Adversary Threat Quotient (ATQ): A Twelve-Factor Quantitative Threat Actor Scoring Model
J. McKenney
This is an unnumbered working paper in the WG-07 Threat Modeling and TACAM Matrix working group. It draws its threat actor records directly from the TACAM Matrix, a confirmed working-group sibling, and the score it computes is the same parameterizing scalar consumed by the Algorithmic Random Walks paper's Seldon Monte Carlo engine, also a confirmed working-group sibling.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Threat intelligence reports on attack groups usually describe them in words, such as "Advanced Persistent Threat" or "High risk," rather than with a number that can be compared directly between one group and another. Two genuinely different groups routinely land in the same top tier, so defenders cannot tell which one presents the greater immediate risk, or what a specific defensive investment is worth against it.
This paper defines a single number, called the Adversary Threat Quotient, on a scale of zero to one hundred, that scores how operationally dangerous a specific attacker is against a specific facility right now, built from twelve separate, individually documented factors rather than one opaque overall judgment. Each factor is drawn from real operational data, such as how recently the group has been active and how well its known tools match the target facility's actual equipment, so the score reflects current threat pressure rather than a static reputation.
The paper then shows the number feeding two practical downstream uses. It drives a simulation engine that models how an attack could physically spread through a facility, and it plugs into the same financial formulas insurers and security teams already use to work out how much a given security investment is worth, so a facility can translate a threat score directly into a defensive spending decision.
Abstract#
The Adversary Threat Quotient (ATQ) formalizes threat actor scoring as a continuous, cardinal metric on the closed interval 0 to 100, replacing the ordinal High/Medium/Low and nominal "Advanced Persistent Threat" labels that dominate conventional threat intelligence and saturate at the top of their own scale for every serious actor alike. The score is computed by a PostgreSQL materialized view, seldon.seldon_score_v2, over the working group's own TACAM, EPSS, knowledge-graph, and geopolitical-conflict data, and decomposes into twelve auditable dimensions across four tiers, Base Capability, Tactical Arsenal, Environmental Exposure, and Dynamic Momentum, each carrying a stated saturation threshold so that no single dimension collapses to unity across the actor population. The move from a coarse three-factor model to the twelve-factor formulation expands top-band score variance from 2.9 to 10.6 points. Downstream, the ATQ is the parameterizing scalar for the Eigenia Monte Carlo graph simulation engine, modulating Boltzmann random walk probabilities across physical facility piping and instrumentation topologies, and it is the input to the Annualized Loss Expectancy and Gordon-Loeb optimal security investment calculations, so that a threat actor's operational posture bridges directly to a stated capital allocation decision rather than stopping at a qualitative label.
1. Introduction#
The Measurement Problem in Threat Intelligence
Industrial control systems (ICS) and hyperscale computing infrastructure face persistent campaigns from sophisticated state-aligned and criminal syndicates. In boardrooms and underwriting syndicates, decision-makers are tasked with allocating finite capital to defend against these adversaries. However, traditional threat intelligence deliverables provide narrative dossiers rather than verifiable mathematical measurements.
When two distinct threat actors; such as Volt Typhoon (PRC-aligned, focusing on critical infrastructure pre-positioning) and Lazarus Group (DPRK-aligned, focusing on currency generation and disruptive malware); are both designated as "Tier 1 Critical Threats", the quantitative gap between their operational postures is lost. In legacy scoring paradigms, both actors saturate the top 5 percent of risk scales. Decision-makers cannot determine which adversary presents greater immediate risk to a specific facility configuration, nor can they quantify the return on investment of targeted architectural defenses.
The discriminatory power deficit#
Legacy three-factor model (V1). Input: Base Intent (33 percent), Static Capability (33 percent), Opportunity (34 percent).
| Threat actor | V1 score |
|---|---|
| Lazarus Group | 83.2 |
| Volt Typhoon | 82.9 |
| APT28 | 80.5 |
| Mustang Panda | 80.3 |
Variance across the top band: 2.9 points. The four actors are mutually indistinguishable, and the result is pervasive ceiling saturation.
Reform: 12 orthogonal dimensions.
