Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
ATQ FormulaAdversary Modeling

Adversary Threat Quotient (ATQ): A Twelve-Factor Quantitative Threat Actor Scoring Model

100% Complete & Untruncated 20 min read
Return to Research Tracks

J. McKenney

This is an unnumbered working paper in the WG-07 Threat Modeling and TACAM Matrix working group. It draws its threat actor records directly from the TACAM Matrix, a confirmed working-group sibling, and the score it computes is the same parameterizing scalar consumed by the Algorithmic Random Walks paper's Seldon Monte Carlo engine, also a confirmed working-group sibling.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

Threat intelligence reports on attack groups usually describe them in words, such as "Advanced Persistent Threat" or "High risk," rather than with a number that can be compared directly between one group and another. Two genuinely different groups routinely land in the same top tier, so defenders cannot tell which one presents the greater immediate risk, or what a specific defensive investment is worth against it.

This paper defines a single number, called the Adversary Threat Quotient, on a scale of zero to one hundred, that scores how operationally dangerous a specific attacker is against a specific facility right now, built from twelve separate, individually documented factors rather than one opaque overall judgment. Each factor is drawn from real operational data, such as how recently the group has been active and how well its known tools match the target facility's actual equipment, so the score reflects current threat pressure rather than a static reputation.

The paper then shows the number feeding two practical downstream uses. It drives a simulation engine that models how an attack could physically spread through a facility, and it plugs into the same financial formulas insurers and security teams already use to work out how much a given security investment is worth, so a facility can translate a threat score directly into a defensive spending decision.

Abstract#

The Adversary Threat Quotient (ATQ) formalizes threat actor scoring as a continuous, cardinal metric on the closed interval 0 to 100, replacing the ordinal High/Medium/Low and nominal "Advanced Persistent Threat" labels that dominate conventional threat intelligence and saturate at the top of their own scale for every serious actor alike. The score is computed by a PostgreSQL materialized view, seldon.seldon_score_v2, over the working group's own TACAM, EPSS, knowledge-graph, and geopolitical-conflict data, and decomposes into twelve auditable dimensions across four tiers, Base Capability, Tactical Arsenal, Environmental Exposure, and Dynamic Momentum, each carrying a stated saturation threshold so that no single dimension collapses to unity across the actor population. The move from a coarse three-factor model to the twelve-factor formulation expands top-band score variance from 2.9 to 10.6 points. Downstream, the ATQ is the parameterizing scalar for the Eigenia Monte Carlo graph simulation engine, modulating Boltzmann random walk probabilities across physical facility piping and instrumentation topologies, and it is the input to the Annualized Loss Expectancy and Gordon-Loeb optimal security investment calculations, so that a threat actor's operational posture bridges directly to a stated capital allocation decision rather than stopping at a qualitative label.


1. Introduction#

The Measurement Problem in Threat Intelligence

Industrial control systems (ICS) and hyperscale computing infrastructure face persistent campaigns from sophisticated state-aligned and criminal syndicates. In boardrooms and underwriting syndicates, decision-makers are tasked with allocating finite capital to defend against these adversaries. However, traditional threat intelligence deliverables provide narrative dossiers rather than verifiable mathematical measurements.

When two distinct threat actors; such as Volt Typhoon (PRC-aligned, focusing on critical infrastructure pre-positioning) and Lazarus Group (DPRK-aligned, focusing on currency generation and disruptive malware); are both designated as "Tier 1 Critical Threats", the quantitative gap between their operational postures is lost. In legacy scoring paradigms, both actors saturate the top 5 percent of risk scales. Decision-makers cannot determine which adversary presents greater immediate risk to a specific facility configuration, nor can they quantify the return on investment of targeted architectural defenses.

The discriminatory power deficit#

Legacy three-factor model (V1). Input: Base Intent (33 percent), Static Capability (33 percent), Opportunity (34 percent).

Threat actorV1 score
Lazarus Group83.2
Volt Typhoon82.9
APT2880.5
Mustang Panda80.3

Variance across the top band: 2.9 points. The four actors are mutually indistinguishable, and the result is pervasive ceiling saturation.

Reform: 12 orthogonal dimensions.

Eigenia twelve-factor model (V2). Input: 12 dimensions, each with a stated saturation bound.

Threat actorV2 ATQ
Volt Typhoon78.6
Dragonfly76.2
Lazarus Group76.0
APT2973.6
Ember Bear73.4
Kimsuky68.0

Variance across the top band: 10.6 points, a 3.7x expansion. Operational posture is decoupled from historical incident volume.

As demonstrated above, the transition from a coarse three-factor model to the twelve-factor ATQ formulation expands the top-decile score variance by 365%365\%, separating dormant historical actors from actively pre-positioned operational threats.


