TLCTC is the Rosetta Stone for Cyber Risk.
10 logically‑derived, non‑overlapping cyber threat clusters that connect strategic cyber risk & -security management, operational security, and secure development into one common language.
TLCTC is a free & open framework. No paywalls, no certifications to buy, no consulting funnel. Built to be used, challenged, and evolved by the community.
Licensed under CC BY 4.0 · Attribution required, commercial use permitted.
Short Video Explainer to connect easier
Bridging Strategy, Operations & Development
Three domains speak different dialects. TLCTC is the shared reference that closes the gaps between them.
From Cause to Consequence
Seven moves from a threat’s root cause to the metric your board understands.
The Dual-Layer Bow-Tie: One Event, Two Altitudes
The strategic layer speaks clusters and risk appetite. The operational layer speaks TTPs and data risk events. Same pivot, two readings — one consistent bridge.
The Asset in Context: What Actually Gets Compromised
Eight layers narrow from region down to the product instance — version and configuration item, where CVEs attach — to name the asset. Actors apply the threats — but neither the context stack nor the actor is a classification input. The cause–event–consequence line stays the same either way.
Not Every Compromise Becomes a Business Risk
Risk events stack in three layers. A System Risk Event escalates only if data is affected; a Data Risk Event escalates only if the business is affected. Root causes act horizontally at each altitude — the chain rises vertically.
Two provenances meet at the same altitude: a System Failure has no attacker, a System Compromise has one of the ten clusters behind it. From there the chain is identical — and it stops the moment a gate does not open.
Naming note. The second Integrity refinement is the misattributed state (If: provenance or attribution fails; the content may be perfectly accurate) since TLCTC v2.5, 2026-09-05. Earlier versions of this figure called it the “fraudulent state”; the state is told apart on the record, never by the intent behind it.
The Bow-Tie: One Pivot, Two Sides
Threats act on the left. Consequences unfold on the right. The System Risk Event — System Compromise, Loss of Control — is the pivot between them.
Zoom in, and the same shape holds the whole incident.
Threats Are Sequences, Not Labels
Every attack is a chain of atomic causes — #9→#4→#1 — one cluster per step, read across three layers: System, Data and Business Risk Events.
10 Causes × 6 Functions = 60 Control Objectives
Cross the ten clusters with the six NIST CSF functions and control coverage becomes falsifiable: every gap is a named, empty cell.
One Number the Board Understands
How do you tell the Board if you are secure? “We stopped 100 viruses” is a vanity metric. The Detection Coverage Score (DCS) is a strategic KPI derived from Attack Velocity.
Mean Time to Detect ÷ Attack Velocity
You are faster than the adversary.
Winning
The adversary completes the step before you detect it.
Losing
If a Ransomware group moves from #4 Identity Theft to #1 Abuse of Functions (Admin Rights) in 10 minutes, and your SIEM alerts in 15 minutes:
You are systematically blind to this attack. No amount of “hard work” by analysts will fix this — you need automation.
Watch the Model Run on a Real Incident
A 17-step Active Directory ransomware cascade, replayed step by step: the tracer keeps returning to #1 Abuse of Functions, and every Data Risk Event stacks in the ledger.
One Framework, Four Audiences
Each domain speaks TLCTC in its own dialect. Pick a bubble above — or a section below — to see the integrations, tools and reading tailored to your role.
Regulators & Standards
Fix the “cyber in the name” taxonomy gap, and give every regime one trigger point on the same event chain.
Strategic Leadership
Enable board-level communication across both sides of the Bow-Tie — ten causes on the left, the System Risk Event as pivot, consequences on the right.
Opsec
Map attacker techniques to cause clusters, not outcome labels. Mark where control is lost — the System Risk Event opens the detection window (Δt) response works in.
Development & Engineering
Prioritize weaknesses by the generic vulnerability they expose, not the outcome they might enable. Place each control left or right of the System Risk Event.
The Full Archive, Through Your Lens
Every post, tagged by target audience. Pick your lens — or search the lot.