathered) (ENISA, 2024)Steal money or assets, demand ransoms, sell stolen data, conduct attacks for hireVarying skills (ENISA, 2024); typically exist as syndicates, contractors or small groupsPhishing, social engineering, deepfakes, business email compromise (BEC) scams, botnets, password attacks, exploit kits, malware, ransomware (Center for Internet Security, 2024)Influence competition in cybersecurity suppliers' markets; contribute to driving innovationThe threat of a sophisticated attack led to a greater demand for cyber-threat intelligence (Bromiley, 2016)Expansion of cyber-threat intelligence offerings by suppliers (Sun et al., 2023)
6Malicious insidersOrganizationsCyber-attacks perpetrated by “… authorized users who have legitimate access to sensitive/confidential material, and they may know the vulnerabilities of the deployed systems and business processes” (Homoliak et al., 2019, p. 30)Various motivations, but mainly financial, political, personal (e.g. revenge by disgruntled employees)Level of skills can vary depending on position and degree of access to privileged information; typically, lack of specific business modelMalicious code (e.g. malware) or intentional disclosure (Homoliak et al., 2019)Breach trust within service systems; undermine internal value co-creation and necessitate stronger identity and access managementExpansion of cybersecurity services protect organizations from insiders' threatsExpansion of identity and access management solutions (IAM)
Source(s): Authors' own work

or Create an Account

Close Modal
Close Modal