← Blog|Risk Assessment

Attacker Profiles Instead of Parameter Guesswork: Risk Rating That Scales Across a Team

Why fixed attacker profiles make risk ratings more consistent than repeatedly estimating individual parameters — and how to define them properly.

September 16, 20265 min readSebastian Schmidt

A proper attack feasibility rating requires estimating five factors for every threat: time, expertise, knowledge of the target, window of opportunity, equipment. With fifteen threats, that is seventy-five individual decisions — and in a workshop with six participants, seventy-five opportunities to disagree.

Anyone who has moderated such sessions knows the result: the first threat is discussed for forty minutes, the last five are waved through. The rating is then not wrong, but it is inconsistent — and in an audit, inconsistency is worse than being strict or lenient.

The idea: define the attacker once, not the parameters fifteen times

Instead of estimating anew for each threat, a small number of attacker profiles is defined up front. Each profile specifies what this attacker brings along — knowledge, access, equipment, time, motivation.

This fundamentally changes the rating question. "How many points does the expertise factor get?" becomes "can this attacker pull it off?". The first question is a matter of judgment, the second a matter of fact — and a team answers factual questions consistently.

Profiles that have proven themselves for field devices

Four to five profiles are almost always enough. More leads to spurious precision, fewer blurs relevant differences:

ProfileAccessResourcesTypical goal
Opportunistic attackerwhatever is reachable over the networkstandard tools, public exploitsno specific target — hits whoever stands out
Insiderlegitimate physical and logical accesson-board tools, local knowledgemanipulation, bypassing controls
Competitora purchasable device in their own labskilled staff, measurement equipment, plenty of timeintellectual property, cloning
Organized crimedeliberately acquired accessfunded, division of labor, scalingextortion, mass impact
Nation-state actorvirtually unlimitedpractically unlimitedstrategic objectives

The last entry is the most important one — and it is usually handled wrongly. A field device cannot be hardened economically against a nation-state actor with unlimited resources. Deliberately placing this case outside the scope of consideration is a legitimate and documentable decision. Silently including it, on the other hand, makes every measure look insufficient, and in the end nothing gets prioritized at all.

How to define a profile properly

A usable profile answers five questions — the same ones the attack feasibility methodology asks, just once instead of per threat:

  • What does the attacker know? Only publicly available information, or also internal material such as schematics, source code, service documentation?
  • Where can the attacker get access? Remotely over the network, in the same segment, physically at the installed device, or at a device in their own lab?
  • What does the attacker work with? A standard laptop, measurement equipment and debuggers, or specialized equipment up to chip-level analysis?
  • How much time does the attacker have? A window of opportunity of minutes, or months without time pressure?
  • What drives the attacker? The methodology explicitly treats motivation separately, because it does not belong in the same bucket as technical capability: it determines whether an elaborate attack appears worthwhile at all.

These definitions are created once, apply to the product or product family and are reviewed when necessary — not renegotiated in every workshop.

What this achieves in practice

Speed without loss of quality. Rating a threat comes down to a few yes/no decisions along the profiles. Fifteen threats can be done in a morning — rated consistently.

Debatability. When someone challenges a result, the discussion shifts to the profile definition. That is the right level: the decision is made there once, instead of having the same argument fifteen times.

An explicit scope. Writing down your profiles implicitly writes down what you are not protecting against. That sounds uncomfortable, but it is exactly the statement an auditor wants to see — and in the event of damage, it makes the difference between a decision that was made and a point that was overlooked.

Where the method breaks down

Two mistakes occur regularly.

Profiles turn into stereotypes. "The insider" is a modeling assumption, not a person. When the discussion starts negotiating character traits instead of capabilities, the model has gone off the rails.

The profile replaces the analysis. The profiles set the bar — they do not replace the question of which attack paths actually exist on this specific device. Beneath the profiles, the five factors remain the foundation; they just no longer have to be renegotiated every time.

Used correctly, profiling is not a substitute for diligence, but the means by which diligence can be sustained across fifteen threats.

Sources

This article was originally published in German on the Alsensio Cybersecurity Hub.

Share:LinkedInX/Twitter
Attacker ProfilesRisk AssessmentAttack PotentialThreat Modeling
Sebastian Schmidt

Need expert guidance?

Sebastian Schmidt — Alsensio

Our team provides hands-on consulting for IEC 62443 and IEC 61508 compliance.

Get in touch