Universal, Non‑overlapping Cyber Threat Language

TLCTC is the Rosetta Stone for Cyber Risk.

10 logically‑derived, non‑overlapping cyber threat clusters that connect strategic cyber risk & -security management, operational security, and secure development into one common language.

Free & Open

TLCTC is a free & open framework. No paywalls, no certifications to buy, no consulting funnel. Built to be used, challenged, and evolved by the community.

Licensed under CC BY 4.0 · Attribution required, commercial use permitted.

Short Video Explainer to connect easier

Escaping Semantic Chaos

Why we need a universal language

The Missing Hub

How TLCTC connects the disparate pieces of the cybersecurity landscape

The Missing What

NIST CSF is the how, TLCTC the what: the control matrix, control objectives and KCIs

Framework Position

Bridging Strategy, Operations & Development

Three domains speak different dialects. TLCTC is the shared reference that closes the gaps between them.

STRATEGIC CISO & Risk Mgmt ISO 27001/5 NIST CSF/SP 800-30 FAIR OPERATIONAL SOC & Threat Intel MITRE ATT&CK • SOC CKC • STIX • CVE DEVELOPMENT DevSecOps & SDLC OWASP • CVE • CWE CIS PASTA • OCTAVE ROSETTA STONE TLCTC 10 CLUSTERS TRANSLATION GAP DESIGN GAP INTELLIGENCE GAP
The Model

From Cause to Consequence

Seven moves from a threat’s root cause to the metric your board understands.

Concept 01 / 08

The Dual-Layer Bow-Tie: One Event, Two Altitudes

The strategic layer speaks clusters and risk appetite. The operational layer speaks TTPs and data risk events. Same pivot, two readings — one consistent bridge.

CAUSE EVENT CONSEQUENCES STRATEGIC OPERATIONAL Threat Clusters Generic vulnerabilities of asset types #1 – #10 · STABLE Threats / TTPs Specific vulnerabilities of specific assets CVE · ATT&CK · VOLATILE Appetite & Tolerance Business Impact Analysis (BIA) BOARD METRICS Consequences Data Risk Events (C · I · Av · Ac) DRE → BUSINESS RISK EVENT RISK EVENT System Compromise LOSS OF CONTROL RISK INCIDENT One bow-tie, two altitudes: the strategic layer sets appetite per cluster, the operational layer works attack paths — both meet at the same risk event.

Read: The Two-Layer Framework: Why Reality Demands Separation →

Concept 02 / 08

The Asset in Context: What Actually Gets Compromised

Eight layers narrow from region down to the product instance — version and configuration item, where CVEs attach — to name the asset. Actors apply the threats — but neither the context stack nor the actor is a classification input. The cause–event–consequence line stays the same either way.

The asset in context: context stack, actors, and the cause–event–consequence line An eight-layer context stack (region, state or nation, sector, asset owner organization, asset topology, asset type, asset product, asset instance with its version and configuration item) narrows down to the asset that is compromised in the central risk event; specific vulnerabilities such as CVEs attach at the instance layer. Actors on the left apply threats to the cause side; each step enters the asset through an interface or function, whose role decides server- versus client-side classification. The cause side, the risk event, and the consequences form one horizontal line, with the CSF functions Protect, Detect, Respond, and Recover placed beneath it as diamonds. Neither the context stack nor the actor is a classification input. The Asset in Context the context stack defines the asset · actors apply threats · the cause–event–consequence line stays the same CONTEXT STACK outside in Region — e.g. EU, US, APAC State / Nation Sector — to which the organization belongs Asset Owner Organization Asset Topology — cloud / on-prem Asset Type — OT / IT, network, application Asset Product — e.g. SharePoint Asset Instance — version & configuration item (CI) the asset that is compromised (CVEs attach at product version / instance) ACTORS apply threats — never classify them Nation-State Cybercriminal (Ransomware) Cybercriminal (General) Hacktivist Insider (outside their grant) Amateur (Script-Kiddie) Any actor can use AI agents — a capability, not an actor. CAUSE SIDE Threat Clusters #1–#10 entry: interface / function role decides #2 vs #3 (R-ROLE) RISK EVENT Asset Compromise (SRE) CONSEQUENCES DRE → BRE* (impact, follow-up events) PROTECT IDENTIFY (indirectly) DETECT RESPOND RECOVER A clear line from context to compromise to consequence. The stack changes the specific vulnerabilities and controls, never the clusters (Axiom I). Actors apply threats; they never classify them (Axiom IV).
Concept 03 / 08

Not Every Compromise Becomes a Business Risk

Risk events stack in three layers. A System Risk Event escalates only if data is affected; a Data Risk Event escalates only if the business is affected. Root causes act horizontally at each altitude — the chain rises vertically.

