Victimology in CTI: How to Decide Who Is Most Likely to Be Targeted
Analyze victim selection without confusing public visibility with adversary preference, then turn the pattern into a defensible warning decision.
Victimology asks why certain organizations, people, technologies, or locations appear in threat activity and who may be next. The answer should help a defender prioritize exposure checks, warn a business unit, or challenge an assumption about targeting.
Begin with observed victims, not an actor stereotype. Separate intended targets from opportunistic compromises, intermediaries, collateral impact, and organizations that simply disclosed more. A pattern is useful only when the collection bias behind it is visible.
Describe Victims With Decision-Relevant Features
Record geography, business function, technology, size, ownership, suppliers, data, public profile, access path, operational calendar, and the role each victim plays in a wider ecosystem. Use consistent fields, but allow a new feature when cases do not fit.
Compare targeted and apparently untargeted peers. If every organization in a sector uses the same vulnerable appliance, technology may explain the pattern better than sector. Do not turn an easy database field into the adversary’s motive.
Correct for What You Cannot See
Map how each case became known: victim disclosure, regulator, leak site, telemetry, partner, or news report. Estimate which populations your sources cover and which they miss. One region may look safe because your team has no language coverage there.
Label duplicates and exclude cases whose victim status is unverified. Use rates only when the denominator is credible. Otherwise describe the observed pattern and its limitations instead of claiming prevalence.
Turn the Pattern Into a Bounded Warning
State which population appears more exposed, the likely selection mechanism, confidence, and time horizon. Then identify observable changes: new geography, new access broker, expansion to a supplier role, or activity around a business event. Assign owners to watch them.
Recommend a discriminating action—validate a technology footprint, brief a subsidiary, add telemetry, or contact a supplier. Reassess when new victims break the pattern. The broader threat relevance test helps translate the result for your own environment.
Keep the Human Choice Visible
Victims are not rows in an actor scorecard. Explain uncertainty without implying that a targeted organization caused its own compromise. Preserve source sensitivity and avoid publishing details that increase harm.
A strong victimology assessment tells a specific audience why its exposure resembles or differs from observed cases and what it can decide now. That is a warning product, not a list of names.
Frequently asked questions
Is sector the most important victimology factor?
Not always. Technology, business role, geography, access, data, timing, or supply-chain position may explain selection better than an industry label.
Can public victim lists show true targeting frequency?
Rarely on their own. Disclosure rules, ransom-site behavior, media interest, detection capability, and language coverage all distort what becomes visible.
Can a small victim sample support a warning?
Yes if the evidence is distinctive and the warning is carefully bounded, but confidence and alternative explanations must remain explicit.
How can analysts infer why a victim was selected?
Compare objectives, accessible assets, timing, business dependencies, data value, and attacker actions across cases rather than assuming motive from victim identity.
What should a victimology assessment recommend?
It should identify exposed populations, priority checks or controls, warning indicators, confidence, and the evidence that would change the targeting judgment.