2. Mathematical Formalization of the Twelve-Factor ATQ#

The Adversary Threat Quotient for an actor aa at temporal epoch tt is defined as a linear combination of twelve normalized dimensional scoring functions:

ATQa(t)=∑k=112wk⋅σk(xa,k(t))×100\text{ATQ}_a(t) = \sum_{k=1}^{12} w_k \cdot \sigma_k\left( x_{a,k}(t) \right) \times 100

Subject to the simplex weight constraint:

∑k=112wk=1.0,wk>0∀k∈{1,…,12}\sum_{k=1}^{12} w_k = 1.0, \quad w_k > 0 \quad \forall k \in \{1, \dots, 12\}

Where:

  • xa,k(t)∈R≥0x_{a,k}(t) \in \mathbb{R}_{\ge 0} represents the raw dimensional metric extracted from authoritative databases.
  • σk:R≥0→[0,1]\sigma_k: \mathbb{R}_{\ge 0} \to [0, 1] represents the dimensional normalization and saturation function.
  • wkw_k denotes the actuarial weight assigned to component kk.

2.1 Component Definitions, Weights, and Authoritative Data Sources#

The twelve dimensions are structured into four operational tiers: Base Capability, Tactical Arsenal, Environmental Exposure, and Dynamic Momentum:

#Dimension NameTierWeight (wkw_k)Raw Metric (xa,kx_{a,k})Saturation Threshold (θk\theta_k)Normalization Function (σk\sigma_k)Authoritative Source
1EIC Base ScoreBase Capability0.18Explicit Intent, Capability, and OpportunityDynamic PercentilePERCENT_RANK(xa,1)\text{PERCENT\_RANK}(x_{a,1})seldon.actor_eic
2Kill Chain CompletenessTactical Arsenal0.14Distinct MITRE Tactics Executable14 Tacticsxa,2/14.0x_{a,2} / 14.0tacam_ttp_clusters
3Temporal Threat ScoreDynamic Momentum0.08Operational Tempo & Recency Decay1.0 (Unit Interval)min⁡(1.0,xa,3)\min(1.0, x_{a,3})tacam_temporal_clusters
4EPSS Base AverageTactical Arsenal0.10Mean Exploit Prediction Score0.20 (5×5\times Multiplier)min⁡(1.0,5.0⋅xˉEPSS)\min(1.0, 5.0 \cdot \bar{x}_{\text{EPSS}})FIRST EPSS Daily Feed
5Technique ReachTactical Arsenal0.10Unique MITRE ATT&CK Techniques120 Techniquesmin⁡(1.0,xa,5/120.0)\min(1.0, x_{a,5} / 120.0)Knowledge Graph (USES_TECHNIQUE)
6Vendor ExposureEnvironmental Exposure0.10Distinct Hardware/Software Vendors50 Vendorsmin⁡(1.0,xa,6/50.0)\min(1.0, x_{a,6} / 50.0)tacam_cpe_clusters
7Sector ReachEnvironmental Exposure0.05CISA Critical Sectors Targeted16 Sectorsmin⁡(1.0,xa,7/16.0)\min(1.0, x_{a,7} / 16.0)Knowledge Graph (TARGETS_SECTOR)
8Protocol ReachEnvironmental Exposure0.05OT/ICS Protocols Exploitable10 Protocolsmin⁡(1.0,xa,8/10.0)\min(1.0, x_{a,8} / 10.0)Knowledge Graph (TARGETS_PROTOCOL)
9Incident Historical VolumeBase Capability0.05Attributed Public Incidents20 Incidentsmin⁡(1.0,xa,9/20.0)\min(1.0, x_{a,9} / 20.0)Curated Incident Corpus
10Campaign RecencyDynamic Momentum0.05Days Elapsed Since Last Activity365 Days Exponentialexp⁡(−λrec⋅Δtdays)\exp(-\lambda_{\text{rec}} \cdot \Delta t_{\text{days}})tacam_temporal_clusters
11EPSS VelocityDynamic Momentum0.05Rate of Change in Exploitability0.01/day (100×100\times Cap)min⁡(1.0,max⁡(0.0,100⋅v˙EPSS))\min(1.0, \max(0.0, 100 \cdot \dot{v}_{\text{EPSS}}))EPSS Trajectory Time-Series
12Geopolitical TensionDynamic Momentum0.05State Hostility & Conflict Index1.0 (Unit Interval)min⁡(1.0,xa,12)\min(1.0, x_{a,12})ACLED & Geopolitical Field

Note on the weight vector#

The twelve weights above sum to exactly 1.00 and the composite therefore lands on [0,100][0, 100] as section 1 states. Dimension 3 (Operational Tempo and Recency Decay) and Dimension 10 (Days Elapsed Since Last Activity) both read from tacam_temporal_clusters and both encode how recently the actor was active, so the two are held to a combined share of 0.13 (0.08 and 0.05) rather than allowed to compound.

