Threats
A threat is a catalogued source of potential harm — a phenomenon, an actor or an event that could compromise an asset, a business process or a regulatory obligation. Threats are building blocks rather than records of anything that happened: one threat, say Phishing, can be named by dozens of risk scenarios across many assessments without being duplicated.
Where to find it
Section titled “Where to find it”Catalog → Threats in the sidebar.
Key concepts
Section titled “Key concepts”Where threats come from
Section titled “Where threats come from”Two routes, and most organizations use both:
- Imported. CyberGuard ships curated threat libraries built on common sources — MITRE ATT&CK, ENISA’s taxonomy, the illustrative catalog from ISO 27005, and sector-specific collections. The import shortcut on this page takes you to Libraries filtered to threat content.
- Written by you. Use Add threat for anything your own analysis surfaces that no published catalog covers. A locally created threat lives in a domain and behaves exactly like an imported one everywhere else.
Fields
Section titled “Fields”| Field | What it is for |
|---|---|
| Reference ID | The identifier from the source catalog, or your own |
| Name | Short, recognisable — this is what appears in scenario pickers |
| Description | What the threat actually is; worth writing properly, because it is what stops two analysts meaning different things |
| Library | Which loaded library supplied it, when imported |
| Provider | Who publishes it |
| Domain | Where it lives, and therefore who can use it |
| Labels | Your own tags — Ransomware, Insider, Supply chain |
Labels are the practical way to slice a large imported catalog. A library can contribute hundreds of entries; tagging the ones relevant to you makes the picker usable when someone is building a scenario.
Where threats show up
Section titled “Where threats show up”- Risk scenarios name the threat driving them. This is the main consumer.
- EBIOS RM operational scenarios map threats onto attacker techniques along the kill chain.
- Vulnerabilities can be linked to threats to express what could exploit a given weakness.
- Applied controls can declare which threats they address, which is how you show coverage rather than just activity.
The Risk tab of Analytics draws a treemap of threats across your scenarios. If it reads No threats mapped, nobody has attached threats to scenarios yet — and that view stays empty until they do.
Working with threats
Section titled “Working with threats”Search covers name, reference ID and description; filters cover domain, provider, library and labels. Optional columns add Provider, Created at and Updated at for spotting stale entries.
Opening a threat shows what references it, which is the quickest way to judge whether it is worth keeping.
Keeping the catalog usable
Section titled “Keeping the catalog usable”A catalog nobody can navigate is worse than a short one. Two habits help:
- Import the source catalog that matches your method rather than several overlapping ones. Two libraries describing phishing differently means two scenarios nobody can compare.
- Curate with labels rather than deletion. Imported entries belong to their library; tagging the relevant subset leaves the library intact and upgradeable.
Related
Section titled “Related”- Risk scenarios — the main consumer of this catalog.
- Reference controls — the mitigations you link threats to.
- Libraries — where threat catalogs are loaded from.
- Labels — the tagging scheme used across the catalog.
