Join our Newsletter — 33% off our NHI Course
Home Glossary Cyber Security Targeting Trend
Cyber Security

Targeting Trend

← Back to Glossary
By NHI Mgmt Group Updated September 18, 2026 Domain: Cyber Security

A targeting trend is a repeatable pattern showing which industries, geographies, technologies, or organisations are being selected by attackers over time. These patterns help security teams judge whether they are in scope, which controls deserve attention, and how attacker focus may shift across campaigns.

What Makes a Targeting Trend Useful?

A targeting trend is more than a retrospective chart of attacks. It is a decision signal that helps practitioners understand whether a sector, region, platform, or organisation type is becoming more attractive to adversaries, and whether their own exposure is rising with that shift.

Because the pattern is repeatable, it helps separate noise from meaningful change. A one-off incident may be important, but a trend suggests sustained attacker interest, which often warrants a different level of monitoring, prioritisation, and stakeholder attention.

Targeting trends also matter because attacker selection is rarely random. Threat actors tend to favour environments with higher payout, easier access, weaker controls, or broader downstream impact, which means the trend itself often reflects both adversary economics and defensive gaps.

How to Read a Targeting Trend

The most useful trend analysis asks four questions: who is being targeted, where they operate, what technology or service layer is being selected, and how that focus changes over time. Those dimensions help you distinguish a campaign aimed at a niche sector from a broader pattern affecting many organisations.

Trends should be read alongside campaign context. For example, a spike in interest in cloud services, managed providers, or particular geographies may reflect changes in attacker tradecraft, but it may also reflect shifts in visibility, reporting, or exposure. The point is not only to notice growth, but to interpret why the growth is occurring.

Good trend analysis also compares your own environment to the pattern. If the same industries, platforms, or operating models appear repeatedly in public reporting, that is a strong cue to reassess whether your controls, monitoring, and incident assumptions still match current attacker behaviour.

Targeting trends are commonly observed in sector-based reporting, threat intelligence, and campaign analysis. Security teams use them to identify whether attackers are concentrating on finance, healthcare, critical infrastructure, SaaS platforms, or other high-value environments, and to judge whether their own business profile makes them a more likely target.

They can also surface technology-specific pressure. When a trend shows repeated interest in remote access services, identity infrastructure, email platforms, or exposed internet-facing systems, the underlying lesson is often that attackers are following concentration points where compromise is efficient and scale is high.

One useful example is where trend reporting shows repeated targeting of identity and access paths. NHIMG’s Ultimate Guide to NHIs notes that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which is exactly the kind of pattern that tells teams where attacker attention is already landing.

Targeting trends help teams prioritise limited defensive effort. If adversaries are repeatedly selecting a certain class of victim or a certain technology layer, that usually justifies stronger monitoring, better exposure management, tighter access control, and more frequent review of assumptions that may already be stale.

They also support communication with leadership. A well-supported targeting trend gives context for why a control investment matters now, not just in theory. It links the abstract idea of “threat landscape” to a practical question: are we in the group attackers are currently choosing?

For that reason, trend analysis is most valuable when it is tied to actionability, such as control validation, detection tuning, or exposure reduction. A trend that is interesting but not operationally translated is easy to ignore; a trend that maps to your own attack surface becomes part of risk management.

Risk and Threat Considerations

Targeting trends create risk because they can reveal that a class of organisations, technologies, or geographies is under active selection by attackers, which increases the likelihood of repeated probing, credential abuse, and opportunistic compromise. The danger is not only direct exploitation, but also the false comfort of assuming your environment is too small, too niche, or too obscure to attract attention.

Failure mechanism: Adversaries concentrate effort where success rates are higher, controls are weaker, or downstream impact is larger, then reuse the same access paths and techniques across similar victims. If defenders do not recognise the trend, they may continue to tune for yesterday’s attack pattern while exposure shifts elsewhere.

Impact: Missed trend recognition can lead to delayed control changes, slower detection, and broader blast radius when the same campaign reaches your environment. In practice, that can mean more successful phishing, credential theft, service disruption, or repeated compromise across organisations that share the same profile.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0ID.RA-1 — Asset Vulnerability and ThreatsTargeting trends inform how organisations identify current threats to their environment.
ID.RA-2 — Risk AssessmentThe term helps assess whether attacker focus changes organisational risk.
DE.CM-8 — Vulnerability Monitoring and AnalysisTrend shifts often indicate where monitoring should be strengthened.
Recommendation — Use threat trend intelligence to update risk prioritisation and control focus. Reassess exposure when trend data shows sustained attacker interest in your sector. Tune monitoring to detect attack patterns that align with emerging targeting trends.
CIS Controls v88.1 — Establish and Maintain an Inventory of Enterprise AssetsTrend analysis becomes actionable when you know which assets and technologies are in the targeted set.
Recommendation — Map targeted technologies back to your asset inventory so you can narrow defensive focus.

Practitioner Guidance

What to watch for: Treat recurring mentions of the same sector, platform, or operating model as a prompt to test whether your own environment matches the attacker’s current selection criteria. The key judgement is not whether the trend is loud, but whether it overlaps with your exposure, trust relationships, and critical services.

Governance implication: Trend intelligence should feed prioritisation, not just reporting. If a pattern keeps appearing in the threat landscape, make sure it is reflected in control reviews, detection priorities, and stakeholder risk discussions rather than staying isolated in an intelligence briefing.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 18, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org