MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour
How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.
Why it matters
What this means for organisations holding critical data
How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.
Written by Mark Fermor. MITRE ATT&CK is the most widely used vocabulary for describing what attackers actually do. It is also one of the most widely misused, usually by being treated as a scorecard. This guide covers what it is, how to map to it honestly, and what a mapping does not tell you.
What ATT&CK is
ATT&CK is a curated, publicly available knowledge base of adversary tactics and techniques observed in real intrusions. It is maintained by MITRE and organised into matrices, principally Enterprise, Mobile and ICS. It is not a framework of security outcomes, not a compliance standard, and not a threat intelligence feed. Nothing certifies against it.
It is also not static. MITRE revises and versions the matrices, adding techniques, renaming them, restructuring them into sub-techniques and deprecating others. Any mapping you build is a snapshot against a version, and needs periodic review or it silently decays.
The structure
- Tactics are the adversary's objectives, such as Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration and Impact.
- Techniques are how an objective is achieved, each with an identifier such as T1566 for Phishing.
- Sub-techniques refine a technique into specific variants, which matters because detection coverage is usually variant-specific.
- Groups and Software record which named threat actors and tools have been observed using which techniques.
- Mitigations and Data Sources connect techniques to defensive measures and to the telemetry needed to see them.
For operational technology, the ICS matrix is the relevant one. Its tactics include Inhibit Response Function and Impair Process Control, which have no Enterprise equivalent and which capture the outcomes that actually matter in a plant.
How to build a mapping that is not self-flattering
- Start from threat, not from the whole matrix. Select the groups and software plausibly relevant to your sector and geography, and work from the techniques they are recorded as using.
- Separate detection from prevention. "Covered" usually conflates the two. Record, per technique, whether you would prevent it, detect it, or only find it afterwards in forensics.
- Anchor claims to data sources. If the telemetry that a technique requires is not collected and retained, coverage is theoretical.
- Validate by emulation. Purple team exercises and atomic tests convert an assumption into evidence. A control that is enabled but misconfigured looks identical to a working one on a heat map.
- Record the version. State which ATT&CK version the mapping was built against and when it will be reviewed.
- Weight by consequence. A partially covered Impact technique that would halt production matters more than full coverage of a Discovery technique.
What a heat map does not tell you
Three limitations are worth stating plainly. ATT&CK records observed behaviour, so novel or unreported techniques are absent by construction. Coverage of a technique says nothing about the speed of response, which is usually the variable that decides incident outcome. And an all-green matrix is a strong signal of optimistic self-assessment rather than strong defence.
Using ATT&CK with frameworks that do certify
ATT&CK complements outcome frameworks rather than competing with them. Use NIST CSF 2.0 or the NCSC Cyber Assessment Framework to decide which outcomes matter and how they are governed; use ATT&CK to test whether the detection and response outcomes actually hold against behaviour seen in the wild. In an industrial context, pair the ICS matrix with ISA/IEC 62443 zone and conduit design, since lateral movement techniques are precisely what a conduit definition constrains.
Techniques that architecture answers better than detection
Some techniques are far more efficiently addressed by removing the opportunity than by improving the alert. Data Encrypted for Impact, Inhibit System Recovery, Exfiltration Over Web Services and Remote Services for lateral movement all depend on a reachable path existing at the moment of the attack.
This is the narrow area Firevault works on. Control by Firevault is a suite of nine purpose-built tools and techniques giving physical control over the paths into and across an estate, applied through Blueprints that treat a specific risk, which is relevant where a path used for lateral movement or command and control does not need to exist continuously. Offline Secure Storage® holds selected recovery and evidential material on storage that is physically disconnected when not in use, so that data which is disconnected at the time of an attack is not reachable by encryption for impact or by recovery inhibition while it remains disconnected.
That is a statement about reachability, not immunity. Detection, response and rehearsed recovery remain necessary, and the assessment of which paths can safely be governed is an availability and safety question first.
Frequently asked questions
Is ATT&CK a compliance framework?
No. It is a knowledge base of adversary behaviour. It informs compliance work but certifies nothing.
Is it a threat intelligence feed?
No. It is curated and versioned rather than live, and it carries no indicators of compromise.
Should we aim to cover every technique?
No. Prioritise by relevance to your threat model and by the consequence of the techniques that would hurt most.
Enterprise or ICS matrix?
Both, where you run both estates. Intrusions into industrial environments typically begin in enterprise IT and cross into operations.
How Firevault would handle this
Controls an auditor can physically verify
Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.



Put this guide into practice
Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.
Takes about 2 minutes. No account needed.


