SafeHarbour Supply Chain Technologies
Cyber Threat Library

Cyber Threat Library

Every major type of cyber attack, explained in plain language for people who run operations rather than networks. What each one is, how it reaches you, what it looks like when it is happening, and which defences actually stop it — with a coverage check to show where your gaps are.

Search & Filter
Prevalence Against Impact
Every attack placed by how often organisations of this profile actually encounter it, against how much damage a successful one does. Ratings are general guidance, not a measurement of your business — a threat that is rare across the economy can be near-certain for you if you hold something particular. Click any attack to open its entry in the library.
Severe — treat as a planning assumption
High
Moderate
Lower
Highest Rated Threats
Threats by Category
Count is not the same as danger. Social engineering carries fewer distinct entries than malware, yet it is the opening move in the large majority of successful intrusions — because it targets the one component you cannot patch.
Which Controls Do You Have?
Select the controls genuinely in place across your business — not the ones on a roadmap. The number beside each is how many attacks in the library it helps mitigate. Nothing is stored or sent anywhere; this runs entirely in your browser.
Coverage
Strongly mitigated
Partially mitigated
No mitigation selected
Best Next Controls
Ranked by how much risk each unselected control would remove given what you already have — so the recommendation changes as your selection does. Weighted by each attack's risk rating, which is why one control can outrank another that technically touches more attacks.
Where You Are Exposed
Attack Category Risk Controls Held Coverage Status Missing Controls
Reach of Each Control
A handful of controls do most of the work. That is the practical argument for depth over breadth: three well-run fundamentals beat a dozen half-configured tools, and the attacks that get through tend to be the ones where a basic control was assumed rather than verified.
Choose an Incident Type
Generic first-response guidance for the kinds of incident in this library. It is written for the operational side of the business — the people who have to keep goods moving while a technical team deals with the systems. It is a starting point, not a substitute for a tested incident response plan or for professional advice at the time.
Applies To
Attacks in the library that would be handled under this playbook. Click any to open its entry.
How to Read This Library
RISKRisk Rating
Risk = prevalence × impact
A 1–25 rating combining how commonly an attack is encountered with how much damage it does when it succeeds. Deliberately coarse. Its job is to order a list, not to price a decision — for that, take the top few into a business impact analysis.
Scoring
PREVPrevalence
1 = rare · 5 = routine
How often a mid-sized organisation actually encounters the attack, not how often it appears in the news. Some of the most damaging attacks are rare; some of the most common are trivial when the basics are in place.
Rating
IMPImpact
1 = nuisance · 5 = existential
Typical damage from a successful attack of this type — operational stoppage, financial loss, data exposure, regulatory consequence. Assumes it is not caught early, which is the case worth planning for.
Rating
DETDetection Difficulty
1 = obvious · 5 = may run for months
How hard the attack is to notice while it is happening. High detection difficulty is why monitoring matters: an attack you cannot see is one where the damage is decided by the attacker's patience rather than your response.
Rating
COVCoverage Status
strong ≥ 70% of listed controls held
Attacks are marked strongly mitigated at 70% or more of their listed controls, partial with at least one, and uncovered with none. Risk-weighted coverage is calculated separately and continuously — the share of listed controls held, averaged across attacks and weighted by risk. No control set makes an attack impossible; this measures whether you have made it expensive.
Coverage
NEXTBest Next Control
(Σ risk × coverage gained) ÷ effort
For each control you lack, the tool sums the risk-weighted coverage it would add across every attack, then divides by an effort weight — foundational counts as one, intermediate two, advanced three. Without that division the ranking simply favours whichever control is named against the most attacks, which puts broad, demanding programmes ahead of cheap decisive ones. It is a greedy calculation: good for the next step, not for planning a whole programme at once.
Method
The Uncomfortable Patterns

Almost nothing here is sophisticated. The overwhelming majority of successful attacks use a stolen password, an unpatched system, or a convincing email. Advanced techniques exist and make good reading, but they are not what is going to happen to you. Fix the ordinary things first.

The finance function is the target more often than the data centre. Payment redirection through compromised or spoofed email costs businesses more each year than ransomware does, and it needs no malware at all. A callback procedure on bank detail changes is the single cheapest control in this entire library.

Your suppliers are part of your attack surface. A meaningful share of breaches arrive through a third party — an IT provider, a logistics partner, a maintenance contractor with remote access. Your security is capped by theirs, which is a contracting problem as much as a technical one.

Attackers wait for the worst moment. Ransomware is disproportionately deployed on Friday evenings, public holidays and during known peak seasons, because that is when response is slowest and pressure to pay is highest. Plan coverage accordingly.

Backups fail when they matter. The common failure is not the absence of backups, it is backups that were reachable from the compromised network, or that had never been restored end-to-end. If it has not been tested by actually rebuilding something, treat it as unproven.

Glossary
Threat Actor
Whoever is behind an attack. Ranges from opportunistic criminals running automated campaigns, through organised extortion groups operating like businesses, to state-linked operations with time and budget.
Attack Surface
Everything an attacker could reach: internet-facing systems, staff email accounts, supplier connections, remote access, physical sites, cloud services nobody remembers signing up for.
Payload
The part of an attack that does the damage, as opposed to the part that gets it in. Ransomware is a payload; the phishing email that delivered it is not.
Lateral Movement
Spreading from the first compromised machine to more valuable systems. Most damaging incidents involve days or weeks of lateral movement before anything visible happens — which is exactly the window where detection pays.
Dwell Time
How long an intruder is inside before discovery. Measured in weeks or months more often than hours, and the single best predictor of how bad an incident becomes.
Privilege Escalation
Turning ordinary access into administrative access. The step that converts an inconvenient breach into a serious one.
Exfiltration
Copying data out of your environment. Modern extortion usually steals data before encrypting anything, so that refusing to pay still carries a consequence.
Zero-Day
A flaw with no patch available at the time it is exploited. Genuinely serious, frequently invoked as an excuse for incidents that were in fact caused by patches available for months.
Indicator of Compromise
Evidence that something has gone wrong — an unfamiliar login location, a spike in outbound traffic, a new administrator account, a rule quietly forwarding someone's email.
Defence in Depth
Layering controls so no single failure is decisive. The principle behind the coverage analysis: attacks with several independent controls against them rarely succeed, even when one control is weak.
Least Privilege
Giving each account only the access it needs. Unglamorous, and the reason many compromises stay small.
Phishing-Resistant MFA
Second factors that cannot be relayed to an attacker in real time — security keys and passkeys. Codes sent by SMS or generated in an app are better than nothing but are routinely defeated by attacks in this library.
Scope & Limitations

This is awareness material, not an assessment. It describes attack types at the level a board briefing would. It deliberately contains no technical instructions, tooling or exploit detail — knowing how an attack works in principle is what lets you recognise and defend against it; anything beyond that serves no defensive purpose here.

Ratings are generic. Prevalence and impact reflect a mid-sized organisation with physical operations and a supply chain. Your own profile will differ, sometimes sharply. Use the ratings to order your thinking, then adjust from what you know about your own business.

Coverage is self-declared. The analysis takes your selections at face value. A control that exists but is misconfigured, unmonitored or only partly deployed will read as protection that is not there — which is the most common way organisations end up surprised.

The library is not exhaustive and does not stay current by itself. Techniques evolve, and new categories emerge — attacks against AI systems and identity infrastructure are both growing quickly. Review it against a current source such as national cyber agency guidance at least annually.

Nothing here is legal, insurance or incident response advice. If you are dealing with a live incident, engage professional response support and your legal counsel before taking irreversible steps, particularly around payment, disclosure and evidence.