Eigenia twelve-factor model (V2). Input: 12 dimensions, each with a stated saturation bound.
| Threat actor | V2 ATQ |
|---|---|
| Volt Typhoon | 78.6 |
| Dragonfly | 76.2 |
| Lazarus Group | 76.0 |
| APT29 | 73.6 |
| Ember Bear | 73.4 |
| Kimsuky | 68.0 |
Variance across the top band: 10.6 points, a 3.7x expansion. Operational posture is decoupled from historical incident volume.
As demonstrated above, the transition from a coarse three-factor model to the twelve-factor ATQ formulation expands the top-decile score variance by , separating dormant historical actors from actively pre-positioned operational threats.
2. Mathematical Formalization of the Twelve-Factor ATQ#
The Adversary Threat Quotient for an actor at temporal epoch is defined as a linear combination of twelve normalized dimensional scoring functions:
Subject to the simplex weight constraint:
Where:
- represents the raw dimensional metric extracted from authoritative databases.
- represents the dimensional normalization and saturation function.
- denotes the actuarial weight assigned to component .
2.1 Component Definitions, Weights, and Authoritative Data Sources#
The twelve dimensions are structured into four operational tiers: Base Capability, Tactical Arsenal, Environmental Exposure, and Dynamic Momentum:
| # | Dimension Name | Tier | Weight () | Raw Metric () | Saturation Threshold () | Normalization Function () | Authoritative Source |
|---|---|---|---|---|---|---|---|
| 1 | EIC Base Score | Base Capability | 0.18 | Explicit Intent, Capability, and Opportunity | Dynamic Percentile | seldon.actor_eic | |
| 2 | Kill Chain Completeness | Tactical Arsenal | 0.14 | Distinct MITRE Tactics Executable | 14 Tactics | tacam_ttp_clusters | |
| 3 | Temporal Threat Score | Dynamic Momentum | 0.08 | Operational Tempo & Recency Decay | 1.0 (Unit Interval) | tacam_temporal_clusters | |
| 4 | EPSS Base Average | Tactical Arsenal | 0.10 | Mean Exploit Prediction Score | 0.20 ( Multiplier) | FIRST EPSS Daily Feed | |
| 5 | Technique Reach | Tactical Arsenal | 0.10 | Unique MITRE ATT&CK Techniques | 120 Techniques | Knowledge Graph (USES_TECHNIQUE) | |
| 6 | Vendor Exposure | Environmental Exposure | 0.10 | Distinct Hardware/Software Vendors | 50 Vendors | tacam_cpe_clusters | |
| 7 | Sector Reach | Environmental Exposure | 0.05 | CISA Critical Sectors Targeted | 16 Sectors | Knowledge Graph (TARGETS_SECTOR) | |
| 8 | Protocol Reach | Environmental Exposure | 0.05 | OT/ICS Protocols Exploitable | 10 Protocols | Knowledge Graph (TARGETS_PROTOCOL) | |
| 9 | Incident Historical Volume | Base Capability | 0.05 | Attributed Public Incidents | 20 Incidents | Curated Incident Corpus | |
| 10 | Campaign Recency | Dynamic Momentum | 0.05 | Days Elapsed Since Last Activity | 365 Days Exponential | tacam_temporal_clusters | |
| 11 | EPSS Velocity | Dynamic Momentum | 0.05 | Rate of Change in Exploitability | 0.01/day ( Cap) | EPSS Trajectory Time-Series | |
| 12 | Geopolitical Tension | Dynamic Momentum | 0.05 | State Hostility & Conflict Index | 1.0 (Unit Interval) | ACLED & Geopolitical Field |
Note on the weight vector#
The twelve weights above sum to exactly 1.00 and the composite therefore lands on as section 1 states. Dimension 3 (Operational Tempo and Recency Decay) and Dimension 10 (Days Elapsed Since Last Activity) both read from tacam_temporal_clusters and both encode how recently the actor was active, so the two are held to a combined share of 0.13 (0.08 and 0.05) rather than allowed to compound.
The weights are actuarial judgment, not a fitted result. No regression against loss outcomes produced them, and no external study is cited for them. They encode this working group's view of what makes an adversary dangerous to an industrial facility, and a reader who disagrees can change one weight and re-run the materialized view rather than argue with the whole score.
