Actor Threat Quotient: Production Mathematical Formulation
J. McKenney
This is an unnumbered working paper in the WG-01-UI underwriting series, alongside the numbered WG-01-UI-05 and WG-01-UI-06 papers. It sets out the production Actor Threat Quotient formula that other Eigenia papers cite by name, including WG-07-TM-TACAM's threat-actor clustering treatise, and its twelve raw dimensional metrics are drawn directly from that working group's TACAM data clusters (tacam_ttp_clusters, tacam_temporal_clusters, tacam_cpe_clusters).
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
In critical infrastructure security, qualitative threat rankings do not survive board scrutiny. Security operations often rank adversaries by brand recognition or categorical labels, and when a decision-maker asks how much more dangerous one actor is than another, the answer collapses into adjectives like "highly sophisticated" or "well-resourced." That obscures operational variance and stalls capital allocation.
The Actor Threat Quotient replaces the adjectives with an actuarial-grade number. It runs in production as a continuous materialized database calculation and returns a composite score on a zero to one hundred scale that measures the operational danger a given adversary presents to a specific facility topology. The score is a weighted additive composite of twelve auditable dimensions, each carrying a named data source and a stated saturation bound, and the twelve weights sum to exactly one, so the score lands on zero to one hundred by construction rather than by a bounding transform.
Every dimension reads from an authoritative source rather than an analyst's impression. The twelve are grouped into four operational tiers, base capability, tactical arsenal, environmental exposure and dynamic momentum, and the composite recalculates as new incident, exploitability and geopolitical data arrive rather than on a reporting cycle. The weights are actuarial judgment, not a regression fit against loss outcomes, so a reader who disagrees can change one weight and re-run the view.
Abstract#
The Actor Threat Quotient (ATQ) casts adversary danger as an actuarial-grade number. It executes in production as a continuous materialized calculation (seldon.seldon_score_v2) and returns a composite normalized on the zero-to-one-hundred interval that quantifies the real-time operational danger an adversary presents to a specific facility topology. The ATQ is a weighted additive composite of twelve orthogonal dimensions, each with a named data source and a stated saturation function, and its actuarial weights sum to exactly 1.00; because every normalization lands on the unit interval, the composite lands on zero to one hundred by construction. The twelve dimensions sit in four operational tiers whose subtotals are 0.23, 0.34, 0.20 and 0.23. A 95 percent confidence band scales with data completeness, and the V2 formulation spreads the top decile from 68.0 to 78.6, separating active groups such as Volt Typhoon (78.6) from dormant history.
1. The Production Formula: Twelve Weighted Dimensions#
The ATQ is a weighted additive score over twelve orthogonal dimensions. For an actor at temporal epoch :
subject to the simplex weight constraint:
Where is the raw dimensional metric drawn from an authoritative source, is that dimension's normalization and saturation function, and is its actuarial weight. Because the twelve weights sum to exactly 1.00 and every lands on the unit interval, the composite lands on by construction rather than by a transform chosen to bound it.
The weights are actuarial judgment, not a fitted result. No regression against loss outcomes produced them and no external study is cited for them. They encode this working group's view of what makes an adversary dangerous to an industrial facility, and a reader who disagrees can change one weight and re-run the materialized view rather than argue with the whole score.
Saturation Bounds and Confidence Bands#
No transform imposes a ceiling on the composite. The score reaches 100 only when all twelve dimensions saturate at once, and each dimension's saturation threshold is stated in section 2, so a reader can see exactly what an adversary would have to do to move each one.
Seldon computes a 95 percent confidence band from data completeness:
An adversary carrying an ATQ of with ten of the twelve dimensions populated therefore has points. Groups with extensive forensic attribution hold narrow uncertainty margins on this rule; emerging groups, for which most dimensions are still empty, exhibit wide confidence bands and the -point floor rarely binds for them.
