TLCTC is the Rosetta Stone for Cyber Risk.
Ten logically‑derived, non‑overlapping cyber threat clusters — each named by the root weakness an attack exploits, not by its outcome — give strategy & risk management, security operations and development & engineering one common language.
TLCTC is a free & open framework. No paywalls, no certifications to buy, no consulting funnel. Built to be used, challenged, and evolved by the community.
Licensed under CC BY 4.0 · Attribution required, commercial use permitted.
Ten Causes, No Overlap
Each cluster names one generic vulnerability — the root weakness an attack step exploits. One attack step, one generic vulnerability, one cluster. The quoted line on each card is the cluster’s canonical attacker’s view from the v2.6 core paper; the full definition is one click away.
internal the weakness lies inside the software domain · bridge it lies in another domain — physical, human or third party — and crosses into cyber. · All ten definitions →
Found on the object, not collected from attacks
Why these ten, and why exactly ten? A thought experiment takes the whole world of IT as a single object and examines its attack surfaces one at a time — from designed functions to server and client code, credentials, the line between them, capacity, foreign code, the physical world, people and third-party trust. Every generic vulnerability with its own control lever becomes one cluster.
Film · 4:48 · English captions
Beyond a list of ten
Four ideas built on the clusters that the usual frameworks do not offer — each explained in full in the model further down.
Why a Shared Threat Language Matters
Ask what “threat” means and you get an attacker, an outcome, a vulnerability or a missing control. With one word for four things, incidents cannot be compared and risk cannot be measured — and the three domains in the triangle above each fill the gap with their own dialect.
The Translation Gap
Risk registers speak outcomes and control failures; the SOC speaks attacker techniques. A board question and a SOC answer do not meet.
With TLCTC: an alert classified as, say, #4 Identity Theft lands on the risk dashboard under the same name.
The Design Gap
Risk decisions rarely reach the backlog as concrete design requirements, so engineering optimises for findings instead of causes.
With TLCTC: each cluster carries a developer’s view — design goals and hardening baselines per root weakness.
The Intelligence Gap
What attackers actually exploit in production seldom flows back to the people who write and harden the code.
With TLCTC: an exploited server flaw becomes cluster #2 — the same ticket in the SOC and in the developer backlog.
TLCTC sits beneath the frameworks you already use
Existing frameworks describe controls, techniques or weaknesses in great detail. TLCTC adds the missing cause-oriented layer they can all point to — the strategic “what” beneath their operational “how”.
Prefer to watch? Three short explainers, with English captions.
Find Your Application
One classification, four ways to use it. Each card leads to tools, integrations and reading for that role further down.
One Attack, Read Step by Step
An illustrative composite — not a specific incident — showing how TLCTC reads an intrusion: one cluster per step, consequences recorded separately.
A convincing e-mail leads an employee to a fake login page, where they type their password.
The weakness exploited is human trust. The stolen password is a Data Risk Event (DRE) of this step — a loss of confidentiality (C) — not yet its use.
Hours later, the attacker signs in with that password.
Using a credential to authenticate as someone else is always #4 — a separate step from stealing it.
Five minutes later, the account’s export function pulls 20,000 customer records.
A designed function, used by someone who was never granted it — no code flaw involved. The records leaving are the confidentiality loss.
#9 + [DRE: C] →[Δt=hours] #4 →[Δt=5m] #1 + [DRE: C]
→ next step · Δt time between steps (attack velocity) · [DRE: C] data risk event, confidentiality
Three layers of events
Break the chain where it is cheapest
Bind the login to the real person. Phishing-resistant multi-factor authentication (MFA) makes the stolen password useless: step 1 may still succeed, but the path stops at #4. That is control objective #4 × Protect in the matrix below.
Watch the speed. Five minutes from sign-in to export is minutes-class velocity (VC‑3): only automated detection and response act in time — see the velocity concept below.
From Cause to Consequence
Eight concepts that take the example above apart: from the basic bow-tie to the speed of an attack.
The Bow-Tie: One Pivot, Two Sides
Threats act on the left. Consequences unfold on the right. The System Risk Event — System Compromise, Loss of Control — is the pivot between them.
Zoom in, and the same shape holds the whole incident.