The vertically layered risk-event model Three stacked layers. At the bottom, the System Risk Event layer holds two events: System Failure, which occurs as either a software failure (from a code defect) or a hardware failure (from material wear or environmental conditions), with error in use and abuse of rights modelled on both kinds; and System Compromise, fed by the ten TLCTC clusters: abuse of functions, exploiting server, exploiting client, identity theft, man in the middle, flooding attack, malware, physical attack, social engineering and supply chain attack. Both feed one escalation chain that rises through a gate labelled "only if data is affected" into the Data Risk Event layer, typed as loss of confidentiality, loss of integrity (incorrect), loss of integrity (fraud), loss of availability and loss of accessibility, and then through a second gate labelled "only if the business is affected" into the Business Risk Event layer, whose consequences are financial loss, regulatory consequences, customer harm, reputational impact and further business risk events. BRE Business RISK EVENT LAYER ORG. CONSEQUENCE DRE Data RISK EVENT LAYER C · Ii · If Av · Ac SRE System RISK EVENT LAYER TWO PATHS ONE ALTITUDE TECHNICAL PATH Code Defect Supply Chain Event Error in Use Abuse of Rights Software Failure Material / Wear Environmental Error in Use Abuse of Rights Hardware Failure CYBER-SPECIFIC PATH #1 Abuse of Functions #2 Exploiting Server #3 Exploiting Client #4 Identity Theft #5 Man in the Middle #6 Flooding Attack #7 Malware #8 Physical Attack #9 Social Engineering #10 Supply Chain Attack EACH STEP CARRIES EXACTLY ONE CLUSTER System Failure SYSTEM RISK EVENT (SRE) System Compromise SYSTEM RISK EVENT (SRE) ROOT CAUSES · INFLUENCE Abuse of Rights Error in Use Supply Chain Event Data Risk Event e.g. payment data no longer accessible cause: ransomware encryption DRE TYPES · EVENT → STATE Loss of Confidentiality LoC · [DRE: C] Loss of Integrity LoI · [DRE: I] Incorrect State LoIi · [DRE: Ii] Misattributed State LoIf · [DRE: If] formerly “fraudulent state” Loss of Availability / Accessibility [DRE: A] Unavailable State LoA · [DRE: Av] Inaccessible State LoAc · [DRE: Ac] ROOT CAUSES · INFLUENCE Lack of Skills people Error in Action people Abuse of Position people Supply Chain Event bridge External Event external Business Risk Event e.g. payment service outage e.g. fraudulent payments executed e.g. § notification duty unmet at t+72h CONSEQUENCES Financial Loss § Regulatory Consequences Customer Harm Reputational Impact Further Business Risk Events ONLY IF DATA IS AFFECTED 0 < Δt · function-related · can be interrupted ONLY IF THE BUSINESS IS AFFECTED 0 < Δt · function-related · can be interrupted ROOT CAUSES ACT HORIZONTALLY RISK EVENTS ESCALATE VERTICALLY ESCALATION IS CONDITIONAL Validated core: the ten TLCTC clusters, bottom right. The rest is the author’s view of the world in August 2026.

Two provenances meet at the same altitude: a System Failure has no attacker, a System Compromise has one of the ten clusters behind it. From there the chain is identical — and it stops the moment a gate does not open.

Naming note. The second Integrity refinement is the misattributed state (If: provenance or attribution fails; the content may be perfectly accurate) since TLCTC v2.5, 2026-09-05. Earlier versions of this figure called it the “fraudulent state”; the state is told apart on the record, never by the intent behind it.

Read: Beyond the Breach — Event Chains in Cyber Risk →

Concept 04 / 08

The Bow-Tie: One Pivot, Two Sides

Threats act on the left. Consequences unfold on the right. The System Risk Event — System Compromise, Loss of Control — is the pivot between them.

A risk event is a deviation from a strategic goal. IT Goal: "Operate securely" • Risk Event: "Compromise of System" GOVERN — Risk Appetite, Responsibilities, Metrics (Cross-cutting) CAUSE SIDE Threat Clusters RISK EVENT / INCIDENT Asset Compromise Generic Vulnerability CONSEQUENCES CONTROL PROTECT IDENTIFY (indirectly) CONTROL DETECT CONTROL RESPOND CONTROL RECOVER Preventive controls affect the likelihood of an event occurring Detective and reactive controls influence the consequences "A control failure is a control risk — it is a deviation from the control objective"

Zoom in, and the same shape holds the whole incident.

The Cyber Bow-Tie: ten threat clusters on the cause side, System Risk Events at the centre, Data Risk Events and Business Risk Events on the consequence side Cyber Threat Clusters IT Risk Events Business Risk Events PREVENT PREVENT PREVENT PREVENT PREVENT PREVENT PREVENT PREVENT PREVENT PREVENT PREVENT Prevent from lateral movement (#1-#10) REACT REACT REACT PREVENT (ONLINE FRAUD/SCAM) #1Abuse of Functions #2Exploiting Server #3Exploiting Client #4Identity Theft #5Man in the Middle #6Flooding Attack #7Malware #8Physical Attack #9Social Engineering #10Supply Chain Attack System Risk Event System Compromise "Loss of Control" Asset: IT system System Risk Event System Compromise Data Risk Event Loss of Confidentiality Data Risk Event Loss of Integrity Data Risk Event Loss of Availability / Accessibility Business Risk Events: Consequences = e.g. Databreach PID Business Risk Events: Consequences = e.g. Money Out Business Risk Events: Consequences = e.g. payment interruption Consequence 1 Consequence 2 Consequence 3 Consequence 1 Consequence 2 Consequence 3 Consequence 1 Consequence 2 Consequence 3
Concept 05 / 08

Threats Are Sequences, Not Labels

Every attack is a chain of atomic causes — #9→#4→#1 — one cluster per step, read across three layers: System, Data and Business Risk Events.