The weights are actuarial judgment, not a fitted result. No regression against loss outcomes produced them, and no external study is cited for them. They encode this working group's view of what makes an adversary dangerous to an industrial facility, and a reader who disagrees can change one weight and re-run the materialized view rather than argue with the whole score.


3. The Mathematics of Saturation Thresholds#

A primary failure mode of composite scoring models is the uncalibrated ceiling effect. If the saturation threshold θk\theta_k for a dimension is established below the median of active adversaries, the dimension loses all mathematical utility, collapsing to unity for all evaluated entities.

3.1 Linear Saturation vs. Piecewise Saturation#

For bounded dimensional functions (k∈{2,4,5,6,7,8,9,11}k \in \{2, 4, 5, 6, 7, 8, 9, 11\}), normalization follows a piecewise continuous linear saturation model:

σk(x)={xθkif 0≤x<θk1.0if x≥θk\sigma_k(x) = \begin{cases} \frac{x}{\theta_k} & \text{if } 0 \le x < \theta_k \\ 1.0 & \text{if } x \ge \theta_k \end{cases}

Consider the mathematical consequence of altering the Incident Volume threshold θ9\theta_9. In the legacy V1 model, θ9=3\theta_9 = 3. The probability of an advanced state-backed threat actor exceeding 3 attributed incidents is P(x≥3)=0.942P(x \ge 3) = 0.942. Consequently, 94.2%94.2\% of evaluated threat actors received σ9=1.0\sigma_9 = 1.0, rendering the dimension mathematically degenerate.

In the ATQ V2 formulation, θ9\theta_9 was calibrated to the 85th percentile of the empirical incident distribution held in the curated incident corpus that Dimension 9 draws on (θ9=20\theta_9 = 20). The percentile is computed over the attributed public incident counts in that corpus, so this threshold is set by counting rather than by judgment; it is the only one of the twelve for which that is true. Under this calibration:

P(x<20)=0.850,P(x≥20)=0.150P(x < 20) = 0.850, \quad P(x \ge 20) = 0.150

Only outlier global campaigns (e.g., Lazarus Group with 120 incidents, Dragonfly with 68 incidents, APT28 with 53 incidents) achieve saturation. Intermediate actors (e.g., CyberAv3ngers with 8 incidents, FIN7 with 12 incidents) exhibit linear differentiation:

σ9(CyberAv3ngers)=820=0.400  ⟹  w9⋅σ9=2.00 points\sigma_9(\text{CyberAv3ngers}) = \frac{8}{20} = 0.400 \implies w_9 \cdot \sigma_9 = 2.00\text{ points}
σ9(FIN7)=1220=0.600  ⟹  w9⋅σ9=3.00 points\sigma_9(\text{FIN7}) = \frac{12}{20} = 0.600 \implies w_9 \cdot \sigma_9 = 3.00\text{ points}

This parameter adjustment restores 1.00 full point of variance to the composite index, directly reflecting operational capacity rather than historical artifacting.

3.2 EPSS Velocity Formulation#

Dimension 11 measures whether an actor's known common vulnerabilities and exposures (CVEs) are accelerating in global weaponization. Let Ca={c1,c2,…,cm}\mathcal{C}_a = \{c_1, c_2, \dots, c_m\} denote the set of CVE identifiers attributed to actor aa. The instantaneous EPSS velocity is computed as:

v˙EPSS(a,t)=1∣Ca∣∑c∈CaEPSS(c,t)−EPSS(c,t−Δt)Δt\dot{v}_{\text{EPSS}}(a, t) = \frac{1}{|\mathcal{C}_a|} \sum_{c \in \mathcal{C}_a} \frac{\text{EPSS}(c, t) - \text{EPSS}(c, t - \Delta t)}{\Delta t}

Where Δt=30 days\Delta t = 30\text{ days}. When threat actors pivot toward zero-day exploits or actively weaponize proof-of-concept repositories in industrial routers, v˙EPSS\dot{v}_{\text{EPSS}} surges, driving Dimension 11 to its maximum contribution (5.0 points5.0\text{ points}) and triggering immediate defensive reassessments.