The Asset in Context: What Actually Gets Compromised
Eight layers narrow from region down to the product instance — version and configuration item, where CVEs attach — to name the asset. Actors apply the threats — but neither the context stack nor the actor is a classification input. The cause–event–consequence line stays the same either way.
Threats Are Sequences, Not Labels
Every attack is a chain of atomic causes — #9→#4→#1 — one cluster per step, because each step exploits exactly one generic vulnerability — read across three layers: System, Data and Business Risk Events.
Every path is a walk through ten nodes
Any cluster can follow any other, so real intrusions trace different routes through the same ten nodes. The network replays example paths step by step, with their notation underneath.
Not Every Compromise Becomes a Business Risk
Risk events stack in three layers. A System Risk Event escalates only if data is affected; a Data Risk Event escalates only if the business is affected. Root causes act horizontally at each altitude — the chain rises vertically.
Two provenances meet at the same altitude: a System Failure has no attacker, a System Compromise has one of the ten clusters behind it. From there the chain is identical — and it stops the moment a gate does not open.
Naming note. The second Integrity refinement is the misattributed state (If: provenance or attribution fails; the content may be perfectly accurate) since TLCTC v2.5, 2026-09-05. Earlier versions of this figure called it the “fraudulent state”; the state is told apart on the record, never by the intent behind it.
The Dual-Layer Bow-Tie: One Event, Two Altitudes
The strategic layer speaks clusters and risk appetite. The operational layer speaks TTPs and data risk events. Same pivot, two readings — one consistent bridge.
10 Causes × 6 Functions = 60 Control Objectives
Cross the ten clusters with the six NIST CSF functions and control coverage becomes falsifiable: every gap is a named, empty cell.
Structure, not proof: the matrix names the 60 control objectives and makes coverage assessable. A populated cell does not show that a control works — effectiveness needs evidence, such as key control indicators measured against targets.
Watch the Model Run on a Real Incident
A 17-step Active Directory ransomware cascade, replayed step by step: the tracer keeps returning to #1 Abuse of Functions, and every Data Risk Event stacks in the ledger.
One Number the Board Understands
How do you tell the Board if you are secure? “We stopped 100 viruses” is a vanity metric. The Detection Coverage Score (DCS) compares the defender’s time with the attacker’s velocity (Δt) at each step of an attack path.
Time to detect (d) or to contain (c), read at the 90th percentile ÷ attack velocity of the step. The earlier mean form, MTTD ÷ Δt, is the special case when only averages exist.
You are faster than the adversary.
Winning
The adversary completes the step before you detect it.
Losing
If a Ransomware group moves from #4 Identity Theft to #1 Abuse of Functions (Admin Rights) in 10 minutes, and 90 % of your alerts arrive within 15 minutes (TTDP90):
You are systematically blind to this attack. No amount of “hard work” by analysts will fix this — you need automation. And seeing a step is not stopping it: only DCSc < 1 means the step is contained in time.
Tools & Audience Resources
Free proof-of-concept tools that run in the browser, and an AI prompt for every role. The status label is the one from the tool gallery.
Strategic Leadership
Enable board-level communication across both sides of the Bow-Tie — ten causes on the left, the System Risk Event as pivot, consequences on the right.
Opsec
Map attacker techniques to cause clusters, not outcome labels. Mark where control is lost — the System Risk Event opens the detection window (Δt) response works in.
Development & Engineering
Prioritize weaknesses by the generic vulnerability they expose, not the outcome they might enable. Place each control left or right of the System Risk Event.
Regulators & Standards
Fix the “cyber in the name” taxonomy gap, and give every regime one trigger point on the same event chain.
Read, Cite, Challenge
The canonical framework: axioms, the ten cluster definitions, classification rules and attack-path notation.
doi:10.5281/zenodo.20633176Putting TLCTC to work: control matrix, key control indicators, governance and reporting.
doi:10.5281/zenodo.22697636The framework in a few pages, for decision-makers.
How the ten clusters are derived — one per generic vulnerability with its own control lever.
Free & open · licensed under CC BY 4.0 — attribution required, commercial use permitted.
The Full Archive, Through Your Lens
Every post, tagged by target audience. Pick your lens — or search the lot.