Cyber-attacker types and their influence on CSaaS
| # | Attacker type | Main target (consumers or organizations) | Description | Attack motivations | Business model/skill level | Typical tactics, techniques, and procedures | Impact on supplier-consumer relationships (value sabotage) | Impact on CSaaS | Examples of impact on CSaaS |
|---|---|---|---|---|---|---|---|---|---|
| 1 | State-nexus actors | Other states and organizations (ENISA, 2024) | State or military-sponsored actors typically with significant time, funding, and resources available to gather intelligence and cause interference (ENISA, 2024) | Undermine geopolitical rivals, gather intelligence, disrupt critical infrastructure, exert political or military pressure | Advanced and expert skills (de Bruijne et al., 2017); associated with existing state or military operations | Spear-phishing password attacks, social engineering, direct compromise, data exfiltration, remote access trojans, and destructive malware (Center for Internet Security, 2024) | Introduce systemic shocks: commercial logic insufficient to guide cybersecurity service configurations | The potential damage from state-nexus actors can make cyber-insurance services unapplicable (Mascellino, 2022). | Cyber-insurance coverage reduced for acts of war (Cremer et al., 2024) |
| 2 | Private Sector Offensive actors | Organizations | “Commercial entities that engage in the cyber-surveillance industry” (ENISA, 2024, p. 20) | Conduct espionage, collect sensitive corporate data, offer surveillance or sabotage services for paying clients | Advanced and expert skills; act like a typical professional services business (ENISA, 2024) | Phishing, social engineering, business email compromise (BEC) scams, botnets, password attacks, exploit kits, malware, ransomware (Center for Internet Security, 2024) | Focus on intelligence-related information, expansion of associated cybersecurity services | Collaboration amongst defenders is critical to combat the significant expertise and skills of these actors (Ackerman, 2021) | MITRE ATT&CK Framework: a collaborative, open-source taxonomy of adversary tactics and techniques (MITRE, n.d.) |
| 3 | Hacktivists | Organizations (often governments or critical infrastructures) | Motivated by the desire for political or social change to disrupt organizations to make an ideologically driven statement (ENISA, 2024; Hald and Pedersen, 2012) | Raise awareness, protest perceived injustices, embarrass or expose organizations, promote ideological agendas | Varying levels of skills and business model sophistication (ENISA, 2024); tends to function on a smaller scale | DDoS, doxing, website defacements (Center for Internet Security, 2024) | Act as institutional entrepreneurs (Tiberius et al., 2020) to reshape norms and expectations within service ecosystems | Unregulated “white hat” hacking has led organizations to set clear boundaries and rules around disclosure (HackerOne, 2021) | Bug bounty programs (Zhang et al., 2024) |
| 4 | Script kiddies | Consumers/organizations | An attacker with limited experience relying on pre-made scripts for hacking; may have various motivations (Hald and Pedersen, 2012) | Experiment, gain peer recognition, demonstrate skills, cause disruption for personal satisfaction or entertainment | Typically, have little experience and knowledge on attack tools; not a clear business model | SQL injections and various scripts (Center for Internet Security, 2024) | Expose eminent vulnerabilities to contribute to shaping the cybersecurity service ecosystem | Script kiddies' activities have raised awareness on the ease-of-use of off-the-shelf attack tools and techniques (Temple-Raston, 2022). Gen AI has powered this further | Individual cybersecurity solutions to counter the increased availability of hacking scripts |
| 5 | Cybercrime actors/Hacker-for-hire actors | Consumers/organizations | Motivated by financial gain to develop opportunistic attacks (i.e. extortion or monetization of information gathered) (ENISA, 2024) | Steal money or assets, demand ransoms, sell stolen data, conduct attacks for hire | Varying skills (ENISA, 2024); typically exist as syndicates, contractors or small groups | Phishing, social engineering, deepfakes, business email compromise (BEC) scams, botnets, password attacks, exploit kits, malware, ransomware (Center for Internet Security, 2024) | Influence competition in cybersecurity suppliers' markets; contribute to driving innovation | The threat of a sophisticated attack led to a greater demand for cyber-threat intelligence (Bromiley, 2016) | Expansion of cyber-threat intelligence offerings by suppliers (Sun et al., 2023) |
| 6 | Malicious insiders | Organizations | Cyber-attacks perpetrated by “… authorized users who have legitimate access to sensitive/confidential material, and they may know the vulnerabilities of the deployed systems and business processes” (Homoliak et al., 2019, p. 30) | Various motivations, but mainly financial, political, personal (e.g. revenge by disgruntled employees) | Level of skills can vary depending on position and degree of access to privileged information; typically, lack of specific business model | Malicious code (e.g. malware) or intentional disclosure (Homoliak et al., 2019) | Breach trust within service systems; undermine internal value co-creation and necessitate stronger identity and access management | Expansion of cybersecurity services protect organizations from insiders' threats | Expansion of identity and access management solutions (IAM) |