3. The Mathematics of Saturation Thresholds#
A primary failure mode of composite scoring models is the uncalibrated ceiling effect. If the saturation threshold for a dimension is established below the median of active adversaries, the dimension loses all mathematical utility, collapsing to unity for all evaluated entities.
3.1 Linear Saturation vs. Piecewise Saturation#
For bounded dimensional functions (), normalization follows a piecewise continuous linear saturation model:
Consider the mathematical consequence of altering the Incident Volume threshold . In the legacy V1 model, . The probability of an advanced state-backed threat actor exceeding 3 attributed incidents is . Consequently, of evaluated threat actors received , rendering the dimension mathematically degenerate.
In the ATQ V2 formulation, was calibrated to the 85th percentile of the empirical incident distribution held in the curated incident corpus that Dimension 9 draws on (). The percentile is computed over the attributed public incident counts in that corpus, so this threshold is set by counting rather than by judgment; it is the only one of the twelve for which that is true. Under this calibration:
Only outlier global campaigns (e.g., Lazarus Group with 120 incidents, Dragonfly with 68 incidents, APT28 with 53 incidents) achieve saturation. Intermediate actors (e.g., CyberAv3ngers with 8 incidents, FIN7 with 12 incidents) exhibit linear differentiation:
This parameter adjustment restores 1.00 full point of variance to the composite index, directly reflecting operational capacity rather than historical artifacting.
3.2 EPSS Velocity Formulation#
Dimension 11 measures whether an actor's known common vulnerabilities and exposures (CVEs) are accelerating in global weaponization. Let denote the set of CVE identifiers attributed to actor . The instantaneous EPSS velocity is computed as:
Where . When threat actors pivot toward zero-day exploits or actively weaponize proof-of-concept repositories in industrial routers, surges, driving Dimension 11 to its maximum contribution () and triggering immediate defensive reassessments.
4. SQL Production Architecture: seldon.seldon_score_v2#
The ATQ is not an offline analytical study; it is implemented as a high-performance materialized view in PostgreSQL, refreshing on a diurnal schedule:
-- Production Materialized View: seldon.seldon_score_v2
CREATE MATERIALIZED VIEW seldon.seldon_score_v2 AS
WITH base_metrics AS (
SELECT
a.actor_id,
a.actor_name,
a.attribution_nation,
a.sophistication_tier,
-- Dimension 1: Percentile Ranked EIC
PERCENT_RANK() OVER (ORDER BY e.eic_composite_raw ASC) AS dim_eic,
-- Dimension 2: Kill Chain Completeness (Cap 14)
LEAST(1.0, kc.tactics_count::numeric / 14.0) AS dim_killchain,
-- Dimension 3: Temporal Threat Score
LEAST(1.0, tc.temporal_score::numeric) AS dim_temporal,
-- Dimension 4: EPSS Base Average (Cap 0.20 via 5x mult)
LEAST(1.0, COALESCE(ep.mean_epss, 0.0) * 5.0) AS dim_epss_base,
-- Dimension 5: Technique Reach (Cap 120)
LEAST(1.0, COALESCE(tr.technique_count, 0)::numeric / 120.0) AS dim_tech_reach,
-- Dimension 6: Vendor Exposure (Cap 50)
LEAST(1.0, COALESCE(ve.vendor_count, 0)::numeric / 50.0) AS dim_vendor_exp,
-- Dimension 7: Sector Reach (Cap 15)
LEAST(1.0, COALESCE(sr.sector_count, 0)::numeric / 16.0) AS dim_sector_reach,
-- Dimension 8: Protocol Reach (Cap 10)
LEAST(1.0, COALESCE(pr.protocol_count, 0)::numeric / 10.0) AS dim_protocol_reach,
