Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Tactic
Cyber Security

Tactic

← Back to Glossary
By NHI Mgmt Group Updated August 24, 2026 Domain: Cyber Security

A tactic is the attacker’s immediate objective within the MITRE ATT&CK framework, such as gaining access, running code, or stealing credentials. Tactics sit above techniques in the model and help security teams understand what outcome the adversary is pursuing before considering the specific method used.

Expanded Definition

In security writing, a tactic describes the adversary’s immediate objective, not the specific method used to achieve it. In the MITRE ATT&CK model, tactics organise techniques into outcome-based stages such as initial access, execution, persistence, privilege escalation, credential access, discovery, lateral movement, exfiltration, and impact. That distinction matters because two incidents can use very different techniques while still serving the same tactical goal.

For defenders, a tactic is useful as a lens for grouping detections, incident notes, and threat intelligence into a coherent storyline. It helps analysts ask what the attacker is trying to accomplish right now, which is especially valuable when tooling surfaces isolated alerts without context. The concept is also used in adjacent frameworks for adversarial AI, including the MITRE ATLAS adversarial AI threat matrix, where tactics help describe the attacker’s aim against AI systems rather than just the exploit method.

Definitions are broadly consistent in the ATT&CK ecosystem, but the term is sometimes misused to mean any attacker action or any detection category. The most common misapplication is treating a tactic as a technique, which occurs when teams label a concrete exploit, command, or payload as if it were the broader objective.

Examples and Use Cases

Implementing tactic-based analysis rigorously often introduces abstraction overhead, requiring organisations to balance cleaner threat modelling against the time needed to normalise alerts into outcome-based categories.

  • When an email campaign leads to malicious login attempts, the tactical goal is often initial access, even though the technique may be phishing, credential stuffing, or token theft.
  • When endpoint activity shows script execution, scheduled task creation, and registry modification, those techniques may support the broader tactic of persistence.
  • During an intrusion investigation, multiple alerts can be grouped under credential access if they reflect password dumping, keylogging, or token harvesting.
  • In an AI security context, the MITRE ATLAS adversarial AI threat matrix uses tactic-like groupings to help defenders reason about an attacker’s objective against models, training data, or inference pipelines.
  • For control mapping, a team may tie recurring tactics such as lateral movement or exfiltration to safeguards described in NIST SP 800-53 Rev 5 Security and Privacy Controls, then tune detections and access controls around those outcomes.

Why It Matters for Security Teams

Tactics matter because they convert noisy technical evidence into a defender-friendly narrative about adversary intent. Without that layer, teams may overreact to isolated events, miss the chain of activity, or fail to see that multiple incidents are actually the same campaign progressing toward a single objective. Tactic-level thinking also supports better prioritisation in detection engineering, threat hunting, and incident response because it shows which outcomes are already being attempted in the environment.

For governance and control design, tactic analysis helps teams decide where to place preventive and detective safeguards. Controls in NIST SP 800-53 Rev 5 Security and Privacy Controls are often more effective when mapped to likely adversary objectives rather than only to isolated indicators. That is particularly true in identity-heavy attacks, where credential access, privilege escalation, and lateral movement often chain together across human and non-human identities, API keys, and service accounts.

Organisations typically encounter the operational cost of misunderstood tactics only after a breach investigation reveals that apparently separate alerts were all part of one attacker objective, at which point tactic alignment becomes operationally unavoidable to reconstruct the intrusion.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Agentic AI Top 10 and MITRE ATLAS address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST AI RMF set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CMTactic-based analysis supports continuous monitoring by grouping alerts around attacker objectives.
NIST SP 800-53 Rev 5AU-6Audit review helps correlate events into attacker tactics during investigation and response.
OWASP Agentic AI Top 10Agentic AI threat work borrows tactic-style adversary objectives for model and tool abuse.
MITRE ATLASATLAS organises adversarial AI threats by attacker objectives and related techniques.
NIST AI RMFAI RMF governance helps contextualise risk by the adversary objective affecting the system.

Use tactic mapping to prioritise monitoring signals into outcome-based detection stories.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org