There is a newer version of the record available.

Published July 14, 2026 | Version 2.3.1

A Cause-Oriented Cyber Threat Taxonomy: The Top Level Cyber Threat Clusters Framework

Authors/Creators

  • 1. Barnes Projects

Description

Cybersecurity discourse routinely uses the term "cyber threat" to denote several distinct concepts at once: the cause of a compromise, its outcome, the actor responsible, and the technique employed.
This conflation impedes consistent classification, comparable incident documentation, and clear communication of cyber risk between leadership, risk functions, and technical teams.
Established frameworks address adjacent layers — control objectives, adversary techniques, software weaknesses, and quantitative risk — but none provides a compact, non-overlapping taxonomy on the cause side that holds stable across system types.
 
The Top Level Cyber Threat Clusters (TLCTC) framework proposes ten top-level threat clusters, each defined by the single generic vulnerability it initially targets.
The taxonomy separates threats (causes) from system events, data risk events, business consequences, and actor identity.
This paper presents the framework's derivation logic, its design principles and threat topology, the ten cluster definitions, the ten axioms that constrain interpretation, and the classification rules that keep assignment reproducible, together with example mappings expressed in an attack-path notation.
 
By distinguishing a stable strategic management view from a concrete operational security view, TLCTC functions as a translation layer linking strategic risk governance, security operations, and secure software development.

Notes

v2.3.1 (erratum, 2026-07-01). Single axiom-conformance correction to cluster #4 Identity Theft. The generic-vulnerability field is retightened from "Weak identity management processes and/or inadequate credential protection mechanisms throughout the identity lifecycle" to "Insufficient binding, at the point of authentication, between a presented credential and the authentic holder of the identity it claims." The Developer's-view field is narrowed to authentication-time controls (MFA, session binding/validation, replay/reuse detection, least privilege), and a clarifier records that credential storage/transmission failures classify to the enabling cluster (#2/#5/#7/#8), per R-CRED and Axioms VI/VII/X. Cluster identity, identifiers (#4 / TLCTC-04.00), definition, attacker's view, topology, and all boundary tests are unchanged; no other cluster is affected. No change to the abstract, structure, or any other section. Full rationale and before/after in tlctc-v2.3-traceability.md.

Files

tlctc-v2.3-core.pdf

Files (701.3 kB)

Name Size Download all
md5:51307dd9c391f43b83e1c9b8eb2530e7
701.3 kB Preview Download

Additional details

Related works

Is described by
Project milestone: https://www.tlctc.net (URL)
Is supplemented by
Dataset: https://github.com/Barnes70/TLCTC (URL)

Software

Repository URL
https://github.com/Barnes70/TLCTC
Development Status
Active