Attack volume can hide the real danger because a few highly targeted, sophisticated messages may matter far more than a large spam campaign. Risk rises when an actor combines targeting, capability, and intent. A useful reporting model should weigh sophistication, targetedness, threat type, and volume together rather than treating all activity as equal.
Why volume is a poor proxy for threat actor danger
High-volume activity can look alarming, but it often says more about scale than about risk. A low-effort spam run may produce thousands of events with limited impact, while a small number of well-targeted messages can be designed to bypass filters, deceive a specific user group, or support a broader intrusion chain. For that reason, practitioners need to separate nuisance traffic from activity that reflects intent, capability, and likely effect. The MITRE ATT&CK Enterprise Matrix is useful here because it helps analysts reason about attacker behaviour instead of counting events in isolation.
Reporting that overweights volume can also distort prioritisation. Teams may spend time suppressing noisy activity while missing the actors most likely to achieve access, persistence, or theft. A better view treats quantity as one signal among several and asks whether the activity is targeted, adaptive, and consistent with a meaningful intrusion path. In practice, many security teams discover this mismatch only after a low-volume campaign has already triggered investigation because the actor’s intent was clearer than the event count suggested.
How to read threat reporting without getting misled by counts
Threat volume becomes useful only when it is anchored to context. The first question is whether the activity is indiscriminate or selective. Bulk spam, commodity scanning, and broad password-spraying attempts can generate huge numbers but still represent a relatively generic threat profile. By contrast, a few messages crafted for a named organisation, role, or platform may indicate reconnaissance, pretexting, or a more advanced intrusion attempt. The count matters, but the shape of the activity matters more.
Analysts should also distinguish between operational noise and threat quality. Volume can rise because a campaign is scaled across many victims, because a defender is newly exposed, or because detection has improved. None of those explanations automatically increase attacker sophistication. What changes the risk picture is whether the actor adapts to controls, uses multiple stages, or shows signs of purposeful targeting. That is why external reporting such as CISA cyber threat advisories and the ENISA Threat Landscape is more valuable when it describes technique, objective, and impact rather than event totals alone.
- Compare volume with targeting: a high count aimed broadly is usually less informative than a small number of messages tailored to specific recipients.
- Weight capability separately from scale: evasion, persistence, and lateral movement potential indicate more than repetition does.
- Use threat type to interpret counts: spam, credential attacks, phishing, and intrusion attempts do not carry the same risk meaning even when the numbers look similar.
- Track whether the actor adapts after defences respond, because adjustment is often a stronger signal than initial volume.
This guidance breaks down when teams only see incomplete telemetry, because missing context can make a low-volume but high-impact campaign look harmless.
When low volume still means high risk
Tighter counting metrics often improve reporting consistency, but they can also understate danger, so organisations need to balance simple dashboards against richer interpretation. Low volume can still be serious when the actor is highly targeted, operates with good intelligence, or uses a technique that succeeds with very few attempts. A single convincing message to the right person can outweigh thousands of random lures if it is tied to access, fraud, or an intrusion path.
There is also a genuine consensus gap in how organisations score threat activity. Some teams emphasise incident frequency, while others prioritise confidence in attribution, targeting quality, or adversary sophistication. The better approach is to treat volume as a descriptive metric and then layer in evidence of intent, specificity, and outcome. That is especially important when analysts are comparing unrelated campaigns, because a noisy actor can still be less dangerous than a quiet one with better tradecraft.
For readers who want a broader strategic lens, the NIST Cybersecurity Framework 2.0 helps anchor this problem in risk management rather than event counting alone, while the Anthropic report on an AI-orchestrated cyber espionage campaign shows why a small number of highly directed actions can matter more than broad activity.
Risk and Threat Considerations
Volume can mask both operational nuisance and real adversary capability. The material risk is that defenders treat “more activity” as equivalent to “more danger,” when the more important signal is whether an actor is choosing targets, adapting to controls, and progressing toward access or impact. That creates blind spots in prioritisation, escalation, and executive reporting.
Failure mechanism: High-volume noise can consume analyst attention, while low-volume but highly targeted activity is misclassified as benign because it does not look large. Attackers exploit that by using selective delivery, layered pretexting, or small test runs that reveal which targets and controls are worth pursuing.
Impact: Organisations can miss early-stage intrusion, under-resource the most dangerous campaigns, or overestimate the value of bulk-blocking metrics. The result is weaker triage, slower response to serious threats, and a distorted picture of adversary risk.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1598 — Phishing for Information | Explains targeted social engineering as a risk signal beyond raw volume. |
| T1078 — Valid Accounts | Low-volume campaigns often precede or support account compromise paths. | |
| Recommendation — Map targeted message patterns to T1598 and investigate recipient-specific pretexting. Correlate selective activity with T1078 and review account misuse indicators. | ||
| NIST CSF 2.0 | RS.AN-3 — Analysis | Supports analysing threat events in context rather than counting them alone. |
| ID.RA-1 — Asset Vulnerabilities and Threats | Risk assessment should weigh threat characteristics, not just scale. | |
| Recommendation — Apply RS.AN-3 to interpret activity patterns with context, not raw event totals. Use ID.RA-1 to assess threat quality, targeting, and exposure together. | ||
Practitioner Guidance
What to prioritise: Score threat activity on at least four dimensions: targeting, capability, intent, and volume. If only one dimension is available, treat the result as incomplete rather than authoritative.
What to verify: Check whether the activity is changing in response to controls. Adaptive behaviour is often a stronger indicator of risk than event count, especially when the observed sample is small.
Decision rule: If a campaign is low volume but highly specific to your users, systems, or business processes, escalate it as higher risk than a larger but generic nuisance campaign.
Practitioner takeaway: Volume is a useful descriptive metric, but it becomes misleading the moment it is allowed to stand in for adversary quality, intent, or likely effect.
Related resources from NHI Mgmt Group
- Why do raw vulnerability counts give a misleading picture of risk in AI-accelerated environments?
- Why do AI-generated attack tools create a bigger problem than volume alone?
- Why do click rates give a misleading picture of phishing risk?
- Why do authentication and gateway controls fail to give a complete view of API risk?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 10, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org