Understanding threat attribution in cybersecurity

The TrendAI framework offers a structured approach to threat attribution, emphasising evidence over labels.

  • Tuesday, 17th February 2026 Posted 3 months ago in by Sophie Milburn
As the cybersecurity industry navigates the complexities of threat actor identification, TrendAI, part of Trend Micro, has released a guide outlining how threat attribution should operate based on evidence, rather than relying on renaming or differences between vendors.

Variations in threat actor naming are often seen as discrepancies, but this perspective oversimplifies the underlying complexity. Different research teams may analyse distinct datasets, use different clustering methods, and reach varying confidence levels. Complete alignment across all entities is neither realistic nor necessary.

TrendAI's guide explains its approach to tracking activity using structured evidence rather than pre-existing labels. It introduces provisional SHADOW designations, which allow analysts to monitor emerging or overlapping activity without prematurely assigning firm attribution or overstating certainty.

The framework aims to clarify how attribution decisions are made within the industry, highlighting the reasons for differing naming practices and emphasising the importance of evidence over labels.

For business leaders, accurate attribution affects risk management and response planning. Overreliance on threat actor names alone can create a false sense of certainty, potentially affecting priorities and defensive measures.

When attribution decisions are reviewed by stakeholders such as boards, auditors, or regulators, labels on their own may not suffice. An evidence-based approach provides a foundation rooted in verifiable data, supporting clearer communication, justification, and adaptation as new information emerges.
SIOS Technology partners with Vaske to resell high availability and disaster recovery solutions across the US.
The 2026 State of Digital Quality in Accessibility report by Applause highlights AI's role in improving digital accessibility amidst persistent...
Apricorn enhances the Aegis Secure Key 3.0, aiming to deliver faster performance, advanced environmental protection, and FIPS 140-3 Level 3...
Lenovo offers AI deployment solutions designed to support production use, with an emphasis on accelerating implementation timelines while maintaining...
Modular Mast Systems launches a new partner programme, aiming to expand its international footprint in telecom infrastructure and beyond.
Leostream Corporation partners with Jigsaw24 to extend their remote access platform across the UK and EU markets, targeting media, education, and...

AI's impact on identity security: a global perspective

Posted 1 day ago by Sophie Milburn
The latest Semperis study highlights how organisations are struggling to secure identity systems as reliance on artificial intelligence grows.
Snom introduces new measures to streamline partner programmes and launch a comprehensive Competence Centre for training.