| # | Attacker type | Main target (consumers or organizations) | Description | Attack motivations | Business model/skill level | Typical tactics, techniques, and procedures | Impact on supplier-consumer relationships (value sabotage) | Impact on CSaaS | Examples of impact on CSaaS |
|---|---|---|---|---|---|---|---|---|---|
| 1 | State-nexus actors | Other states and organizations ( | State or military-sponsored actors typically with significant time, funding, and resources available to gather intelligence and cause interference ( | Undermine geopolitical rivals, gather intelligence, disrupt critical infrastructure, exert political or military pressure | Advanced and expert skills ( | Spear-phishing password attacks, social engineering, direct compromise, data exfiltration, remote access trojans, and destructive malware ( | Introduce systemic shocks: commercial logic insufficient to guide cybersecurity service configurations | The potential damage from state-nexus actors can make cyber-insurance services | Cyber-insurance coverage reduced for |
| 2 | Private Sector Offensive actors | Organizations | “Commercial entities that engage in the cyber-surveillance industry” ( | Conduct espionage, collect sensitive corporate data, offer surveillance or sabotage services for paying clients | Advanced and expert skills; act like a typical professional services business ( | Phishing, social engineering, business email compromise (BEC) scams, botnets, password attacks, exploit kits, malware, ransomware ( | Focus on intelligence-related information, expansion of associated cybersecurity services | Collaboration amongst defenders is critical to combat the significant expertise and skills of these actors ( | MITRE ATT&CK Framework: a collaborative, open-source taxonomy of adversary tactics and techniques (MITRE, n.d.) |
| 3 | Hacktivists | Organizations (often governments or critical infrastructures) | Motivated by the desire for political or social change to disrupt organizations to make an ideologically driven statement ( | Raise awareness, protest perceived injustices, embarrass or expose organizations, promote ideological agendas | Varying levels of skills and business model sophistication ( | DDoS, doxing, website defacements ( | Act as institutional entrepreneurs ( | Unregulated “white hat” hacking has led organizations to set clear boundaries and rules around disclosure ( | Bug bounty programs ( |
| 4 | Script kiddies | Consumers/organizations | An attacker with limited experience relying on pre-made scripts for hacking; may have various motivations ( | Experiment, gain peer recognition, demonstrate skills, cause disruption for personal satisfaction or entertainment | Typically, have little experience and knowledge on attack tools; not a clear business model | SQL injections and various scripts ( | Expose eminent vulnerabilities to contribute to shaping the cybersecurity service ecosystem | Script kiddies' activities have raised awareness on the ease-of-use of off-the-shelf attack tools and techniques ( | Individual cybersecurity solutions to counter the increased availability of hacking scripts |
| 5 | Cybercrime actors/Hacker-for-hire actors | Consumers/organizations | Motivated by financial gain to develop opportunistic attacks (i.e. extortion or monetization of information gathered) ( | Steal money or assets, demand ransoms, sell stolen data, conduct attacks for hire | Varying skills ( | Phishing, social engineering, deepfakes, business email compromise (BEC) scams, botnets, password attacks, exploit kits, malware, ransomware ( | Influence competition in cybersecurity suppliers' markets; contribute to driving innovation | The threat of a sophisticated attack led to a greater demand for cyber-threat intelligence ( | Expansion of cyber-threat intelligence offerings by suppliers ( |
| 6 | Malicious insiders | Organizations | Cyber-attacks perpetrated by “… authorized users who have legitimate access to sensitive/confidential material, and they may know the vulnerabilities of the deployed systems and business processes” ( | Various motivations, but mainly financial, political, personal (e.g. revenge by disgruntled employees) | Level of skills can vary depending on position and degree of access to privileged information; typically, lack of specific business model | Malicious code (e.g. malware) or intentional disclosure ( | Breach trust within service systems; undermine internal value co-creation and necessitate stronger identity and access management | Expansion of cybersecurity services protect organizations from insiders' threats | Expansion of identity and access management solutions (IAM) |
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.