Home  /  Services  /  Threat tiers and assurance

Threat tiers and assurance

Two worlds exist at the same time. In one, using standard certified technology is the correct answer and the licence to operate. In the other, standard certified technology is the thing a capable adversary has already shaped. Most advisors only work in one of them.

TIER 1TIER 2-3TIER 4PROPORTIONATE CONTROLSTIERADVERSARY CLASSCLASSIFIED · NATO · EU · NATIONAL LAWTIER 1 · SHAPES THE TECHNOLOGYSENSITIVE · NIS2 · GDPRTIER 2-3 · ATTACKS THE TECHNOLOGYNON-SENSITIVE · GENERAL BUSINESSTIER 4 · COMMODITYINTELLIGENCE AND DEFENCEDESIGNED IN, NOT BROKEN INCRITICAL INFRASTRUCTURE · FINANCE · HEALTHMUST FIND A WAY INPERSONAL AND ROUTINE COMMUNICATIONTAKES WHAT IS LEFT OPENTHE AXIS IS POSITION, NOT HOSTILITY. TIER 1 CAN INFLUENCE WHAT IS BUILT; TIER 2-3 MUST ATTACK IT FROM OUTSIDE.Sovereign and custom cryptographyHardened high-assurance endpointsHardware-enforced separationAuditable, source-available stacksCustomer-generated and held keysMetadata-resistant communicationsCertified standard cryptographyPhishing-resistant authenticationSegmentation and monitoringDetection, forensics and responseStandard managed servicesMulti-factor authenticationEndpoint protection and hygieneAble to influence what gets built:standards participation, strategicinvestment, and jurisdiction overthe vendors themselves.State-sponsored groups andorganised crime, operating fromoutside the supply chain.Criminals, hacktivists, phishers.Opportunistic and volume-driven.

Threat tier model · Arimo Koivisto

The tension

The same decision is right in one world and wrong in the other

For most organisations, using standard, certified, widely adopted technology is not merely acceptable — it is the correct answer. It is what ISO 27001 expects, what auditors recognise, what suppliers support, and what the market has tested. Departing from it without cause is how you end up with bespoke cryptography nobody has reviewed.

At the top tier the calculation inverts. If the adversary you are defending against is one that participates in standards work, invests in the vendors, and holds legal jurisdiction over the companies that write your operating system, then “widely adopted and certified” describes their reach rather than your protection.

Neither position is a general truth. Which one applies is a function of what you hold and who wants it — which is precisely the assessment worth paying for.

What this changes in practice

Key generationWho creates them
Key custodyWho can be compelled
JurisdictionWhose law reaches the vendor
Supply chainWhose silicon and firmware
AuditabilityCan it be read, not just trusted
MetadataWhat leaks when content does not

Why the top tier is a different problem

Capability that is designed in, not broken in

The distinction the model draws is not about which countries are hostile. It is about which actors are structurally positioned to influence the technology itself, and that is a matter of public record rather than speculation.

Crypto AG. Reporting in 2020 established that the Swiss manufacturer selling encryption equipment to roughly 120 governments had been secretly owned by the CIA and the German BND. Customers who believed they were buying neutrality were buying the opposite, for decades.

Dual_EC_DRBG. A NIST-standardised random number generator, widely assessed to have contained a deliberate weakness, withdrawn in 2014. The standards process was subsequently reopened — an admission in itself.

NOBUS. “Nobody But Us”: the doctrine that a vulnerability may reasonably be left in place if you assess that only you can exploit it. Once that is a stated principle, “no known exploit” and “no exploit” stop being the same claim.

Strategic investment. In-Q-Tel, the CIA’s investment arm, is public and openly described. Capability arrives through ownership and influence as readily as through intrusion.


Set against that, an actor without jurisdiction over the dominant operating systems, cloud platforms and silicon has to do something harder and noisier: find a way in from outside. That is a serious threat, and it is a different threat, and it is defeated by different controls. Collapsing both into “nation-state actor” is how organisations end up buying the wrong protection.

A worked question

Encrypted content is not the same as private communication

Strong content encryption is freely available in consumer messaging, while comparable proprietary systems fall under export control through the Wassenaar Arrangement and national implementations. That asymmetry is real and documented.

It is also explicable without conspiracy. Consumer messengers encrypt content. They do not encrypt the fact that you spoke, to whom, from where, how often, and in what pattern. For intelligence purposes that metadata is frequently the product, not the residue — which is why an organisation whose exposure is relational rather than textual gets very little from adopting a consumer messenger, however good its cipher.

This is the kind of question the tier model exists to force. Not “is the encryption strong”, but “what does this system still reveal, to whom, and under whose law”.

Where this applies

Most organisations are Tier 2. Some are not.

If your exposure is regulatory and criminal, the standard answer is the right one and we will tell you so. If it is not, the assessment needs to start somewhere else entirely. Establishing which of those you are is usually a short piece of work.

Discuss an assessment