Home / Services / Threat tiers and assurance
Threat tiers and assurance
Two worlds exist at the same time. In one, using standard certified technology is the correct answer and the licence to operate. In the other, standard certified technology is the thing a capable adversary has already shaped. Most advisors only work in one of them.
Threat tier model · Arimo Koivisto
The tension
The same decision is right in one world and wrong in the other
For most organisations, using standard, certified, widely adopted technology is not merely acceptable — it is the correct answer. It is what ISO 27001 expects, what auditors recognise, what suppliers support, and what the market has tested. Departing from it without cause is how you end up with bespoke cryptography nobody has reviewed.
At the top tier the calculation inverts. If the adversary you are defending against is one that participates in standards work, invests in the vendors, and holds legal jurisdiction over the companies that write your operating system, then “widely adopted and certified” describes their reach rather than your protection.
Neither position is a general truth. Which one applies is a function of what you hold and who wants it — which is precisely the assessment worth paying for.
What this changes in practice
Why the top tier is a different problem
Capability that is designed in, not broken in
The distinction the model draws is not about which countries are hostile. It is about which actors are structurally positioned to influence the technology itself, and that is a matter of public record rather than speculation.
Crypto AG. Reporting in 2020 established that the Swiss manufacturer selling encryption equipment to roughly 120 governments had been secretly owned by the CIA and the German BND. Customers who believed they were buying neutrality were buying the opposite, for decades.
Dual_EC_DRBG. A NIST-standardised random number generator, widely assessed to have contained a deliberate weakness, withdrawn in 2014. The standards process was subsequently reopened — an admission in itself.
NOBUS. “Nobody But Us”: the doctrine that a vulnerability may reasonably be left in place if you assess that only you can exploit it. Once that is a stated principle, “no known exploit” and “no exploit” stop being the same claim.
Strategic investment. In-Q-Tel, the CIA’s investment arm, is public and openly described. Capability arrives through ownership and influence as readily as through intrusion.
Set against that, an actor without jurisdiction over the dominant operating systems, cloud platforms and silicon has to do something harder and noisier: find a way in from outside. That is a serious threat, and it is a different threat, and it is defeated by different controls. Collapsing both into “nation-state actor” is how organisations end up buying the wrong protection.
A worked question
Encrypted content is not the same as private communication
Strong content encryption is freely available in consumer messaging, while comparable proprietary systems fall under export control through the Wassenaar Arrangement and national implementations. That asymmetry is real and documented.
It is also explicable without conspiracy. Consumer messengers encrypt content. They do not encrypt the fact that you spoke, to whom, from where, how often, and in what pattern. For intelligence purposes that metadata is frequently the product, not the residue — which is why an organisation whose exposure is relational rather than textual gets very little from adopting a consumer messenger, however good its cipher.
This is the kind of question the tier model exists to force. Not “is the encryption strong”, but “what does this system still reveal, to whom, and under whose law”.
Where this applies
Most organisations are Tier 2. Some are not.
If your exposure is regulatory and criminal, the standard answer is the right one and we will tell you so. If it is not, the assessment needs to start somewhere else entirely. Establishing which of those you are is usually a short piece of work.
