Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
ATQ PRODUCTIONCyber Risk Underwriting

Actor Threat Quotient: Production Mathematical Formulation

100% Complete & Untruncated 9 min read
Return to Research Tracks

J. McKenney

This is an unnumbered working paper in the WG-01-UI underwriting series, alongside the numbered WG-01-UI-05 and WG-01-UI-06 papers. It sets out the production Actor Threat Quotient formula that other Eigenia papers cite by name, including WG-07-TM-TACAM's threat-actor clustering treatise, and its twelve raw dimensional metrics are drawn directly from that working group's TACAM data clusters (tacam_ttp_clusters, tacam_temporal_clusters, tacam_cpe_clusters).

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

In critical infrastructure security, qualitative threat rankings do not survive board scrutiny. Security operations often rank adversaries by brand recognition or categorical labels, and when a decision-maker asks how much more dangerous one actor is than another, the answer collapses into adjectives like "highly sophisticated" or "well-resourced." That obscures operational variance and stalls capital allocation.

The Actor Threat Quotient replaces the adjectives with an actuarial-grade number. It runs in production as a continuous materialized database calculation and returns a composite score on a zero to one hundred scale that measures the operational danger a given adversary presents to a specific facility topology. The score is a weighted additive composite of twelve auditable dimensions, each carrying a named data source and a stated saturation bound, and the twelve weights sum to exactly one, so the score lands on zero to one hundred by construction rather than by a bounding transform.

Every dimension reads from an authoritative source rather than an analyst's impression. The twelve are grouped into four operational tiers, base capability, tactical arsenal, environmental exposure and dynamic momentum, and the composite recalculates as new incident, exploitability and geopolitical data arrive rather than on a reporting cycle. The weights are actuarial judgment, not a regression fit against loss outcomes, so a reader who disagrees can change one weight and re-run the view.

Abstract#

The Actor Threat Quotient (ATQ) casts adversary danger as an actuarial-grade number. It executes in production as a continuous materialized calculation (seldon.seldon_score_v2) and returns a composite normalized on the zero-to-one-hundred interval that quantifies the real-time operational danger an adversary presents to a specific facility topology. The ATQ is a weighted additive composite of twelve orthogonal dimensions, each with a named data source and a stated saturation function, and its actuarial weights sum to exactly 1.00; because every normalization lands on the unit interval, the composite lands on zero to one hundred by construction. The twelve dimensions sit in four operational tiers whose subtotals are 0.23, 0.34, 0.20 and 0.23. A 95 percent confidence band scales with data completeness, and the V2 formulation spreads the top decile from 68.0 to 78.6, separating active groups such as Volt Typhoon (78.6) from dormant history.

1. The Production Formula: Twelve Weighted Dimensions#

The ATQ is a weighted additive score over twelve orthogonal dimensions. For an actor aa at temporal epoch tt:

ATQa(t)=∑k=112wk⋅σk(xa,k(t))×100\text{ATQ}_a(t) = \sum_{k=1}^{12} w_k \cdot \sigma_k\left( x_{a,k}(t) \right) \times 100

subject to the simplex weight constraint:

∑k=112wk=1.0,wk>0∀k∈{1,…,12}\sum_{k=1}^{12} w_k = 1.0, \quad w_k > 0 \quad \forall k \in \{1, \dots, 12\}

Where xa,k(t)∈R≥0x_{a,k}(t) \in \mathbb{R}_{\ge 0} is the raw dimensional metric drawn from an authoritative source, σk:R≥0→[0,1]\sigma_k: \mathbb{R}_{\ge 0} \to [0, 1] is that dimension's normalization and saturation function, and wkw_k is its actuarial weight. Because the twelve weights sum to exactly 1.00 and every σk\sigma_k lands on the unit interval, the composite lands on [0,100][0, 100] by construction rather than by a transform chosen to bound it.

The weights are actuarial judgment, not a fitted result. No regression against loss outcomes produced them and no external study is cited for them. They encode this working group's view of what makes an adversary dangerous to an industrial facility, and a reader who disagrees can change one weight and re-run the materialized view rather than argue with the whole score.