2. Deconstruction of the Twelve Dimensions#
Every point in an adversary's ATQ originates from an explicit database function executing against a structured relational table. The twelve dimensions are grouped into four operational tiers, and their weights sum to exactly 1.00:
| # | Dimension Name | Tier | Weight () | Raw Metric () | Saturation Threshold () | Normalization Function () | Authoritative Source |
|---|---|---|---|---|---|---|---|
| 1 | EIC Base Score | Base Capability | 0.18 | Explicit Intent, Capability, and Opportunity | Dynamic Percentile | seldon.actor_eic | |
| 2 | Kill Chain Completeness | Tactical Arsenal | 0.14 | Distinct MITRE Tactics Executable | 14 Tactics | tacam_ttp_clusters | |
| 3 | Temporal Threat Score | Dynamic Momentum | 0.08 | Operational Tempo & Recency Decay | 1.0 (Unit Interval) | tacam_temporal_clusters | |
| 4 | EPSS Base Average | Tactical Arsenal | 0.10 | Mean Exploit Prediction Score | 0.20 ( Multiplier) | FIRST EPSS Daily Feed | |
| 5 | Technique Reach | Tactical Arsenal | 0.10 | Unique MITRE ATT&CK Techniques | 120 Techniques | Knowledge Graph (USES_TECHNIQUE) | |
| 6 | Vendor Exposure | Environmental Exposure | 0.10 | Distinct Hardware/Software Vendors | 50 Vendors | tacam_cpe_clusters | |
| 7 | Sector Reach | Environmental Exposure | 0.05 | CISA Critical Sectors Targeted | 16 Sectors | Knowledge Graph (TARGETS_SECTOR) | |
| 8 | Protocol Reach | Environmental Exposure | 0.05 | OT/ICS Protocols Exploitable | 10 Protocols | Knowledge Graph (TARGETS_PROTOCOL) | |
| 9 | Incident Historical Volume | Base Capability | 0.05 | Attributed Public Incidents | 20 Incidents | Curated Incident Corpus | |
| 10 | Campaign Recency | Dynamic Momentum | 0.05 | Days Elapsed Since Last Activity | 365 Days Exponential | tacam_temporal_clusters | |
| 11 | EPSS Velocity | Dynamic Momentum | 0.05 | Rate of Change in Exploitability | 0.01/day ( Cap) | EPSS Trajectory Time-Series | |
| 12 | Geopolitical Tension | Dynamic Momentum | 0.05 | State Hostility & Conflict Index | 1.0 (Unit Interval) | ACLED & Geopolitical Field |
The tier subtotals are Base Capability 0.23, Tactical Arsenal 0.34, Environmental Exposure 0.20 and Dynamic Momentum 0.23, and they add to 1.00.
One of the twelve saturation thresholds is set by counting rather than by judgment: is the 85th percentile of the attributed public incident distribution held in the curated incident corpus, which puts it at 20 incidents. Of the remaining eleven, four are the size of a fixed enumeration and the rest are the working group's own caps, and the table above says which each one is.
Dimension 3 and Dimension 10 both read from tacam_temporal_clusters and both encode how recently an adversary was active, so the two are deliberately held at a combined 0.13 rather than allowed to compound. Dimension 4 and Dimension 11 both read the EPSS feed, one as a level and one as a first difference, and are held at a combined 0.15 for the same reason.
3. Saturation Limits: Resolving the Ceiling Effect#
Earlier V1 scoring frameworks exhibited severe ceiling compression: low saturation thresholds caused over 30 distinct state-sponsored groups to tie within an indistinguishable 2.9-point range.
| Model Generation | Scoring Paradigm | Top-Decile Spread | Primary Distortion |
|---|---|---|---|
| V1 Framework | Coarse Additive Triad | () | Severe ceiling saturation; state-sponsored actors indistinguishable |
| V2 Formulation | Twelve-Dimension Weighted Additive | () | Broad discriminative spread separating active posture from dormant history |
The V2 recalibration raised saturation parameters against empirical distributions:
- Incident Attribution Threshold: Scaled from confirmed operations.
- Product Targeting Range (CPE): Scaled from distinct product families.
- Technique Breadth: Scaled from distinct sub-techniques.
Under V2, dormant historical actors experience natural score decay, while pre-positioned, operationally active groups (such as Volt Typhoon, ATQ 78.6) cleanly separate from baseline criminal syndicates, and the ordering of the top band is set by current operational posture rather than by historical incident volume: Volt Typhoon at 78.6 leads Dragonfly at 76.2 and Lazarus Group at 76.0.
4. Continuous Event-Driven Database Pipeline#
The ATQ executes within PostgreSQL using asynchronous trigger pipelines to ensure scores reflect fresh intelligence without manual reporting cycles:
Database recalculations write immutable records to seldon.atq_score_history, allowing underwriting algorithms to calculate Actor Drift: the quantifiable rate at which an adversary's operational capability accelerates following geopolitical flashpoints.
5. Downstream Applications: Underwriting & Digital Twin Modeling#
The ATQ score is not an end in itself; it is a live input other Eigenia systems and treatises consume once it lands in seldon.seldon_score_v2. Three downstream applications currently draw on it.
- Monte Carlo Random Walk Biasing: When the digital twin simulates lateral propagation across plant conduits, edge traversal weights are scaled by active ATQ modifiers ().
- Deterministic Seldon Rating: Internal vulnerabilities are crossed against external threat pressure, ensuring compliance ratings reflect adversaries actually targeting deployed hardware rather than generic checklists.
- Gordon-Loeb Budget Optimization: By establishing empirical probabilities of compromise, ATQ calculations feed directly into Gordon-Loeb investment equations, establishing mathematically optimal expenditure boundaries for cyber risk mitigation [1].
6. References#
- [1] Gordon, L. A., & Loeb, M. P. (2002): "The economics of information security investment." ACM Transactions on Information and System Security, 5(4), 438-457.