Join our Newsletter — 33% off our NHI Course

Attack Risk

Attack risk is the likelihood that a user or user group will be targeted by a cyberattack. It is typically inferred from threat volume, attack diversity, actor sophistication, and how strongly a group is being focused on by hostile activity. This helps teams decide where attention should go first.

What Attack Risk Means in Practice

Attack risk is not the same as a confirmed attack, a vulnerability, or a general threat landscape. It is a prioritisation lens that estimates which users or groups are more likely to be targeted, based on observable pressure from hostile activity and the attacker interest surrounding them.

That makes the term useful for focusing attention, but it also means it is inherently probabilistic. A group can have elevated attack risk without being compromised, and a lower-risk group can still be hit if the attacker’s objective changes or the campaign widens.

What Drives Attack Risk

The most useful inputs are the ones that reveal intent and concentration: threat volume, the variety of attack types being used, the sophistication of the actors involved, and whether the same population is repeatedly being selected as a target. Those signals help distinguish routine background noise from a group that is being actively focused on.

Attack risk rises when targeting is broad and persistent, but it can also spike when a specific population becomes valuable for a short period, such as during a credential theft campaign, a phishing surge, or a sector-specific intrusion wave. The term therefore works best as a relative measure, not a fixed label.

How Attack Risk Supports Security Prioritisation

Security teams use attack risk to decide where to put effort first when resources are limited. A group with higher attack risk may justify stronger monitoring, faster alert triage, more aggressive hardening, or more frequent user communication because it is more likely to be probed, socially engineered, or targeted with credentials-focused attacks.

It also helps avoid a common mistake: treating every user population as equally exposed. Risk-based prioritisation is more defensible when it is tied to real attacker focus, especially where MITRE ATT&CK Enterprise techniques such as credential access and lateral movement are part of the threat pattern, or when known campaigns appear in CISA cyber threat advisories.

Attack Risk, Exposure, and the Need for Context

Attack risk should be read alongside the environment around it. A group may be heavily targeted because of its role, data access, public profile, or the value of the systems it can reach. The same risk signal can therefore mean very different things depending on whether the target is a customer population, privileged staff, partners, or users exposed to a current campaign.

Context also matters because attack risk changes over time. It can rise during active campaigns and fall when attacker attention moves elsewhere, so the term is best used as a living prioritisation measure rather than a permanent property of a group.

Risk and Threat Considerations

Attack risk matters because it reflects where hostile attention is already concentrated, which can turn a normal user population into an efficient target set for phishing, credential theft, account takeover, or follow-on intrusion. The main hazard is not certainty, but skewed exposure: teams may underprotect groups that are quietly attracting repeated attack activity.

Failure mechanism: Adversaries increase pressure through repeated targeting, varied attack types, and campaign-specific focus, which raises the chance that one successful attempt will land on a user or group with reachable privileges or sensitive access.

Impact: Higher attack risk can drive disproportionate loss of accounts, data, and operational continuity if the targeted population is not prioritised for monitoring and protective controls.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1078 — Valid Accounts Attack risk often tracks campaigns that seek account access for later abuse.
T1110 — Brute Force Repeated targeting and attack volume can indicate credential attack pressure.
Recommendation — Prioritise monitoring for valid-account abuse when a group shows repeated targeting. Increase detection for credential attacks when a population shows elevated targeting.
NIST CSF 2.0 ID.RA-01 — Asset Vulnerabilities Are Identified and Documented Attack risk is a prioritisation input for identifying which groups face greater exposure.
PR.AA-05 — Least Privilege Is Applied High attack risk is more damaging when targeted users have broader access.
Recommendation — Use risk intake to rank user groups that need earlier protection and review. Apply least-privilege access to reduce the impact of targeted user compromise.
CIS Controls v8 CIS-5 — Account Management User attack risk directly informs which accounts need stricter control and monitoring.
Recommendation — Tighten account management for populations showing persistent targeting.

Practitioner Guidance

Why practitioners should care: Attack risk is most useful when it changes what gets attention first. If you do not translate the signal into prioritisation, the metric becomes descriptive instead of operational.

What to watch for: Look for persistent targeting, unusual campaign diversity, and a mismatch between a group’s business importance and the protective effort it receives. Those are the conditions that usually justify reordering response and monitoring priorities.