Why You Are a Target
Motivations, methods and the value of access.
12 min
The common belief that causes breaches
“We are too small to be a target.” Most attacks are not targeted at all. Automated tools scan the entire internet for exposed services and weak credentials, and phishing is sent in volume to millions of addresses. Being small removes you from nobody’s list; it usually just means weaker defences.
Even in a targeted attack, the initial entry point is rarely a senior executive. It is whoever clicks first — and smaller suppliers are routinely attacked as a route into the larger organisations they work with.
Who attacks and why
- Organised criminals — money, by extortion, fraud or selling stolen data. The overwhelming majority of activity.
- Opportunists — using automated tools against whatever is exposed.
- Insiders — deliberate, through grievance or gain, and far more often accidental.
- Competitors and industrial espionage — commercial information, tenders, designs.
- State-aligned actors — intelligence and disruption, mainly in critical infrastructure, energy, defence and government supply chains.
- Activists — disruption and publicity.
What they want
- Credentials — a working username and password is the most valuable item, because it turns an attack into a login.
- Money — invoice fraud, payment redirection, ransom.
- Personal data — saleable, and expensive for you in regulatory terms.
- Commercial information — bids, pricing, designs, contracts.
- Access itself — to reach a customer, a supplier, or to resell.
- Computing resources — for mining, spam or onward attacks.
How attacks typically unfold
- Reconnaissance — public websites, social media, job adverts revealing which systems you run, and out-of-office replies.
- Initial access — phishing, stolen credentials, an unpatched internet-facing system, or a compromised supplier.
- Establishing a foothold — malware, or simply using the stolen credentials quietly.
- Escalation and movement — gaining higher privileges and moving across the network, often over weeks.
- Action — data theft, encryption for ransom, or fraudulent payment.
Ransomware
Ransomware encrypts data and demands payment, now almost always combined with stealing the data first and threatening publication, so that backups alone do not resolve it. The operational impact is usually worse than the data impact: systems unavailable for weeks, manual working, and disrupted customers and suppliers. Prevention rests on the ordinary controls — patching, multi-factor authentication, least privilege, segregation and tested offline backups — not on anything exotic.
Where the human fits
A large majority of breaches involve a human element: a click, a reused password, a misdirected email, a misconfiguration. This is not an argument that people are the weak link. People are the control that generalises — the one that notices the thing no system was configured to catch. The purpose of awareness is to make that control reliable, and that requires a culture where reporting is welcomed rather than punished.