After a noisy weekend ransomware hit on a library public PC, staff start calling every attacker an "APT." How should the civic SOC correct that mix-up?
Select an answer to reveal the explanation.
Short Explanation
APT is a reserved parking spot, not the name of every dented bumper. A smash-and-grab on a library public PC is still a threat actor — just not an advanced persistent one. Keep "APT" for capable, long-haul adversaries and use the generic words the rest of the time.
Full Explanation
APT is a subset of threat actors: capable and persistent, not a synonym for every civic incident. Inflating a weekend ransomware hit on a library kiosk into APT language misleads leadership and wastes hunt effort on nation-state playbooks. Zero trust is a defensive model, and C2 is a channel, not a substitute actor label. Defense Analysts should default to threat actor or adversary, then promote the APT label only when sophistication and dwell support it.