4. SQL Production Architecture: seldon.seldon_score_v2#

The ATQ is not an offline analytical study; it is implemented as a high-performance materialized view in PostgreSQL, refreshing on a diurnal schedule:

sql
-- Production Materialized View: seldon.seldon_score_v2
CREATE MATERIALIZED VIEW seldon.seldon_score_v2 AS
WITH base_metrics AS (
    SELECT 
        a.actor_id,
        a.actor_name,
        a.attribution_nation,
        a.sophistication_tier,
        -- Dimension 1: Percentile Ranked EIC
        PERCENT_RANK() OVER (ORDER BY e.eic_composite_raw ASC) AS dim_eic,
        -- Dimension 2: Kill Chain Completeness (Cap 14)
        LEAST(1.0, kc.tactics_count::numeric / 14.0) AS dim_killchain,
        -- Dimension 3: Temporal Threat Score
        LEAST(1.0, tc.temporal_score::numeric) AS dim_temporal,
        -- Dimension 4: EPSS Base Average (Cap 0.20 via 5x mult)
        LEAST(1.0, COALESCE(ep.mean_epss, 0.0) * 5.0) AS dim_epss_base,
        -- Dimension 5: Technique Reach (Cap 120)
        LEAST(1.0, COALESCE(tr.technique_count, 0)::numeric / 120.0) AS dim_tech_reach,
        -- Dimension 6: Vendor Exposure (Cap 50)
        LEAST(1.0, COALESCE(ve.vendor_count, 0)::numeric / 50.0) AS dim_vendor_exp,
        -- Dimension 7: Sector Reach (Cap 15)
        LEAST(1.0, COALESCE(sr.sector_count, 0)::numeric / 16.0) AS dim_sector_reach,
        -- Dimension 8: Protocol Reach (Cap 10)
        LEAST(1.0, COALESCE(pr.protocol_count, 0)::numeric / 10.0) AS dim_protocol_reach,
        -- Dimension 9: Incident Historical Volume (Cap 20)
        LEAST(1.0, COALESCE(ic.incident_count, 0)::numeric / 20.0) AS dim_incidents,
        -- Dimension 10: Campaign Recency (Exponential Decay)
        EXP(-0.005 * GREATEST(0, tc.days_since_active)) AS dim_recency,
        -- Dimension 11: EPSS Velocity (Cap 0.01 via 100x mult)
        LEAST(1.0, GREATEST(0.0, COALESCE(ep.epss_velocity, 0.0) * 100.0)) AS dim_epss_vel,
        -- Dimension 12: Geopolitical Tension Scalar
        LEAST(1.0, COALESCE(gp.tension_index, 0.0)::numeric) AS dim_geo_tension
    FROM seldon.threat_actors a
    LEFT JOIN seldon.actor_eic e ON a.actor_id = e.actor_id
    LEFT JOIN seldon.tacam_ttp_clusters kc ON a.actor_id = kc.actor_id
    LEFT JOIN seldon.tacam_temporal_clusters tc ON a.actor_id = tc.actor_id
    LEFT JOIN seldon.epss_aggregates ep ON a.actor_id = ep.actor_id
    LEFT JOIN seldon.technique_reach tr ON a.actor_id = tr.actor_id
    LEFT JOIN seldon.vendor_exposure ve ON a.actor_id = ve.actor_id
    LEFT JOIN seldon.sector_reach sr ON a.actor_id = sr.actor_id
    LEFT JOIN seldon.protocol_reach pr ON a.actor_id = pr.actor_id
    LEFT JOIN seldon.incident_corpus ic ON a.actor_id = ic.actor_id
    LEFT JOIN seldon.geopolitical_field gp ON a.attribution_nation = gp.nation_iso
)
SELECT 
    actor_id,
    actor_name,
    attribution_nation,
    sophistication_tier,
    -- Individual weighted components
    ROUND((dim_eic * 18.0)::numeric, 2) AS w_eic,
    ROUND((dim_killchain * 14.0)::numeric, 2) AS w_killchain,
    ROUND((dim_temporal * 8.0)::numeric, 2) AS w_temporal,
    ROUND((dim_epss_base * 10.0)::numeric, 2) AS w_epss_base,
    ROUND((dim_tech_reach * 10.0)::numeric, 2) AS w_tech_reach,
    ROUND((dim_vendor_exp * 10.0)::numeric, 2) AS w_vendor_exp,
    ROUND((dim_sector_reach * 5.0)::numeric, 2) AS w_sector_reach,
    ROUND((dim_protocol_reach * 5.0)::numeric, 2) AS w_protocol_reach,
    ROUND((dim_incidents * 5.0)::numeric, 2) AS w_incidents,
    ROUND((dim_recency * 5.0)::numeric, 2) AS w_recency,
    ROUND((dim_epss_vel * 5.0)::numeric, 2) AS w_epss_vel,
    ROUND((dim_geo_tension * 5.0)::numeric, 2) AS w_geo_tension,
    -- Final Composite ATQ Score
    ROUND((
        (dim_eic * 18.0) +
        (dim_killchain * 14.0) +
        (dim_temporal * 8.0) +
        (dim_epss_base * 10.0) +
        (dim_tech_reach * 10.0) +
        (dim_vendor_exp * 10.0) +
        (dim_sector_reach * 5.0) +
        (dim_protocol_reach * 5.0) +
        (dim_incidents * 5.0) +
        (dim_recency * 5.0) +
        (dim_epss_vel * 5.0) +
        (dim_geo_tension * 5.0)
    )::numeric, 1) AS composite_atq
FROM base_metrics;