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

Saturation Bounds and Confidence Bands#

No transform imposes a ceiling on the composite. The score reaches 100 only when all twelve dimensions saturate at once, and each dimension's saturation threshold is stated in section 2, so a reader can see exactly what an adversary would have to do to move each one.

Seldon computes a 95 percent confidence band from data completeness:

Confidence=Non-Zero Dimensions12\text{Confidence} = \frac{\text{Non-Zero Dimensions}}{12}
σ=max⁡(2.0, ATQ×(1−Confidence)×0.3)\sigma = \max\left(2.0, \ \text{ATQ} \times (1 - \text{Confidence}) \times 0.3\right)

An adversary carrying an ATQ of 78.678.6 with ten of the twelve dimensions populated therefore has σ=78.6×(1−10/12)×0.3=3.9\sigma = 78.6 \times (1 - 10/12) \times 0.3 = 3.9 points. Groups with extensive forensic attribution hold narrow uncertainty margins on this rule; emerging groups, for which most dimensions are still empty, exhibit wide confidence bands and the 2.02.0-point floor rarely binds for them.


2. Deconstruction of the Twelve Dimensions#

Every point in an adversary's ATQ originates from an explicit database function executing against a structured relational table. The twelve dimensions are grouped into four operational tiers, and their weights sum to exactly 1.00:

#Dimension NameTierWeight (wkw_k)Raw Metric (xa,kx_{a,k})Saturation Threshold (θk\theta_k)Normalization Function (σk\sigma_k)Authoritative Source
1EIC Base ScoreBase Capability0.18Explicit Intent, Capability, and OpportunityDynamic PercentilePERCENT_RANK(xa,1)\text{PERCENT\_RANK}(x_{a,1})seldon.actor_eic
2Kill Chain CompletenessTactical Arsenal0.14Distinct MITRE Tactics Executable14 Tacticsxa,2/14.0x_{a,2} / 14.0tacam_ttp_clusters
3Temporal Threat ScoreDynamic Momentum0.08Operational Tempo & Recency Decay1.0 (Unit Interval)min⁡(1.0,xa,3)\min(1.0, x_{a,3})tacam_temporal_clusters
4EPSS Base AverageTactical Arsenal0.10Mean Exploit Prediction Score0.20 (5×5\times Multiplier)min⁡(1.0,5.0⋅xˉEPSS)\min(1.0, 5.0 \cdot \bar{x}_{\text{EPSS}})FIRST EPSS Daily Feed
5Technique ReachTactical Arsenal0.10Unique MITRE ATT&CK Techniques120 Techniquesmin⁡(1.0,xa,5/120.0)\min(1.0, x_{a,5} / 120.0)Knowledge Graph (USES_TECHNIQUE)
6Vendor ExposureEnvironmental Exposure0.10Distinct Hardware/Software Vendors50 Vendorsmin⁡(1.0,xa,6/50.0)\min(1.0, x_{a,6} / 50.0)tacam_cpe_clusters
7Sector ReachEnvironmental Exposure0.05CISA Critical Sectors Targeted16 Sectorsmin⁡(1.0,xa,7/16.0)\min(1.0, x_{a,7} / 16.0)Knowledge Graph (TARGETS_SECTOR)
8Protocol ReachEnvironmental Exposure0.05OT/ICS Protocols Exploitable10 Protocolsmin⁡(1.0,xa,8/10.0)\min(1.0, x_{a,8} / 10.0)Knowledge Graph (TARGETS_PROTOCOL)
9Incident Historical VolumeBase Capability0.05Attributed Public Incidents20 Incidentsmin⁡(1.0,xa,9/20.0)\min(1.0, x_{a,9} / 20.0)Curated Incident Corpus
10Campaign RecencyDynamic Momentum0.05Days Elapsed Since Last Activity365 Days Exponentialexp⁡(−λrec⋅Δtdays)\exp(-\lambda_{\text{rec}} \cdot \Delta t_{\text{days}})tacam_temporal_clusters
11EPSS VelocityDynamic Momentum0.05Rate of Change in Exploitability0.01/day (100×100\times Cap)min⁡(1.0,max⁡(0.0,100⋅v˙EPSS))\min(1.0, \max(0.0, 100 \cdot \dot{v}_{\text{EPSS}}))EPSS Trajectory Time-Series
12Geopolitical TensionDynamic Momentum0.05State Hostility & Conflict Index1.0 (Unit Interval)min⁡(1.0,xa,12)\min(1.0, x_{a,12})ACLED & Geopolitical Field

The tier subtotals are Base Capability 0.23, Tactical Arsenal 0.34, Environmental Exposure 0.20 and Dynamic Momentum 0.23, and they add to 1.00.