-- Dimension 9: Incident Historical Volume (Cap 20)
LEAST(1.0, COALESCE(ic.incident_count, 0)::numeric / 20.0) AS dim_incidents,
-- Dimension 10: Campaign Recency (Exponential Decay)
EXP(-0.005 * GREATEST(0, tc.days_since_active)) AS dim_recency,
-- Dimension 11: EPSS Velocity (Cap 0.01 via 100x mult)
LEAST(1.0, GREATEST(0.0, COALESCE(ep.epss_velocity, 0.0) * 100.0)) AS dim_epss_vel,
-- Dimension 12: Geopolitical Tension Scalar
LEAST(1.0, COALESCE(gp.tension_index, 0.0)::numeric) AS dim_geo_tension
FROM seldon.threat_actors a
LEFT JOIN seldon.actor_eic e ON a.actor_id = e.actor_id
LEFT JOIN seldon.tacam_ttp_clusters kc ON a.actor_id = kc.actor_id
LEFT JOIN seldon.tacam_temporal_clusters tc ON a.actor_id = tc.actor_id
LEFT JOIN seldon.epss_aggregates ep ON a.actor_id = ep.actor_id
LEFT JOIN seldon.technique_reach tr ON a.actor_id = tr.actor_id
LEFT JOIN seldon.vendor_exposure ve ON a.actor_id = ve.actor_id
LEFT JOIN seldon.sector_reach sr ON a.actor_id = sr.actor_id
LEFT JOIN seldon.protocol_reach pr ON a.actor_id = pr.actor_id
LEFT JOIN seldon.incident_corpus ic ON a.actor_id = ic.actor_id
LEFT JOIN seldon.geopolitical_field gp ON a.attribution_nation = gp.nation_iso
)
SELECT
actor_id,
actor_name,
attribution_nation,
sophistication_tier,
-- Individual weighted components
ROUND((dim_eic * 18.0)::numeric, 2) AS w_eic,
ROUND((dim_killchain * 14.0)::numeric, 2) AS w_killchain,
ROUND((dim_temporal * 8.0)::numeric, 2) AS w_temporal,
ROUND((dim_epss_base * 10.0)::numeric, 2) AS w_epss_base,
ROUND((dim_tech_reach * 10.0)::numeric, 2) AS w_tech_reach,
ROUND((dim_vendor_exp * 10.0)::numeric, 2) AS w_vendor_exp,
ROUND((dim_sector_reach * 5.0)::numeric, 2) AS w_sector_reach,
ROUND((dim_protocol_reach * 5.0)::numeric, 2) AS w_protocol_reach,
ROUND((dim_incidents * 5.0)::numeric, 2) AS w_incidents,
ROUND((dim_recency * 5.0)::numeric, 2) AS w_recency,
ROUND((dim_epss_vel * 5.0)::numeric, 2) AS w_epss_vel,
ROUND((dim_geo_tension * 5.0)::numeric, 2) AS w_geo_tension,
-- Final Composite ATQ Score
ROUND((
(dim_eic * 18.0) +
(dim_killchain * 14.0) +
(dim_temporal * 8.0) +
(dim_epss_base * 10.0) +
(dim_tech_reach * 10.0) +
(dim_vendor_exp * 10.0) +
(dim_sector_reach * 5.0) +
(dim_protocol_reach * 5.0) +
(dim_incidents * 5.0) +
(dim_recency * 5.0) +
(dim_epss_vel * 5.0) +
(dim_geo_tension * 5.0)
)::numeric, 1) AS composite_atq
FROM base_metrics;
CREATE UNIQUE INDEX idx_seldon_score_v2_actor ON seldon.seldon_score_v2(actor_id);5. Downstream Systems Coupling: Monte Carlo Boltzmann Walk Engine#
The primary systems assurance application of the ATQ is parameterizing stochastic threat traversal in the Eigenia Cyber Digital Twin.
5.1 The Boltzmann Graph Walk Formulation#
When simulating threat propagation across an industrial network graph comprising PLCs, SCADA servers, engineering workstations, and physical chillers, transition probabilities are modeled as a Boltzmann distribution:
Where:
- represents the security barrier energy: defense-in-depth controls, firewall inspection latency, mTLS authentication, and air-gap separation.
- represents the effective threat temperature, governed directly by the actor's ATQ:
Where:
- is the non-linearity exponent. The working group set it at 1.85 so that a top-decile actor's effective temperature separates clearly from a mid-band actor's. No fit against incident data produced the value and none is claimed for it; every effective temperature downstream carries that choice.
