Updated: 6 July 2026
What are APT threats and why do they affect private companies? An Advanced Persistent Threat (APT) is an advanced, long-term cyberattack conducted by highly motivated attackers, usually state-sponsored groups or organised criminal groups with quasi-state characteristics. Historically, APT activity was associated mainly with government targets and critical infrastructure.
Since 2020, however, APT groups have systematically targeted private companies in finance, energy, technology, defence, and healthcare. Sometimes the company is the direct target, for intellectual property theft or sabotage. Sometimes it is a route into the real target through the supply chain, as SolarWinds showed. For a private company, the right question is not “is APT a real threat?” but “what is our geopolitical risk profile, and what can we realistically do?”
Geopolitical cyber risk – key takeaways:
- ENISA Threat Landscape 2024 lists state-sponsored attacks among the most serious vectors for the private sector, especially in finance, energy, and technology
- Companies that subcontract for or supply the defence or government sector are attractive APT targets as routes into the real target, a tactic often called “island hopping”
- APT groups often have access to zero-day exploits that bypass signature-based security controls, making antivirus-only protection insufficient
- Long dwell time is a key difference between APT and ordinary ransomware: attackers may remain inside the network for months before detection; Kyivstar is a classic example, with 7 months of presence
- Cyber resilience for private companies exposed to APT risk is not only prevention, but detection and response – an assumed breach mentality
- Patronusec, in the vCISO role, helps private companies assess their geopolitical risk profile and implement controls proportionate to budget and threat level
Table of Contents
How can I assess whether my company is a potential APT target?
Not every company is attractive to state-sponsored APT groups. A geopolitical risk profile helps keep the response realistic.
Factors that increase APT risk:
Sector: Energy, finance, telecommunications, healthcare, defence technology, semiconductor manufacturing, aviation, and pharmaceuticals are systematically targeted by APT groups. Retail and hospitality are much less attractive APT targets unless they process large volumes of payment data. In that case, financially motivated cybercrime is usually the more likely threat.
Access to valuable IP: Companies that hold trade secrets, patents, or advanced technology are attractive intelligence targets. Examples include pharmaceutical research, military software, and advanced manufacturing technology.
Government or defence links: Subcontractors for government, military, or critical infrastructure organisations are targeted as routes into the real target.
Geography and market exposure: Companies operating in countries or regions actively targeted by specific APT groups, such as Ukraine and NATO countries by Russian groups or Taiwan by Chinese groups, carry higher risk.
APT risk levels:
| Company profile | APT risk level | Recommended actions |
|---|---|---|
| Small companies outside critical sectors | Low | Standard security hygiene, backup, patch management |
| Mid-sized companies in finance or energy | Medium | EDR, MFA, monitoring, threat intelligence |
| Companies with high-value IP or government links | High | Extended monitoring, hunt team, segmentation, IR plan |
| Critical infrastructure suppliers | Very high | Threat-led programme, TLPT, NIS2/DORA compliance |
Patronusec Insight: Companies often ask “is APT our threat?” when they really mean “are we important enough?” The better question is: “are we an attractive component in someone else’s attack?” A small technology company serving a large financial institution can be a highly attractive APT target – not because of its own data, but because of client access. Island hopping is a real tactic. We assess geopolitical risk profile as part of the vCISO service, and the results help calibrate budget and priorities.
Which APT tactics are most dangerous for private companies?
APT groups use techniques that bypass standard security controls, which is what differentiates them from ordinary cybercrime.
Living off the Land (LotL):
Instead of deploying malware that antivirus tools could detect, APT groups use legitimate system tools such as PowerShell, WMI, PsExec, and certutil. Administrators use these tools every day, so standard security products often do not block them. Detecting LotL activity requires behavioural monitoring and anomaly detection, not signatures.
Spear phishing and BEC:
APT groups do not rely on mass phishing. They send precisely targeted messages to specific people, based on OSINT from LinkedIn, public records, and social media. The message may impersonate a colleague, client, or partner using a credible pretext.
Zero-day exploits:
State-sponsored APT groups may have access to exploits for unknown vulnerabilities, or they may exploit newly published vulnerabilities before patching is complete. This means patching alone cannot be the only protection strategy.
Supply chain infiltration:
As SolarWinds showed, APT groups attack software and service providers to reach customers through a trusted channel. This requires security verification of key suppliers.
