Knowledge base

Threat profiles: why the distinction matters

A threat profile records in advance which actors realistically have an interest in the information discussed or processed in a room, what capabilities they have, and what access they can obtain on site or remotely. That determines which attack vectors are relevant, what is examined and which examination methods fit. A state actor generally has different means, budgets and time horizons than a competitor or a malicious employee. Without that consideration the examination scope quickly becomes arbitrary rather than threat-driven.

A threat profile is an explicit assumption

A threat profile, also called a threat picture, is an explicit set of assumptions about a possible adversary: who may have an interest in the information discussed or processed in a room (actors), what that party wants to achieve (intent), which means it can deploy (capabilities) and what access it can obtain on site or remotely (opportunity).

Without such a profile, an examination still proceeds on assumptions — they simply stay implicit. Those assumptions always steer the work: they determine which attack vectors are relevant, which equipment and methods are deployed, how long measurements run and where the search does and does not go.

That is why we record the threat profile together with you in advance. The starting points are then open to discussion, traceable and testable both internally and externally.

It starts with what you have to protect

Before we look at possible adversaries, we look at you and at the interests you have to protect. What information passes through the room, how often, and what might it be worth to someone with an interest in it? An acquisition file, the walk-away point in a negotiation, tender figures, a reorganisation plan that is still confidential, research results representing years of investment, or classified information falling under the ABRO. That information represents different kinds of value and has widely differing shelf lives: some is worthless after days, other material stays sensitive for years.

Empty boardroom with a meeting table and a screen on the wall
The profile begins with this room: what information passes through here, how often, and what it is worth to someone with an interest in it.

That value partly determines how much time, means and risk an adversary is reasonably willing to invest. Information that is price-sensitive for a single quarter calls for a different consideration than knowledge of a production process that retains strategic value for ten years. The use of the room also counts: a boardroom hosting weekly confidential meetings is a different target from a room used once for one specific transaction.

Who is on the other side determines what we look for

The difference between adversaries lies not in their intent but above all in their capabilities. The examples below are purely illustrative; the relevant threat profile can differ considerably from one organisation and situation to the next.

The malicious insider or opportunist often already has access and does not have to obtain it first. This actor type generally uses readily available means and aims at a concrete, often short-lived objective. Thorough physical inspection and examination of the RF spectrum are important parts of the work.

A competitor or a hired party can operate more professionally and make use of moments of legitimate access, for instance during maintenance, refurbishment or installation work. Technical devices can therefore be integrated more covertly into furniture, infrastructure or equipment that belongs in the room already. The examination then shifts markedly towards fixed infrastructure, cabling and devices that are not actively transmitting during the work.

An organised criminal group usually works towards a concrete, time-bound interest such as a transaction, a shipment, inside information or a negotiation. The distinction lies not necessarily in more advanced technology but in the operational opportunity to arrange, buy or coerce access through people who legitimately enter the building. A placement can therefore look like regular work and only needs to function for as long as the information holds value. The Barclays case shows how physical access under a legitimate pretext can be exploited.

A state actor may have more time, specialist means and the ability to obtain access earlier in the chain. That also means taking into account passive or hard-to-detect devices, long-term placement that went unnoticed, and attack vectors that can fall outside the reach of a standard examination. With this profile in particular it matters that the examination scope explicitly matches the assumed capabilities of the adversary.

Not every sensitive room is an office. Confidential conversations also take place at home, in transit and in hotels — in short, in settings where the security measures of your own building do not apply and access is often less controlled. The first example on our case page took place in a private office. For the threat profile it is therefore also relevant where sensitive information is discussed or processed outside the primary secured environment.

Different devices call for different methods

The threat profile makes a technical difference too. A device that transmits only intermittently calls for a different examination strategy than a recorder that stores locally and produces no radio signal. Passive devices behave differently from active transmitters.

A professional examination therefore does not simply consist of one measurement. Methodology, duration and scope follow from the attack vectors considered relevant for the threat profile that has been established.

What the distinction gives you

The threat profile is not a formality up front; it determines how the examination is set up. Concretely, it determines:

  • which attack vectors are relevant and which examination methods fit them;
  • how long and at which moments measurements are taken;
  • which rooms, installations and adjacent zones fall within the scope;
  • which detection criteria are recorded in advance;
  • and, just as importantly, what stays outside the scope.

That avoids two costly wrong choices. The first is an unnecessarily heavy set-up: examining as though you face a state actor while the realistic threat is a competitor. That costs time and money without necessarily yielding more certainty. The second is more serious: underestimating an adversary’s capabilities, producing a seemingly reassuring conclusion based on an examination that was not set up for the relevant attack vectors.

The threat profile also makes the conclusion traceable and defensible. A client, an auditor or a competent authority can see which threat the reasoning started from, what was examined on that basis and where the limits lay. The conclusion therefore does not have to be taken on trust; it can be weighed on its merits.

Your own constraints count too

The threat profile is one half of the preparation. The other half consists of your wishes and practical constraints. Does the examination have to stay unnoticed by staff, or can it be announced? Can the room be taken out of use temporarily, and may furniture and installations be opened? Is there a concrete trigger, or is this periodic work? And what should happen if something is in fact found?

Those choices have direct consequences for the work. An examination that has to remain fully discreet has different possibilities and limitations than one where a room can be cleared for a day. In ABRO engagements, alignment with the NBIV may also be relevant: our examination supports and strengthens the preparation towards a formal accreditation, but does not replace it.

From threat profile to examination scope

The result of the preparation is not a standard package but a bounded assignment that matches the interests you have to protect, who might target them and what that party is capable of. The starting points are recorded in the report, so that it remains traceable afterwards why this scope and methodology were chosen.

If the threat picture changes, the scope can change with it. A new client, an acquisition, a dispute, an incident or a change in room use can be reason to reassess the assumptions.

The aim is therefore not to assume the heaviest conceivable scenario as a matter of course, but to record which scenario you want the examination carried out against.

Frequently asked questions

What if I do not know who might have an interest?

Then we start with you, not with the adversary. What information passes through this room, how often, and what is it worth to someone with an interest in it? Who comes into view usually follows from the interests you have to protect.

Can I not simply assume the heaviest scenario?

You can, but it costs time and money without changing the outcome when the realistic adversary is a competitor or an insider. The reverse is more serious still: an examination that underestimates the adversary’s capabilities produces a report that is worth nothing.

When should a threat profile be revised?

When the context shifts. An acquisition, a new client, an ongoing dispute or an incident can change the profile, and with it the question of which examination is appropriate. Beyond that, it is sensible to reconsider it periodically.

Does GreyOps draw up the profile, or do we?

We do it together. You know what is discussed in the room and what that is worth; we know which means an adversary can deploy for it and what of that is measurable. We work through a number of standard questions in the first conversation. The profile is recorded and appears in the report, so that it remains visible afterwards what the scope was based on.

Read more about our countersurveillance sweep.

Written by · Published , revised