CREATE UNIQUE INDEX idx_seldon_score_v2_actor ON seldon.seldon_score_v2(actor_id);

5. Downstream Systems Coupling: Monte Carlo Boltzmann Walk Engine#

The primary systems assurance application of the ATQ is parameterizing stochastic threat traversal in the Eigenia Cyber Digital Twin.

5.1 The Boltzmann Graph Walk Formulation#

When simulating threat propagation across an industrial network graph G=(V,E)\mathcal{G} = (\mathcal{V}, \mathcal{E}) comprising PLCs, SCADA servers, engineering workstations, and physical chillers, transition probabilities are modeled as a Boltzmann distribution:

P(u→v∣a)=exp⁡(−ΔE(u,v)kB⋅Teff(a))∑w∈N(u)exp⁡(−ΔE(u,w)kB⋅Teff(a))P(u \to v \mid a) = \frac{\exp\left( -\frac{\Delta E(u, v)}{k_B \cdot \mathcal{T}_{\text{eff}}(a)} \right)}{\sum_{w \in \mathcal{N}(u)} \exp\left( -\frac{\Delta E(u, w)}{k_B \cdot \mathcal{T}_{\text{eff}}(a)} \right)}

Where:

  • ΔE(u,v)\Delta E(u, v) represents the security barrier energy: defense-in-depth controls, firewall inspection latency, mTLS authentication, and air-gap separation.
  • Teff(a)\mathcal{T}_{\text{eff}}(a) represents the effective threat temperature, governed directly by the actor's ATQ:
Teff(a)=T0⋅(ATQa(t)100)γ⋅∏s∈Sectorsμs(a)\mathcal{T}_{\text{eff}}(a) = \mathcal{T}_0 \cdot \left( \frac{\text{ATQ}_a(t)}{100} \right)^{\gamma} \cdot \prod_{s \in \text{Sectors}} \mu_s(a)

Where:

  • γ≈1.85\gamma \approx 1.85 is the non-linearity exponent. The working group set it at 1.85 so that a top-decile actor's effective temperature separates clearly from a mid-band actor's. No fit against incident data produced the value and none is claimed for it; every effective temperature downstream carries that choice.
  • μs(a)∈[1.0,2.5]\mu_s(a) \in [1.0, 2.5] is the TACAM sector-affinity multiplier.

Under this formulation, an actor with an ATQ of 78.678.6 (Volt Typhoon) exhibits an effective temperature 2.8×2.8\times higher than an actor with an ATQ of 42.042.0. Consequently, high-ATQ adversaries overcome substantial cyber-physical security barriers (ΔE\Delta E) with high probability, penetrating deep into Layer 1/Layer 2 control networks.

Boltzmann propagation trajectory. The same topological barrier yields radically different transition probabilities depending on the actor's ATQ, because ATQ modulates the effective temperature TeffT_{\text{eff}} in the Boltzmann factor:

ActorATQEdge barrierΔE\Delta ETeffT_{\text{eff}}P(DMZ→SCADA)P(\text{DMZ} \rightarrow \text{SCADA})Outcome
Low-ATQ actor38.2Corporate DMZ to SCADA DMZ8.4 eV1.2 (baseline)0.012Defenses hold
Volt Typhoon (energy-sector affinity)78.6Corporate DMZ to SCADA DMZ8.4 eVsurges 1.2 to 4.80.684Breach imminent

5.2 Physical Process Coupling: Thermal Hydraulic Transients#

When a high-ATQ adversary successfully navigates the graph walk and establishes write-access to Layer 1/Layer 2 controllers, the operational outcome is governed by the physical plant thermodynamics. In high-density liquid-cooled computing facilities operating at 120 kW120\text{ kW} per rack, malware-induced volumetric flow cessation triggers catastrophic thermal runaway.

