Skip to content

Threat Landscape

What is Threat Landscape?

The current state of threats facing an organization or industry, including active threat actors, attack methods, and emerging attack trends.

Risk Management

Each of these is named in at least one of the same controls as threat landscape. The number is how many controls name both.

What the standards actually require on threat landscape

Requirements naming threat landscape across 6 standards, quoted from the control text.

HKMA C-RAF Domain 5 RESPONSE AND RECOVERY + Domain 6 SITUATIONAL AWARENESS. DOMAIN 5 RESPONSE AND RECOVERY (3 sub-areas): (1) INCIDENT RESPONSE PLANNING - documented IR plan + playbooks + runbooks + RACI + escalation criteria + decision trees + communication p...

HKMA-CRAF-Domain5-6-Response-Recovery-SitAwareness · HKMA C-RAF Domain 5 (Response and Recovery) + Domain 6 (Situational Awareness) - Incident Response, Recovery, Threat Landscape, Information Sharing

A Generic Threat Landscape (GTL) for the jurisdiction/sector is produced (by the relevant authorities) to inform the threat scenarios used in TIBER-EU tests; entities and providers take it into account when developing targeted threat intelligence.

TIBER-0.1 · Generic Threat Landscape

Use data analytics to integrate threat sources into a single real-time view of the threat landscape to move towards predicting malicious activity.

ASIC-CR-DE-2 · Data analytics for threat integration

Article 25 requires the Commission to evaluate the Regulation by 5 February 2027 (initial early assessment focused on Hub deployment and Reserve operationalisation), and to carry out a comprehensive evaluation every four years thereafter.

CSA-Art.25 · Evaluation and review (Article 25)

Questions people ask about threat landscape

What is Threat Landscape?
The current state of threats facing an organization or industry, including active threat actors, attack methods, and emerging attack trends.
Why is Threat Landscape important for compliance?
Threat Landscape is a key concept in Risk Management. Understanding threat landscape helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Threat Landscape?
Threat Landscape appears in the requirement text of HKMA Cyber Resilience Assessment Framework (C-RAF), ECB TIBER-EU Framework, IMO Maritime Cybersecurity Guidelines (MSC-FAL.1/Circ.3/Rev.2), Japan FSA Cybersecurity Guidelines for Financial Institutions, ASIC Cyber Resilience Good Practices. Across these standards we have identified 10 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Threat Landscape?
Explore our compliance framework pages to see how threat landscape applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Threat Landscape applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.