Long dwell time:
APT groups aim for long-term presence rather than immediate activation. Median dwell time for advanced actors can be weeks or months. During that time, attackers map the environment, escalate privileges, and identify valuable data. Sandworm’s presence in Kyivstar for 7 months before detonation is a clear example.
Do you want to assess whether your organisation is exposed to geopolitical cyber risk and what you can do about it?
Patronusec conducts threat assessments: risk-profile reviews and recommendations aligned with threat level and budget. The output is a prioritised action plan, not a list of every possible threat.
How should a private company approach APT protection with a realistic budget?
Full protection against advanced APT groups is beyond reach even for governments. The realistic goal is to raise the cost of attack, shorten detection time, and have a plan for breach scenarios.
Assumed breach mentality:
Instead of asking “how do we avoid being attacked?”, ask “what do we do if the attacker is already in the network?” This means network segmentation to reduce blast radius, behavioural monitoring to detect anomalies rather than only signatures, an exercised incident response plan, and backups isolated from the production network.
Risk-based prioritisation:
You cannot protect everything equally. Identify the crown jewels: what the attacker values most, such as customer data, intellectual property, or access to key systems. Focus resources on protecting those assets.
Threat intelligence:
Threat intelligence subscriptions, including free sources such as CERT Polska, ENISA, and US-CERT, provide context on active APT groups and their TTPs. Current threat intelligence helps prioritise detection rules and hunting activity.
Controls aligned with budget:
| Priority | Control | Cost | Impact |
|---|---|---|---|
| 1 | MFA for all accounts, especially privileged accounts | Low | Very high |
| 2 | EDR with behavioural detection | Medium | High |
| 3 | Network segmentation, with microsegmentation for crown jewels | Medium-high | High |
| 4 | Privileged Access Management (PAM) | High | High |
| 5 | Central SIEM with detection rules for APT TTPs | High | High |
| 6 | Tabletop exercise for an APT scenario | Low | Medium |
FAQ – Geopolitical Cyber Risk and APT
Can a small company be targeted by an APT group?
Yes, if the company is a subcontractor or has access to systems belonging to a large institution, government body, or critical infrastructure operator. Island hopping means attacking the weaker link in the supply chain as a route into the real target. A small IT company serving a bank may have far higher risk than its size suggests.
How is APT different from ordinary ransomware?
Ransomware is usually an opportunistic, financially motivated attack. Attackers look for weak targets and encrypt data for payment. APT is a targeted, long-term attack motivated by intelligence gathering, sabotage, or IP theft. The attacker invests time and resources in a specific target and does not necessarily act immediately after gaining access.
Which security standards best protect against APT?
No standard guarantees protection against a sufficiently advanced attacker. NIST CSF, ISO 27001, and CIS Controls provide frameworks that reduce risk. For companies with a high geopolitical risk profile, NIST CSF with stronger Respond and Recover capabilities, regular TLPT or red team testing, and a threat intelligence programme are recommended.
Does cyber insurance cover the consequences of an APT attack?
Many cyber policies include exclusions for acts of war or terrorism, which may be interpreted to include state-sponsored attacks. After NotPetya in 2017, several companies discovered that their policies did not cover losses. Before buying a policy, review the cyber warfare exclusion and whether state-sponsored attacks are excluded.
What does a professional threat assessment cost at Patronusec?
A threat assessment includes geopolitical risk profiling, crown jewel mapping, a review of current controls, and recommendations prioritised by risk and budget. Patronusec prices the service after a free introductory call. In the vCISO model, threat intelligence and risk assessment are part of the ongoing service.
How does NIS2 relate to APT threats?
NIS2 requires essential and important entities to manage cybersecurity risk, including geopolitical risk and state-sponsored attacks. Article 21 requires risk management measures covering network security, incident management, and business continuity. Threat intelligence and red team testing are increasingly recommended by regulators as evidence of security programme maturity.
Geopolitical cyber risk – free consultation
Patronusec helps organisations in finance, technology, and critical infrastructure assess and manage geopolitical cyber risk, from threat assessment and control implementation to threat-led testing programmes such as TLPT.
In a free 30-minute consultation, we will help you:
- Assess your organisation’s geopolitical risk profile based on sector, business model, and dependencies
- Identify crown jewels and key gaps in protection against advanced attackers
- Plan priorities and budget aligned with APT threat level
- Discuss support options: threat intelligence, red team, TLPT, or ongoing vCISO
Free consultation | vCISO – risk management | Penetration testing and TLPT | Vulnerability scans | NIS2