The rate of change of silicon junction temperature Tj(t)T_j(t) is governed by the transient convective energy balance:

dTj(t)dt=Pdie−hconv(Q˙vol)⋅Adie⋅(Tj−Tcoolant)Cthermal\frac{dT_j(t)}{dt} = \frac{P_{\text{die}} - h_{\text{conv}}(\dot{Q}_{\text{vol}}) \cdot A_{\text{die}} \cdot (T_j - T_{\text{coolant}})}{C_{\text{thermal}}}

Where:

  • Pdie=1,200 WP_{\text{die}} = 1{,}200\text{ W} dissipation per accelerator package, the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU. A compute tray carries four such packages together with two Grace CPUs and draws roughly 5.4 kW.
  • Q˙vol\dot{Q}_{\text{vol}} is the volumetric coolant flow rate (122 L/min122\text{ L/min} nominal per rack).
  • hconvh_{\text{conv}} is the convective heat transfer coefficient, which collapses toward zero during fluid stagnation.
  • Package heat flux is 75 W/cm275\text{ W/cm}^2 across the 1,600 mm21{,}600\text{ mm}^2 dual-die module.
  • Cthermal=800 J/KC_{\text{thermal}} = 800\text{ J/K} thermal capacitance of the stagnant cold plate assembly, dominated by the coolant retained in the channels once flow stops.

When flow halts, junction temperature surges at 1.46∘C/s1.46^\circ\text{C/s}. The emergency hardware shutdown trips when TjT_j reaches 94.0∘C94.0^\circ\text{C}, establishing a strict 15-second thermal trip cliff. The ATQ effective temperature translates directly into the probability that an adversary executes this command sequence before manual operator intervention can occur.


6. Financial and Actuarial Economics: Gordon-Loeb Capital Allocation#

The ultimate objective of quantitative threat modeling is providing boards of directors and insurance underwriters with mathematically defensible investment thresholds.

6.1 Gordon-Loeb Optimal Investment Bounds#

Under the classical Gordon-Loeb model, the optimal cybersecurity investment z∗z^* to defend an information set with asset value vv and vulnerability probability ss under potential loss LL is bounded by:

z∗≤1e⋅s⋅L≈0.368⋅s⋅Lz^* \le \frac{1}{e} \cdot s \cdot L \approx 0.368 \cdot s \cdot L

In the Eigenia actuarial architecture, the vulnerability probability ss is not a static assumption; it is the integrated breach probability computed by the Monte Carlo engine parameterized by ATQa(t)\text{ATQ}_a(t):

s(a)=∫0TmissionPbreach(t; Teff(ATQa)) dts(a) = \int_0^{T_{\text{mission}}} \mathcal{P}_{\text{breach}}\left( t; \, \mathcal{T}_{\text{eff}}(\text{ATQ}_a) \right) \, dt

Annualized Loss Expectancy (ALE\text{ALE}) is directly determined by the threat-weighted adversary pool:

ALEtotal=∑a∈A[ARO(a)⋅s(a)⋅SLE(a)]\text{ALE}_{\text{total}} = \sum_{a \in \mathcal{A}} \left[ \text{ARO}(a) \cdot s(a) \cdot \text{SLE}(a) \right]

Where:

  • ARO(a)\text{ARO}(a) is the Annualized Rate of Occurrence derived from Dimension 10 (Recency) and Dimension 12 (Geopolitical Tension).
  • SLE(a)\text{SLE}(a) is the Single Loss Expectancy encompassing physical equipment replacement, business interruption, and regulatory fines under EU CRA Article 64.

6.2 Worked Underwriting Case Study#

Consider an enterprise operating a 120 MW120\text{ MW} compute facility with $144,000,000 in physical asset exposure. When evaluated against the legacy three-factor model, threat pressure was categorized as "High", justifying a generic $4,000,000 perimeter upgrade.

When evaluated via the twelve-factor ATQ:

  • Volt Typhoon scored 78.678.6, with extreme affinity for the facility's specific Siemens SIMATIC S7-1500 controllers (CPE Dimension 6: 8.0/108.0/10) and electrical switchgear protocols (Dimension 8: 3.4/53.4/5).
  • Monte Carlo simulations revealed that Volt Typhoon's effective threat temperature breached perimeter defenses in 68.4%68.4\% of trials, inducing physical cooling stagnation (TjT_j reaching 94.0∘C94.0^\circ\text{C} in 14.8 seconds14.8\text{ seconds}).
  • Recomputed ALE\text{ALE} rose from $2,400,000 to $18,200,000.
  • The Gordon-Loeb optimal security investment z∗z^* shifted to:
z∗=0.368×0.684×$18,200,000=$4,579,000z^* = 0.368 \times 0.684 \times \$18{,}200{,}000 = \$4{,}579{,}000

Directing capital specifically to hardwired, autonomous SIL-3 emergency trip cutouts that physically isolate coolant pumps from network control, eliminating human latency and mitigating the threat path.