- is the TACAM sector-affinity multiplier.
Under this formulation, an actor with an ATQ of (Volt Typhoon) exhibits an effective temperature higher than an actor with an ATQ of . Consequently, high-ATQ adversaries overcome substantial cyber-physical security barriers () with high probability, penetrating deep into Layer 1/Layer 2 control networks.
Boltzmann propagation trajectory. The same topological barrier yields radically different transition probabilities depending on the actor's ATQ, because ATQ modulates the effective temperature in the Boltzmann factor:
| Actor | ATQ | Edge barrier | Outcome | |||
|---|---|---|---|---|---|---|
| Low-ATQ actor | 38.2 | Corporate DMZ to SCADA DMZ | 8.4 eV | 1.2 (baseline) | 0.012 | Defenses hold |
| Volt Typhoon (energy-sector affinity) | 78.6 | Corporate DMZ to SCADA DMZ | 8.4 eV | surges 1.2 to 4.8 | 0.684 | Breach imminent |
5.2 Physical Process Coupling: Thermal Hydraulic Transients#
When a high-ATQ adversary successfully navigates the graph walk and establishes write-access to Layer 1/Layer 2 controllers, the operational outcome is governed by the physical plant thermodynamics. In high-density liquid-cooled computing facilities operating at per rack, malware-induced volumetric flow cessation triggers catastrophic thermal runaway.
The rate of change of silicon junction temperature is governed by the transient convective energy balance:
Where:
- dissipation per accelerator package, the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU. A compute tray carries four such packages together with two Grace CPUs and draws roughly 5.4 kW.
- is the volumetric coolant flow rate ( nominal per rack).
- is the convective heat transfer coefficient, which collapses toward zero during fluid stagnation.
- Package heat flux is across the dual-die module.
- thermal capacitance of the stagnant cold plate assembly, dominated by the coolant retained in the channels once flow stops.
When flow halts, junction temperature surges at . The emergency hardware shutdown trips when reaches , establishing a strict 15-second thermal trip cliff. The ATQ effective temperature translates directly into the probability that an adversary executes this command sequence before manual operator intervention can occur.
6. Financial and Actuarial Economics: Gordon-Loeb Capital Allocation#
The ultimate objective of quantitative threat modeling is providing boards of directors and insurance underwriters with mathematically defensible investment thresholds.
6.1 Gordon-Loeb Optimal Investment Bounds#
Under the classical Gordon-Loeb model, the optimal cybersecurity investment to defend an information set with asset value and vulnerability probability under potential loss is bounded by:
In the Eigenia actuarial architecture, the vulnerability probability is not a static assumption; it is the integrated breach probability computed by the Monte Carlo engine parameterized by :
Annualized Loss Expectancy () is directly determined by the threat-weighted adversary pool:
Where:
- is the Annualized Rate of Occurrence derived from Dimension 10 (Recency) and Dimension 12 (Geopolitical Tension).
- is the Single Loss Expectancy encompassing physical equipment replacement, business interruption, and regulatory fines under EU CRA Article 64.
6.2 Worked Underwriting Case Study#
Consider an enterprise operating a compute facility with $144,000,000 in physical asset exposure. When evaluated against the legacy three-factor model, threat pressure was categorized as "High", justifying a generic $4,000,000 perimeter upgrade.
When evaluated via the twelve-factor ATQ:
- Volt Typhoon scored , with extreme affinity for the facility's specific Siemens SIMATIC S7-1500 controllers (CPE Dimension 6: ) and electrical switchgear protocols (Dimension 8: ).
- Monte Carlo simulations revealed that Volt Typhoon's effective threat temperature breached perimeter defenses in of trials, inducing physical cooling stagnation ( reaching in ).
- Recomputed rose from $2,400,000 to $18,200,000.
- The Gordon-Loeb optimal security investment shifted to:
Directing capital specifically to hardwired, autonomous SIL-3 emergency trip cutouts that physically isolate coolant pumps from network control, eliminating human latency and mitigating the threat path.