BRE Business Risk Event organizational consequence DRE Data Risk Event C / I / A on data assets SRE System Risk Event cause-side TLCTC sequence BRE Fraudulent transfer financial loss no BRE DRE present, but no organizational consequence no BRE no DRE means no escalation path DRE: C Credentials exposed phished by user no DRE credential USE only (R-CRED rule) DRE: I Wire transfer altered payment integrity Δt: 5m Δt: 5m #9 SOCIAL ENGINEERING BRIDGE #4 IDENTITY THEFT INTERNAL #1 ABUSE OF FUNCTIONS INTERNAL phishing email delivers credential form attacker logs in as the user approves wire transfer via legitimate function ||boundary|| eBanking example: phishing → identity theft → function abuse. Each step escalates only as far as it can — no DRE means no BRE.
Concept 06 / 08

10 Causes × 6 Functions = 60 Control Objectives

Cross the ten clusters with the six NIST CSF functions and control coverage becomes falsifiable: every gap is a named, empty cell.

NIST CSF FUNCTIONS operational lifecycle (Identify → Recover) GOVERN IDENTIFY PROTECT DETECT RESPOND RECOVER GV ID PR DE RS RC #1 Abuse of Functions #2 Exploiting Server #3 Exploiting Client #4 Identity Theft #5 Man in the Middle #6 Flooding Attack #7 Malware #8 Physical Attack #9 Social Engineering #10 Supply Chain Attack CELL = 1 CONTROL OBJECTIVE = NIST verb + TLCTC noun e.g., DETECT · #7 Malware Local Control asset / system specific Umbrella Control enterprise-wide / shared GOV-Umbrella cross-cutting · ERM integration TOTAL 10 × 6 = 60 Objectives Only the GOV-Umbrella controls are cross-cutting — they form the integration layer to Enterprise Risk Management (policies, ERM forums, risk appetite, assurance). All other Local & Umbrella controls remain cluster-specific (Whitepaper §8.1.3, §9).
Explore all 60 cells: Control Matrix Tool
Controls that act after a system is compromised (encryption at rest, backups) sit one layer later: DRE Control Matrix
Concept 07 / 08

One Number the Board Understands

How do you tell the Board if you are secure? “We stopped 100 viruses” is a vanity metric. The Detection Coverage Score (DCS) is a strategic KPI derived from Attack Velocity.

The Formula
DCS = MTTD ÷ Δt

Mean Time to Detect ÷ Attack Velocity

Score < 1.0

You are faster than the adversary.

Winning

Score > 1.0

The adversary completes the step before you detect it.

Losing

Example

If a Ransomware group moves from #4 Identity Theft to #1 Abuse of Functions (Admin Rights) in 10 minutes, and your SIEM alerts in 15 minutes:

DCS = 15 ÷ 10 = 1.5

You are systematically blind to this attack. No amount of “hard work” by analysts will fix this — you need automation.

Concept 08 / 08

Watch the Model Run on a Real Incident

A 17-step Active Directory ransomware cascade, replayed step by step: the tracer keeps returning to #1 Abuse of Functions, and every Data Risk Event stacks in the ledger.

AD-DOMAIN-ADMIN-CASCADE-2025
composite reference path · Lynx · Storm-2603 · Storm-0300 (2025)
DRE Ledger
    The cascade is structurally #1 Abuse of Functions — the tracer keeps returning to #1 — with #4 for credential application and #7 only where foreign executable content executes. Each step’s Data Risk Event pops at the node and stacks in the ledger; “ransomware” is the outcome at s13 (#7 + [DRE: Ac]), never a cluster of its own.
    Read the full #1-Cascade forensic analysis
    For Every Audience

    One Framework, Four Audiences

    Each domain speaks TLCTC in its own dialect. Pick a bubble above — or a section below — to see the integrations, tools and reading tailored to your role.

    Audience 01 · Compliance & Industry

    Regulators & Standards

    Fix the “cyber in the name” taxonomy gap, and give every regime one trigger point on the same event chain.

    Audience 02 · CISO & Risk Mgmt

    Strategic Leadership

    Enable board-level communication across both sides of the Bow-Tie — ten causes on the left, the System Risk Event as pivot, consequences on the right.

    Audience 03 · SOC & Threat Intelligence

    Opsec

    Map attacker techniques to cause clusters, not outcome labels. Mark where control is lost — the System Risk Event opens the detection window (Δt) response works in.

    Audience 04 · DevSecOps & Secure SDLC

    Development & Engineering

    Prioritize weaknesses by the generic vulnerability they expose, not the outcome they might enable. Place each control left or right of the System Risk Event.

    From the Blog

    The Full Archive, Through Your Lens

    Every post, tagged by target audience. Pick your lens — or search the lot.

    RSS