Most senior executives have a working model of the cyber threat that goes something like this: ransomware gangs encrypt systems and demand payment. Nation-states target governments and defence contractors. The company is exposed to the first category, maybe, but not really the second.
This model is wrong in ways that directly shape how security budgets get allocated and what controls get prioritised. Worth correcting.
The Motive Difference Is the Starting Point
Criminal ransomware groups want money. Nothing else. Their behaviour is predictable precisely because it follows from that motive with rigid consistency: find a target where disruption creates leverage, encrypt, demand payment, leave. They don’t care about your intellectual property. They’re not building a persistent picture of your commercial relationships. Once the transaction is complete (one way or another) they’re gone.
Nation-state actors have different objectives, and those objectives vary meaningfully between states.
Russia’s cyber operations against Western commercial targets have focused on intelligence collection supporting sanctions monitoring, gathering material on political figures and their advisors, pre-positioning in critical infrastructure for potential future use, and, particularly since 2022, supporting information operations by gathering and selectively leaking material that shapes public narratives. Some of what looks like criminal activity from Russian-nexus actors is better understood as state-directed operations with financial cover.
China’s primary objective against commercial targets is long-term economic espionage. Patient, sustained collection of intellectual property, trade secrets, M&A intelligence, and commercial data across any sector where the information has long-term strategic value. Pharmaceutical research. Aerospace manufacturing. Semiconductor design. Financial services. Chinese state actors are not making targeted decisions about which specific company to hit this quarter. They’re running persistent, broad-spectrum collection across sectors of strategic interest.
Iran targets organisations with visibility into Gulf state affairs, Jewish community organisations, Western defence contractors, and energy infrastructure in US-allied states. North Korea is the outlier in this group: a state actor with genuine financial motivations, responsible for some of the largest cryptocurrency thefts on record, using cyber operations partly to generate revenue under sanctions pressure.
”We’re Not a Target” Is Usually Wrong
The boardroom assumption that nation-state activity is reserved for governments and prime contractors has never been entirely true. It’s increasingly untenable.
During the COVID-19 pandemic, vaccine research programmes were targeted by multiple state actors (Russian intelligence most prominently), not to prevent vaccination, but to collect intelligence and secure leverage. The pharmaceutical sector didn’t consider itself a geopolitical target. It was one.
Financial services firms are targeted for intelligence about sanctions effectiveness, capital flows, and commercial decision-making at scale. Law firms handling M&A are targeted for deal intelligence: what’s being acquired, on what terms, by whom. Technology companies are targeted for source code and roadmaps. Universities for any research with dual commercial and strategic value.
The question isn’t “are we important enough?” It’s “what do we have that a state actor might want?” The honest answer, for almost any substantial commercial organisation, is something. Customer data, proprietary processes, financial positions, commercial relationships, or simply access to systems that serve as useful footholds in a network a patient adversary is slowly mapping. The organisations that have been most surprised by nation-state intrusions are usually ones that answered the first question rather than the second.
They Operate on a Different Timescale
This is the operational difference that matters most for detection and defence.
Ransomware affiliates move fast. Initial access to ransom demand can happen in hours. The urgency is commercial: the faster they encrypt, the less time defenders have to respond. This creates a detectable signature: rapid lateral movement, mass encryption activity, observable data staging before exfiltration.
Nation-state actors have no equivalent urgency. Volt Typhoon maintained access in US critical infrastructure systems for at least five years in some documented cases. Five years. The goal is persistence and collection, not speed, and every operational decision reflects that. They use built-in Windows administration tools, legitimate remote access software, and credentials obtained through phishing rather than deploying custom malware that signature-based detection would flag. They may only act on a fraction of the access they’ve established, and only when circumstances call for it. Your clean penetration test result from last quarter doesn’t tell you whether you’re currently hosting a persistent presence that hasn’t been tasked to do anything yet.
This is what “living off the land” means in practice: the adversary’s tools are indistinguishable from your legitimate administrative traffic, which is exactly why standard detection misses them.
Different Threat, Different Controls
The defensive priorities for criminal ransomware and nation-state threats overlap partially, but not completely.
For ransomware, the high-return controls are well-known: current patch state on externally-facing systems, MFA on remote access, offline backups, network segmentation. These work because criminal actors are opportunistic: high friction means they move on to softer targets.
Nation-state defence requires additional investment that most commercial organisations haven’t made: comprehensive logging with retention periods measured in months, not weeks; anomaly detection capable of identifying subtle patterns rather than just known signatures; regular threat hunting that goes beyond automated alerting; and genuine participation in the intelligence-sharing programmes that NCSC and sector bodies run.
The budgets are different. The skills required are different. The specialist suppliers who can actually help are a different set of firms.
The board conversation is different, too. A risk picture framed entirely around ransomware probability and ransom quantum is missing a threat class that is harder to detect, more difficult to fully remediate, and potentially more consequential in the long run, even if it never generates a headline.