6.3 Reinsurance Underwriting, the Lloyd's Y5381 Exclusion, and ROSI#

In catastrophic property reinsurance, Lloyd's Market Bulletin Y5381, issued by the Corporation of Lloyd's on 16 August 2022, requires that stand-alone cyber-attack policies written or renewed from 31 March 2023 exclude losses arising from war and from state-backed cyber attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state; the Lloyd's Market Association's model clauses LMA5564 to LMA5567 (November 2021) are the wordings drafted to meet that requirement. Insurers evaluate Probable Maximum Loss (PML\text{PML}) across concentrated facility clusters:

PMLhall=∑k=1NracksCreplacement(k)+∫0TrestoreL˙BI(t) dt+Φregulatory\text{PML}_{\text{hall}} = \sum_{k=1}^{N_{\text{racks}}} C_{\text{replacement}}(k) + \int_0^{T_{\text{restore}}} \dot{L}_{\text{BI}}(t) \, dt + \Phi_{\text{regulatory}}

Where:

  • CreplacementC_{\text{replacement}} represents physical hardware replacement cost ($14,400,000 per 120-rack compute hall).
  • L˙BI(t)\dot{L}_{\text{BI}}(t) is the business interruption revenue loss rate ($24,000/hour).
  • Φregulatory\Phi_{\text{regulatory}} represents statutory penalties under EU CRA Article 64.

By running the ATQ through the penetration simulation and deploying deterministic SIL-3 physical trip controls (Ccontrols=240,000 USDC_{\text{controls}} = 240{,}000\text{ USD}), the insured cuts modeled breach probability from 0.6840.684 to 0.0120.012. That moves modeled ALE\text{ALE} from $18,200,000 to $410,000, giving a modeled Return on Security Investment (ROSI\text{ROSI}):

ROSI=(ALEunmitigated−ALEhardened)−CcontrolsCcontrols×100%=$17,790,000−$240,000$240,000×100%=7,312%\text{ROSI} = \frac{(\text{ALE}_{\text{unmitigated}} - \text{ALE}_{\text{hardened}}) - C_{\text{controls}}}{C_{\text{controls}}} \times 100\% = \frac{\$17{,}790{,}000 - \$240{,}000}{\$240{,}000} \times 100\% = 7{,}312\%

Every input to that quotient is the working group's: the 240,000 USD control cost, the two breach probabilities out of the simulation, and the 144,000,000 USD asset exposure the ALE is built on. The division is exact and reproduces to 7,312.5 percent, which is a statement about the arithmetic and not about the inputs. A reduction of this shape, once an operator has substituted its own asset values and its own control costs, is what lets underwriters waive restrictive sub-limit caps, lower policy deductible retentions from $10,000,000 to $2,500,000, drop consequential loss exclusions, and hold systemic accumulation exposure down. The percentage is the model talking; the placement is a negotiation.


7. Systems Assurance and Multi-BOM Traceability#

The ATQ model enforces full end-to-end normative systems assurance across cyber-physical infrastructure:

  • IEC 62443 Standards Alignment: Mapped to IEC 62443-3-2 risk assessment zones, Security Level Targets (SL-T 1 through SL-T 4), and SecRAC operational conditions.
  • Physical Topology Integration (DEXPI 2.0 / ISO 15926-4): Threat propagation graphs are anchored directly to XML piping and instrumentation schematics.
  • CycloneDX 1.6+ Multi-BOM Architecture:
    • HBOM (Hardware Bill of Materials): Silicon ASICs, power distribution units, and variable frequency drives (VFDs).
    • SBOM (Software Bill of Materials): Firmware digests, SCADA runtime binaries, and Modbus protocol stacks.
    • CBOM (Cryptographic Bill of Materials): Mutual TLS certificates, hardware root-of-trust identity keys, and DICE credentials.
    • OBOM (Operational Bill of Materials): Permissible physical operating envelopes (flow rate ≥35 L/min\ge 35\text{ L/min}, temperature ≤45∘C\le 45^\circ\text{C}).
    • VEX (Vulnerability Exploitability eXchange): Automated machine-readable threat advisories updating Dimension 4 and Dimension 11 in real-time.
  • Silicon Root-of-Trust Hardware: Caliptra 2.0 and OpenSIL integration providing cryptographic measurement registers and DICE attestation, establishing immutable supply chain provenance under EN 50126 reliability standards.

8. Interactive Console & Telemetry Terminal: ATQ Card#

To enable real-time operator inspection and dynamic adversary re-scoring, the complete twelve-factor mathematical model is rendered through the ATQ Interactive Card Terminal; accessible at /terminals/atq-card-terminal.html.

