Threat landscape
A picture of the kinds of threats a company could face right now, and who or what is behind them.
Draft - this entry has not been reviewed yet.
Formal
The current picture of which threats are active against an organisation, its sector or country, including the likely attackers, their methods and how these are changing.
In plain English
Like a weather forecast for danger, telling you whether to expect rain, storms or a heat wave in the weeks ahead.
In practice
Before the yearly risk review, the IT lead at a small manufacturer reads the latest threat assessment from the Danish Resilience Agency (SAMSIK) and brings the threats it rates highest into the review.
Why it matters
Risks can only be judged against the threats that actually exist, so an outdated picture leads to protecting against yesterday's attacks.
Technical deep dive
A threat landscape is an aggregate, periodic picture rather than a feed. It is usually described at several levels: global and regional reports such as ENISA's annual Threat Landscape, national assessments, sector-specific assessments from sector CERTs or ISACs, and finally the organisation's own view, which filters the others through its sector, geography, technology stack and visibility. The organisation-level view is what ISO/IEC 27001:2022 clause 4.1 expects to be considered among external issues and what feeds likelihood estimates in the risk assessment; NIS2 Art. 21(2) adds that measures must follow an all-hazards approach, so the landscape should include accidental, technical and physical threats and not only hostile actors.
In Denmark the reference is the annual assessment Cybertruslen mod Danmark, published since 2016, first by the Centre for Cyber Security (CFCS) and, from the November 2025 edition, by Styrelsen for Samfundssikkerhed in close cooperation with, among others, the Danish Defence Intelligence Service. It uses a five-level scale, INGEN, LAV, MIDDEL, HØJ and MEGET HØJ, per purpose category. The 2025 edition kept cybercrime and cyber espionage at MEGET HØJ, cyber activism at HØJ, destructive cyber attacks at MIDDEL and cyber terrorism at INGEN, and for the first time organised the analysis around six attack types: ransomware, data theft, digital fraud, DDoS, manipulation of operational technology and wiper attacks. Such levels change between editions, so any register citing them should record the edition used.
A national threat level describes actors' intent and capability against the country as a whole; it is not a likelihood for a specific organisation. Translating it into risk requires asking which actors have a reason to target this organisation or will hit it opportunistically, which techniques they use, and which of the organisation's exposures match those techniques. Vendor reports such as Verizon's Data Breach Investigations Report or incident-response firms' annual reviews add useful statistics on initial access vectors and dwell times, but reflect the vendor's own customer and case sample, so they are indicative rather than representative.
The landscape differs from threat intelligence in time scale and purpose: the landscape is a strategic snapshot used for risk assessment, planning and board communication, typically refreshed annually; intelligence is the continuous, requirement-driven flow of analysed information that updates the snapshot and drives detection and response. An outdated landscape is a common reason why risk registers keep rating last decade's threats while missing current patterns such as edge-device exploitation, MFA fatigue or supply-chain compromise.
What to learn first
Everything this builds on, foundations first.
- Threat
- →Threat landscape
Relationships
- Part of
- Risk management
- Consists of
- Threat actor
- Requires
- Threat
- Don't confuse with
- Attack surface
Sources & further reading
Standards & official texts
- ISO/IEC 27005:2022
Official documentation
- Cybertruslen mod Danmark 2025 (trusselsvurdering, november 2025) · Styrelsen for Samfundssikkerhed
Course material
- Cyber Security Fast Track - Ordliste
Where this data comes from
This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.
See the review queueSuggest a correction on GitHubThis term as JSON
Check yourself
Loading…