One of the twelve saturation thresholds is set by counting rather than by judgment: θ9\theta_9 is the 85th percentile of the attributed public incident distribution held in the curated incident corpus, which puts it at 20 incidents. Of the remaining eleven, four are the size of a fixed enumeration and the rest are the working group's own caps, and the table above says which each one is.

Dimension 3 and Dimension 10 both read from tacam_temporal_clusters and both encode how recently an adversary was active, so the two are deliberately held at a combined 0.13 rather than allowed to compound. Dimension 4 and Dimension 11 both read the EPSS feed, one as a level and one as a first difference, and are held at a combined 0.15 for the same reason.


3. Saturation Limits: Resolving the Ceiling Effect#

Earlier V1 scoring frameworks exhibited severe ceiling compression: low saturation thresholds caused over 30 distinct state-sponsored groups to tie within an indistinguishable 2.9-point range.

Model GenerationScoring ParadigmTop-Decile SpreadPrimary Distortion
V1 FrameworkCoarse Additive Triad80.3−83.280.3 - 83.2 (Δ=2.9 pts\Delta = 2.9\text{ pts})Severe ceiling saturation; state-sponsored actors indistinguishable
V2 FormulationTwelve-Dimension Weighted Additive68.0−78.668.0 - 78.6 (Δ=10.6 pts\Delta = 10.6\text{ pts})Broad discriminative spread separating active posture from dormant history

The V2 recalibration raised saturation parameters against empirical distributions:

  • Incident Attribution Threshold: Scaled from ÷3→÷20\div 3 \to \div 20 confirmed operations.
  • Product Targeting Range (CPE): Scaled from ÷15→÷50\div 15 \to \div 50 distinct product families.
  • Technique Breadth: Scaled from ÷80→÷120\div 80 \to \div 120 distinct sub-techniques.

Under V2, dormant historical actors experience natural score decay, while pre-positioned, operationally active groups (such as Volt Typhoon, ATQ 78.6) cleanly separate from baseline criminal syndicates, and the ordering of the top band is set by current operational posture rather than by historical incident volume: Volt Typhoon at 78.6 leads Dragonfly at 76.2 and Lazarus Group at 76.0.


4. Continuous Event-Driven Database Pipeline#

The ATQ executes within PostgreSQL using asynchronous trigger pipelines to ensure scores reflect fresh intelligence without manual reporting cycles:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

Database recalculations write immutable records to seldon.atq_score_history, allowing underwriting algorithms to calculate Actor Drift: the quantifiable rate at which an adversary's operational capability accelerates following geopolitical flashpoints.


5. Downstream Applications: Underwriting & Digital Twin Modeling#

The ATQ score is not an end in itself; it is a live input other Eigenia systems and treatises consume once it lands in seldon.seldon_score_v2. Three downstream applications currently draw on it.

  1. Monte Carlo Random Walk Biasing: When the digital twin simulates lateral propagation across plant conduits, edge traversal weights are scaled by active ATQ modifiers (w′=wbase×[0.3+1.2×ATQ/100]w' = w_{\text{base}} \times [0.3 + 1.2 \times \text{ATQ}/100]).
  2. Deterministic Seldon Rating: Internal vulnerabilities are crossed against external threat pressure, ensuring compliance ratings reflect adversaries actually targeting deployed hardware rather than generic checklists.
  3. Gordon-Loeb Budget Optimization: By establishing empirical probabilities of compromise, ATQ calculations feed directly into Gordon-Loeb investment equations, establishing mathematically optimal expenditure boundaries for cyber risk mitigation [1].

6. References#

  • [1] Gordon, L. A., & Loeb, M. P. (2002): "The economics of information security investment." ACM Transactions on Information and System Security, 5(4), 438-457.
Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 14,042 chars