6.3 Reinsurance Underwriting, the Lloyd's Y5381 Exclusion, and ROSI#
In catastrophic property reinsurance, Lloyd's Market Bulletin Y5381, issued by the Corporation of Lloyd's on 16 August 2022, requires that stand-alone cyber-attack policies written or renewed from 31 March 2023 exclude losses arising from war and from state-backed cyber attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state; the Lloyd's Market Association's model clauses LMA5564 to LMA5567 (November 2021) are the wordings drafted to meet that requirement. Insurers evaluate Probable Maximum Loss () across concentrated facility clusters:
Where:
- represents physical hardware replacement cost ($14,400,000 per 120-rack compute hall).
- is the business interruption revenue loss rate ($24,000/hour).
- represents statutory penalties under EU CRA Article 64.
By running the ATQ through the penetration simulation and deploying deterministic SIL-3 physical trip controls (), the insured cuts modeled breach probability from to . That moves modeled from $18,200,000 to $410,000, giving a modeled Return on Security Investment ():
Every input to that quotient is the working group's: the 240,000 USD control cost, the two breach probabilities out of the simulation, and the 144,000,000 USD asset exposure the ALE is built on. The division is exact and reproduces to 7,312.5 percent, which is a statement about the arithmetic and not about the inputs. A reduction of this shape, once an operator has substituted its own asset values and its own control costs, is what lets underwriters waive restrictive sub-limit caps, lower policy deductible retentions from $10,000,000 to $2,500,000, drop consequential loss exclusions, and hold systemic accumulation exposure down. The percentage is the model talking; the placement is a negotiation.
7. Systems Assurance and Multi-BOM Traceability#
The ATQ model enforces full end-to-end normative systems assurance across cyber-physical infrastructure:
- IEC 62443 Standards Alignment: Mapped to IEC 62443-3-2 risk assessment zones, Security Level Targets (SL-T 1 through SL-T 4), and SecRAC operational conditions.
- Physical Topology Integration (DEXPI 2.0 / ISO 15926-4): Threat propagation graphs are anchored directly to XML piping and instrumentation schematics.
- CycloneDX 1.6+ Multi-BOM Architecture:
- HBOM (Hardware Bill of Materials): Silicon ASICs, power distribution units, and variable frequency drives (VFDs).
- SBOM (Software Bill of Materials): Firmware digests, SCADA runtime binaries, and Modbus protocol stacks.
- CBOM (Cryptographic Bill of Materials): Mutual TLS certificates, hardware root-of-trust identity keys, and DICE credentials.
- OBOM (Operational Bill of Materials): Permissible physical operating envelopes (flow rate , temperature ).
- VEX (Vulnerability Exploitability eXchange): Automated machine-readable threat advisories updating Dimension 4 and Dimension 11 in real-time.
- Silicon Root-of-Trust Hardware: Caliptra 2.0 and OpenSIL integration providing cryptographic measurement registers and DICE attestation, establishing immutable supply chain provenance under EN 50126 reliability standards.
8. Interactive Console & Telemetry Terminal: ATQ Card#
To enable real-time operator inspection and dynamic adversary re-scoring, the complete twelve-factor mathematical model is rendered through the ATQ Interactive Card Terminal; accessible at /terminals/atq-card-terminal.html.
ATQ interactive card terminal architecture#
Location: /terminals/atq-card-terminal.html. Capabilities:
- High-assurance HUD view: 20-segment micro-LED bars for all 12 weights.
- TACAM 7D cross-match matrix: sector, protocol, CPE, and kill chain.
- 90-day trajectory sparkline: historical delta analysis across epochs.
- Raw ASCII console output: direct terminal export for CLI workflows.
- Production formula specification: mathematical table and data links.