ATQ interactive card terminal architecture#

Location: /terminals/atq-card-terminal.html. Capabilities:

  1. High-assurance HUD view: 20-segment micro-LED bars for all 12 weights.
  2. TACAM 7D cross-match matrix: sector, protocol, CPE, and kill chain.
  3. 90-day trajectory sparkline: historical delta analysis across epochs.
  4. Raw ASCII console output: direct terminal export for CLI workflows.
  5. Production formula specification: mathematical table and data links.

8.1 Production Decomposed Telemetry Display#

The interactive terminal renders the auditable component decomposition for any profiled adversary:

VOLT TYPHOON · ATQ: 78.6 · Attribution: China / People's Republic of China · Sophistication: Advanced Persistent Threat

Component breakdown

ComponentWeightScore
EIC Score18%14.7 / 18
Kill Chain14%12.0 / 14
Temporal13%12.4 / 13
EPSS Base10%7.3 / 10
Technique Reach10%6.8 / 10
Vendor Exposure10%8.0 / 10
Sector Reach5%4.2 / 5
Protocol Reach5%3.4 / 5
Incident Count5%4.2 / 5
Campaign Recency5%4.8 / 5
EPSS Velocity5%0.4 / 5
Geo Tension5%0.3 / 5

TACAM cross-match

FieldValue
SectorEnergy (0.94), Water (0.71), Comms (0.83)
ProtocolsOPC-UA, Modbus, DNP3
Top CPE TargetsSiemens SIMATIC, Cisco IOS, Fortinet
Campaign RecencyActive (last 30 days)
Kill Chain12/14 tactics (missing: Exfiltration, Impact)

Trajectory (90-day)

MeasureValue
ATQ Δ+2.3 points ↑ (Epoch 228 → 234)
Driven byTemporal +1.4, EPSS vel +0.6, Recency +0.3
ForecastElevated through Q3 2026 (87% confidence)

The terminal allows operators to switch dynamically between profiled actors (including Sandworm, Lazarus Group, LockBit 3.0, and Scattered Spider), inspect individual mathematical weights, and export standardized JSON payloads to downstream security orchestrators.


9. Comparative Evaluation: Industry Benchmarks vs. Eigenia ATQ#

To validate the methodological rigor of the ATQ, it is benchmarked against established commercial and open-source threat intelligence rating frameworks:

Evaluation DimensionTraditional Commercial TI (Mandiant, CrowdStrike)CVSS / EPSS Base FeedsMITRE ATT&CK MatrixEigenia ATQ Specification
Measurement TypeQualitative narrative / nominal tiersVulnerability-centric probabilityCategorical behavioral ontologyMulti-factor cardinal scalar ([0,100][0, 100])
Component AuditabilityProprietary black boxUnidimensional logistic regressionTTP checklist without weights12 auditable SQL-materialized columns
Temporal DynamicsPeriodic PDF reportsDiurnal score refreshVersioned releases (bi-annual)Diurnal epoch snapshots with delta tracking
Downstream SimulationManual analyst interpretationPrioritization filtersThreat mappingDirect Boltzmann random-walk parameterization
Financial TranslationSubjective risk heatmapsNoneNoneGordon-Loeb optimal investment & ALE bounds
Operational TechnologyLimited IT/OT convergencePrimarily IT software CVEsDedicated ICS matrixFull TACAM protocol & CPE physical mapping

10. Conclusion: From Threat Narrative to a Stated Model#

The Adversary Threat Quotient resolves the measurement problem in modern cybersecurity. By grounding threat actor evaluation in twelve dimensions, each with a named data source and a stated saturation bound, continuously refreshed against live telemetry and weaponization feeds, the ATQ replaces the nominal labels of traditional threat intelligence with a number whose construction can be argued with. The weights are the working group's actuarial judgment, stated in section 2.1 so a reader can disagree with a specific one rather than with the whole score.

When coupled to physical facility digital twins through DEXPI 2.0 piping schematics and Boltzmann random-walk graph traversals, the ATQ bridges the chasm between threat actor capabilities and thermodynamic consequences. Security leaders and reinsurance underwriters are equipped with an auditable, cardinal measurement that translates raw threat data into deterministic engineering controls and mathematically optimal capital investments.


11. References#

McKenney, J. (2026). The TACAM Matrix: Spectral Decomposition and Adversary Threat Quotients in Industrial Control Systems. Eigenia Research Working Group 07 Treatise WG-07-TM-TACAM.

The per-accelerator power figure in section 5 is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet. The four-GPU, two-Grace-CPU compute tray composition given in the same section is NVIDIA's own, from the NVIDIA Mission Control Systems Administration Guide, FAQ, docs.nvidia.com/mission-control/docs/systems-administration-guide/2.0.0/prs/faq.html.

Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 33,158 chars