Who attacks, and why it decides what you defend

~30 min

(Quick review first: security is not a wall, nothing is absolutely secure, and the job is to make bad things hard and to notice quickly when they happen anyway.)

Why motive matters

It is tempting to treat "attackers" as one undifferentiated group of hooded figures. But who is coming for you decides almost everything about how you defend, because different attackers want different things, have wildly different budgets, and give up at different points.

A useful way to think about it: defence is about making yourself more expensive than you are worth to a particular attacker. So you need to know which attacker.

The categories that actually matter

Opportunistic criminals. By far the most common, and the ones you will spend your career on. They are not targeting you. They scan the whole internet for a known weakness, and if your server has it, you are in the list. Their business is volume: ransomware, stolen card data, hijacked email accounts used for fraud. They give up the moment you are harder than the next target, which is why unglamorous work — patching, strong passwords, backups — stops most of them.

Targeted criminals. They picked you specifically because you have money or data worth the effort. Business Email Compromise is the big one in Nigeria: an attacker studies a company for weeks, learns who approves payments and how they write, then sends a convincing instruction to move funds. No malware, no technical exploit — just patience and a well-written email. These attackers do not give up when you get harder; they change approach.

Insiders. An employee or contractor who already has legitimate access. Sometimes malicious — a departing staff member taking the customer list. Far more often careless: someone who reuses a password, or emails a spreadsheet to their personal address to work on at home. Insiders are hard because every control you build assumes the person is supposed to be there.

Hacktivists. Attacking to make a political or social point. Usually defacement or knocking a site offline — noisy, visible, aimed at embarrassment rather than profit.

State actors. Governments, with budgets and patience you cannot match. If a serious nation-state genuinely wants into your system, they will get in. This is not defeatism; it is why organisations at that risk level focus on detection and limiting damage rather than pretending they can build a perfect wall.

What this means in practice

Here is the part beginners get wrong. Most people imagine defending against the state actor and neglect the opportunistic criminal — the security equivalent of installing a bank vault door and leaving the window open.

The overwhelming majority of real incidents come from unremarkable causes: a password that was reused, a system that was never patched, an email someone believed, a backup nobody tested.

Not clever zero-day exploits. Not movie hacking. Boring, preventable, well-understood failures that were known about for months.

This is genuinely good news, because it means ordinary competent work — the kind you are about to learn — prevents most of what actually happens.

The attack chain

Attacks are not a single event. They are a sequence, and every step is a chance to notice:

  1. Reconnaissance — learning about the target: staff names, email formats, what software is exposed.
  2. Initial access — getting a first foothold: a phished credential, an unpatched service, a malicious attachment.
  3. Establishing persistence — making sure they keep access even if you reboot or change the password.
  4. Escalating privilege — moving from an ordinary user account to an administrator.
  5. Moving laterally — spreading from the first machine to more valuable ones.
  6. Acting on the objective — stealing data, encrypting it for ransom, committing fraud.

The lesson buried in that list: there is usually a long gap between the first foothold and the damage. Attackers often sit in networks for weeks. That gap is where defenders win — but only if something is watching. That "something" is what you build from Week 8.

Try it now

Pick an organisation you know — your employer, your school, a business you use. Write two or three sentences on each:

  1. Which attacker would realistically come for them, and what would that attacker want?
  2. What would the attacker have to get through first?
  3. If the attacker succeeded today, how would anyone find out — and how long might that take?

Keep this. You will expand it into this week's project.

Sign in to track your progress.