Per its website, “MITRE ATT&CK (ATT&CK) is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations” (https://tinyurl.com/bddydxrz). The parent organization is a nonprofit actively engaged in advancing national security. Unlike other cybersecurity risk assessment frameworks familiar to the accounting and finance professions, ATT&CK focuses on threat intelligence. The National Institute of Standards and Technology (NIST) defines this as “threat information that has been aggregated, transformed, analyzed, interpreted, or enriched to provide the necessary context for decision-making processes” (https://tinyurl.com/4ckk4uc7). This enhanced perspective, used by more advanced and resource-rich information security functions, gained increased attention from accounting and financial professionals, because of both recent SEC cybersecurity requirements and continued executive frustration with the inability to eliminate cyber risks.
SEC Rules and Continued Governance Frustrations
In a recent CPA Journal article, the authors provide the background, an overview of the rule, and recommended guidance to address requirements (Kevin Agnew, “The SEC Finalizes Rule on Cybersecurity Disclosures: Increased Documentation, Disclosure, and Transparency,” The CPA Journal, June 2025, https://tinyurl.com/3fhpv69m). PwC’s “Threat Intelligence: A Basis for Sound Cyber Disclosures,” highlights the practical implications of using threat intelligence to address a key SEC rule requirement: “Threat intelligence can enhance leaders’ confidence in determining materiality of a cyber incident. Specifically, threat intelligence can provide timely and accurate information on aspects of the threat landscape, including technical indicators, threat actor techniques, threat actor motivation (espionage, financial), and in some cases, origin and sponsor” (https://tinyurl.com/2xx7eamv).
Many executives and their boards continue to have frustrations with managing cybersecurity risks. They have devoted significant attention and made substantial financial investments to help address and manage cybersecurity challenges, yet these challenges seem never-ending. Managing cybersecurity risks seems to contradict what many executives were trained to do: find the problem, fix it, and don’t let it happen again. Unfortunately, in cybersecurity, the problem recurs due to technological changes and the discovery of new threats. To communicate the challenges involved and demonstrate basic due diligence (and explain to governance functions why the problem is not fully resolved), risk assessments, heat maps, and even risk quantification models are used. Regulatory and insurance carrier expectations have also heightened the state of practice, promoting a basic level of security hygiene by considering established control questionnaires and frameworks. Current related risk assessment frameworks primarily focus on providing control inventories, although they mention the need for risk and threat identification. Some publicly available reports enable CPAs to supplement their assessments by including current attack and threat types. A supplemental approach that more resource-enabled and qualified security functions are increasingly adopting emphasizes how attacks actually occur (offense) in addition to defensive tactics (more traditional accounting-related frameworks). The most popular framework for this purpose is ATT&CK.
Highly Respected by Experts, Relatively Unknown to the Profession
The US Cybersecurity and Infrastructure Security Agency (CISA) recognized the importance and reputation of the framework in its publication “Best Practices for MITRE ATT&CK Mapping” (https://tinyurl.com/ms7494n9). Per the publication, the framework is used by CISA to identify attacker behavior and “provides details on 100+ threat actor groups, including the techniques and software they are known to use.”
This is critical for organizations looking to expand their threat intelligence efforts, as it allows them to leverage existing work. Because it provides a perspective that identifies and analyzes a hacker’s behavior, a more offensive view of potential threats can be considered alongside the defensive posture of most current risk assessment frameworks.
Interestingly, many security vendors and consultants publish whitepapers discussing how their products and services can support clients’ efforts to implement ATT&CK as part of their overall security program. They include Microsoft, IBM, Splunk, Palo Alta Networks, and CrowdStrike. In some instances, the vendor will specify how their product addresses ATT&CK recommendations by providing a specific reference to the recommendation.
Despite its significant involvement in cybersecurity governance, the ATT&CK framework is not well known within the accounting community. A popular explanation for this is that ATT&CK’s has a greater technical emphasis compared to more business- or balanced-focused frameworks. In many organizations, elevating cybersecurity and other technology topics was challenging enough. In the case of CoBIT (Control Objectives for Information and Related Technologies), it is tied to COSO (Committee of Sponsoring Organizations of the Treadway Commission) and focuses on governing and managing information technology or information security functions.
By its nature, ATT&CK needs to be much more technical. For those without cybersecurity expertise, ATT&CK can be overwhelming, as it reflects the extensive range of options that attackers may use to achieve their objectives. Although some of the attacks are easier for a financial expert to understand (e.g., configurations that do not comply with policy), most of the attacks identified by ATT&CK do require some level of technological sophistication.
Lessons can be learned from when the defensive frameworks were first introduced to audit and governance-related committees. When first introduced, these executives were unaware of core cybersecurity concepts with which they are familiar today. Many advisors converted the framework diagrams into heat maps using the traditional red, yellow, and green color codes. The colors would then inform decisionmakers of the issue’s status. They would then govern by the color of the box, rather than focus on the technical details. This can also be done for the ATT&CK model. For example, attacks coded in red would indicate a high likelihood that the organization will be successfully attacked using the attack method described in the ATT&CK framework.
The Framework
Tactics and techniques are presented in an easy-to-reference organization chart interface. These are known as matrices within the framework. Different matrices address the various technological environments used by many midsized and larger companies. Higher-level matrices include enterprise (where most organizations will start), mobile technology, and industrial control systems. Providing a visual representation of the framework, the matrices summarize the tools and techniques for the attacks analyzed. For many serving in governance functions, this understanding should be sufficient for overseeing information security. The framework then presents the adversarial methods (tactics) using the typical stages of an attack.
A brief outline of the 14 tactics, along with a one-line description, is available on the ATT&CK website (https://tinyurl.com/2vn9h75v). By clicking the tactic, a more detailed description and applicable techniques (per their website, the “how” by which an adversary achieves a tactical goal through an action) are displayed. These are helpful for those preparing reports for governance committees and for managers who oversee technical security engineering activities. The summary outline could easily be used as a heat map to demonstrate the priority and likelihood of attacks, as well as their mitigation.
From the enterprise perspective, a detailed matrix with easy-click access to further information is available for technology environments (referred to as platforms within ATT&CK), including Windows, MacOS, Linux, Cloud, Network Devices, Containers, and ESXi (VMware). Another platform, PRE, focuses on the actions attackers take to research and prepare for their attacks. The general population, and thereby business executives, would probably be more familiar with these less technical activities.
Getting Started
Even for technically competent information security professionals, ATT&CK can appear overwhelming. Fortunately, much guidance is provided, and non-MITRE organizations offer support as well. The developers of ATT&CK created “Getting Started with ATT&CK” in order to help new users consider and implement the ATT&CK framework (https://tinyurl.com/39u8y2cx). Although slightly technical and geared towards information security professionals, it can jumpstart efforts even for partial or gradual implementations. It’s not expected that an accounting or finance professional will become an expert in the framework, but rather that they will understand what it is. This should facilitate conversations within their organizations to determine whether cybersecurity risks should be viewed from an offensive perspective in addition to current defensive practices.
Cybersecurity risk management continues to evolve. Attackers continuously and rapidly adapt their approaches to exploit vulnerable companies. The ATT&CK framework provides defenders with an alternative way to consider threats, thus minimizing harm. Additionally, it provides decision-makers and those responsible for governance with a heightened, realistic perspective on the challenges they face in defending their organization. This could also serve as a basis for requesting and justifying necessary future investments.





























