Every major type of cyber attack, explained in plain language for people who run operations rather than networks. What each one is, how it reaches you, what it looks like when it is happening, and which defences actually stop it — with a coverage check to show where your gaps are.
| Attack | Category | Risk | Controls Held | Coverage | Status | Missing Controls |
|---|
Almost nothing here is sophisticated. The overwhelming majority of successful attacks use a stolen password, an unpatched system, or a convincing email. Advanced techniques exist and make good reading, but they are not what is going to happen to you. Fix the ordinary things first.
The finance function is the target more often than the data centre. Payment redirection through compromised or spoofed email costs businesses more each year than ransomware does, and it needs no malware at all. A callback procedure on bank detail changes is the single cheapest control in this entire library.
Your suppliers are part of your attack surface. A meaningful share of breaches arrive through a third party — an IT provider, a logistics partner, a maintenance contractor with remote access. Your security is capped by theirs, which is a contracting problem as much as a technical one.
Attackers wait for the worst moment. Ransomware is disproportionately deployed on Friday evenings, public holidays and during known peak seasons, because that is when response is slowest and pressure to pay is highest. Plan coverage accordingly.
Backups fail when they matter. The common failure is not the absence of backups, it is backups that were reachable from the compromised network, or that had never been restored end-to-end. If it has not been tested by actually rebuilding something, treat it as unproven.
This is awareness material, not an assessment. It describes attack types at the level a board briefing would. It deliberately contains no technical instructions, tooling or exploit detail — knowing how an attack works in principle is what lets you recognise and defend against it; anything beyond that serves no defensive purpose here.
Ratings are generic. Prevalence and impact reflect a mid-sized organisation with physical operations and a supply chain. Your own profile will differ, sometimes sharply. Use the ratings to order your thinking, then adjust from what you know about your own business.
Coverage is self-declared. The analysis takes your selections at face value. A control that exists but is misconfigured, unmonitored or only partly deployed will read as protection that is not there — which is the most common way organisations end up surprised.
The library is not exhaustive and does not stay current by itself. Techniques evolve, and new categories emerge — attacks against AI systems and identity infrastructure are both growing quickly. Review it against a current source such as national cyber agency guidance at least annually.
Nothing here is legal, insurance or incident response advice. If you are dealing with a live incident, engage professional response support and your legal counsel before taking irreversible steps, particularly around payment, disclosure and evidence.