8.1 Production Decomposed Telemetry Display#
The interactive terminal renders the auditable component decomposition for any profiled adversary:
VOLT TYPHOON · ATQ: 78.6 · Attribution: China / People's Republic of China · Sophistication: Advanced Persistent Threat
Component breakdown
| Component | Weight | Score |
|---|---|---|
| EIC Score | 18% | 14.7 / 18 |
| Kill Chain | 14% | 12.0 / 14 |
| Temporal | 13% | 12.4 / 13 |
| EPSS Base | 10% | 7.3 / 10 |
| Technique Reach | 10% | 6.8 / 10 |
| Vendor Exposure | 10% | 8.0 / 10 |
| Sector Reach | 5% | 4.2 / 5 |
| Protocol Reach | 5% | 3.4 / 5 |
| Incident Count | 5% | 4.2 / 5 |
| Campaign Recency | 5% | 4.8 / 5 |
| EPSS Velocity | 5% | 0.4 / 5 |
| Geo Tension | 5% | 0.3 / 5 |
TACAM cross-match
| Field | Value |
|---|---|
| Sector | Energy (0.94), Water (0.71), Comms (0.83) |
| Protocols | OPC-UA, Modbus, DNP3 |
| Top CPE Targets | Siemens SIMATIC, Cisco IOS, Fortinet |
| Campaign Recency | Active (last 30 days) |
| Kill Chain | 12/14 tactics (missing: Exfiltration, Impact) |
Trajectory (90-day)
| Measure | Value |
|---|---|
| ATQ Δ | +2.3 points ↑ (Epoch 228 → 234) |
| Driven by | Temporal +1.4, EPSS vel +0.6, Recency +0.3 |
| Forecast | Elevated through Q3 2026 (87% confidence) |
The terminal allows operators to switch dynamically between profiled actors (including Sandworm, Lazarus Group, LockBit 3.0, and Scattered Spider), inspect individual mathematical weights, and export standardized JSON payloads to downstream security orchestrators.
9. Comparative Evaluation: Industry Benchmarks vs. Eigenia ATQ#
To validate the methodological rigor of the ATQ, it is benchmarked against established commercial and open-source threat intelligence rating frameworks:
| Evaluation Dimension | Traditional Commercial TI (Mandiant, CrowdStrike) | CVSS / EPSS Base Feeds | MITRE ATT&CK Matrix | Eigenia ATQ Specification |
|---|---|---|---|---|
| Measurement Type | Qualitative narrative / nominal tiers | Vulnerability-centric probability | Categorical behavioral ontology | Multi-factor cardinal scalar () |
| Component Auditability | Proprietary black box | Unidimensional logistic regression | TTP checklist without weights | 12 auditable SQL-materialized columns |
| Temporal Dynamics | Periodic PDF reports | Diurnal score refresh | Versioned releases (bi-annual) | Diurnal epoch snapshots with delta tracking |
| Downstream Simulation | Manual analyst interpretation | Prioritization filters | Threat mapping | Direct Boltzmann random-walk parameterization |
| Financial Translation | Subjective risk heatmaps | None | None | Gordon-Loeb optimal investment & ALE bounds |
| Operational Technology | Limited IT/OT convergence | Primarily IT software CVEs | Dedicated ICS matrix | Full TACAM protocol & CPE physical mapping |
10. Conclusion: From Threat Narrative to a Stated Model#
The Adversary Threat Quotient resolves the measurement problem in modern cybersecurity. By grounding threat actor evaluation in twelve dimensions, each with a named data source and a stated saturation bound, continuously refreshed against live telemetry and weaponization feeds, the ATQ replaces the nominal labels of traditional threat intelligence with a number whose construction can be argued with. The weights are the working group's actuarial judgment, stated in section 2.1 so a reader can disagree with a specific one rather than with the whole score.
When coupled to physical facility digital twins through DEXPI 2.0 piping schematics and Boltzmann random-walk graph traversals, the ATQ bridges the chasm between threat actor capabilities and thermodynamic consequences. Security leaders and reinsurance underwriters are equipped with an auditable, cardinal measurement that translates raw threat data into deterministic engineering controls and mathematically optimal capital investments.
11. References#
McKenney, J. (2026). The TACAM Matrix: Spectral Decomposition and Adversary Threat Quotients in Industrial Control Systems. Eigenia Research Working Group 07 Treatise WG-07-TM-TACAM.
The per-accelerator power figure in section 5 is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet. The four-GPU, two-Grace-CPU compute tray composition given in the same section is NVIDIA's own, from the NVIDIA Mission Control Systems Administration Guide, FAQ, docs.nvidia.com/mission-control/docs/systems-administration-guide/2.0.0/prs/faq.html.