Skip to content
← Threat modelling and risk for people at risk

Lesson 1 of 4 · 8 min

Adversaries and their motives

Who actually targets NGOs, lawyers and journalists, what each kind of adversary wants, and why that changes what you should protect.

Security advice that starts with tools before people usually goes wrong. The Electronic Frontier Foundation’s Surveillance Self-Defense guide puts the right question first: not “what should I install”, but “who do I want to protect [my information] from”. An adversary is, in its words, “a person or entity that poses a threat to your assets”. Before choosing any protection, it helps to name who you are actually up against, because an NGO worker, a defence lawyer and an investigative journalist rarely face the same one.

What separates one adversary from another

The NCAE-C Cyber Threats knowledge unit organises threat actors around what it calls an adversary model: their resources, capabilities, intent, motivation, tolerance for risk, and the access they already have. Two attackers who both want your password can look completely different once you ask those questions. A credit-card thief has money as the goal, modest skills, and will move on to an easier target the moment you look expensive to attack. A government intelligence service has patience, engineers, legal cover, and no reason to give up.

Four adversaries at-risk people commonly face

A simplified adversary model. Real cases often combine more than one row.
AdversaryWhat they wantTypical access and methods
Financially motivated criminalsMoney: ransom, stolen banking details, resale of accountsMass phishing, credential stuffing from breached password lists, harmful attachments
An abusive partner or stalkerLocation, control, evidence of “disloyalty”Shared accounts and devices, guessed or observed passwords, stalkerware apps, family-plan visibility
Commercial surveillance and data brokersProfit from your data: location history, contacts, behaviourSoftware development kits inside ordinary apps, ad identifiers, data purchased and combined across companies
State and state-linked actorsSuppress reporting, identify sources, monitor dissentTargeted messages, exploitation of unpatched software, legal or physical pressure, network-level surveillance

Why the same behaviour means different risk for different people

An NGO documenting abuses, a lawyer holding a client’s asylum file, and a journalist protecting a source all handle information that would harm someone if it leaked, but the person it would harm and the adversary who wants it differ. For the NGO, a state actor or a hostile local group may want the identities of witnesses. For the lawyer, the client’s own opposing party or an unfriendly government may want the file. For the journalist, the source’s employer or a state security service may want to know who talked. Access Now, which runs a Digital Security Helpline for “civil society groups, journalists, bloggers, human rights defenders, and activists”, sees this pattern across the cases it handles: the tool that matters is the one that answers the specific threat, not a generic list of “best practices”.

Insiders and low-skill attackers still matter

The Cyber Threats knowledge unit also names two categories that are easy to underestimate: the insider threat (someone with legitimate access who misuses it) and the “script kiddie”, an attacker with limited skill running tools built by others. A disgruntled volunteer with your donor database, or a former partner who still knows your unlock code, can do as much damage as a more sophisticated actor, and are statistically far more likely to be the one who actually acts.

Naming the adversary changes what you do next

EFF’s Surveillance Self-Defense frames the payoff plainly: once you know who you are protecting information from, you can decide “how much trouble you are willing to go through” to defend it, and where that effort is wasted. A lawyer worried about opposing counsel subpoenaing emails needs different habits than one worried about a state intercepting calls. The next lesson in this course follows a specific adversary’s attack from the first message to the goal; the one after it turns “who might target me” into a repeatable way of weighing likelihood and impact.

Key takeaways

  • An adversary is anyone with a reason to threaten what you value; name them before choosing defences.
  • The adversary model — resources, capabilities, intent, motivation, risk tolerance, access — explains why the same attack means different risk for different people.
  • Financially motivated criminals, abusive partners, commercial data brokers, and state actors pursue different goals with different methods.
  • Insiders and low-skill attackers are common and often more likely to act than a sophisticated adversary.
  • Specialised help exists: Access Now’s Digital Security Helpline and Freedom of the Press Foundation both work with people facing these exact adversaries.

Check yourself

  1. 1. According to EFF’s Surveillance Self-Defense guide, what should come before choosing a security tool?

    • Reading reviews of the most popular app
    • Naming who you are protecting your information from — Right.
    • Buying the most expensive option available
    • Asking a friend what they use

    The guide’s security-planning questions start with what you want to protect and who you want to protect it from, since that determines which tools make sense.

  2. 2. Which factor is NOT part of the adversary model described in the Cyber Threats knowledge unit?

    • Resources and capabilities
    • Intent and motivation
    • Tolerance for risk
    • The brand of antivirus software installed — Right.

    The adversary model concerns the attacker’s resources, capabilities, intent, motivation, risk aversion and access — not the defender’s specific software.

  3. 3. Why does an insider threat deserve attention alongside sophisticated attackers?

    • Insiders never cause real damage
    • Someone with legitimate access who misuses it can be as damaging, and is often more likely to act — Right.
    • Only large organisations have insiders
    • Insiders are always malicious from day one

    Legitimate access removes many of the barriers a sophisticated attacker has to work around, and insider situations (a former partner, a disgruntled volunteer) are common in practice.

Do it with FireAI

Put this lesson into practice on your own Mac.

Sources

Put it into practice on your Mac

Try every feature free for 17 days, no card needed.

Download for Mac Docs