---
title: "MITRE ATT&amp;CK Guide: Mapping Controls to Real Ad… | Firevault"
description: "How to use MITRE ATT&amp;CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/learn/guides/mitre-attack-mapping-guide#webpage",
      "url": "https://fire-vault.com/learn/guides/mitre-attack-mapping-guide",
      "name": "MITRE ATT&CK Guide: Mapping Controls to Real Ad…",
      "description": "How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/mitre-attack-mapping-guide.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/learn/guides/mitre-attack-mapping-guide#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/learn/guides/mitre-attack-mapping-guide#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Guides",
          "item": "https://fire-vault.com/learn/knowledge?filter=guides"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour",
          "item": "https://fire-vault.com/learn/guides/mitre-attack-mapping-guide"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour",
      "description": "How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.",
      "url": "https://fire-vault.com/learn/guides/mitre-attack-mapping-guide",
      "image": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/mitre-attack-mapping-guide.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "datePublished": "2026-08-28T07:21:44.874262+00:00",
      "dateModified": "2026-08-28T10:12:43.171224+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/learn/guides/mitre-attack-mapping-guide"
      },
      "inLanguage": "en-GB",
      "articleSection": "Standards & Frameworks",
      "wordCount": 859,
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What ATT&amp;CK isThe structureHow to build a mapping that is n…What a heat map does not tell youUsing ATT&amp;CK with frameworks…Techniques that architecture ans…Frequently asked questionsMore

[Guides](/learn/knowledge?filter=guides)/ Standards & Frameworks 

Standards & Frameworks · 28 August 2026 

# MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour

How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

5 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fmitre-attack-mapping-guide)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fmitre-attack-mapping-guide&text=MITRE%20ATT%26CK%20Guide%3A%20Mapping%20Controls%20to%20Real%20Adversary%20Behaviour%0A%0AHow%20to%20use%20MITRE%20ATT%26CK%20properly%3A%20tactics%2C%20techniques%20and%20sub-techniques%2C%20the%20Enterprise%20and%20ICS%20matrices%2C%20coverage%20mapping%20without%20self-deception%2C%20and%20why%20version%20changes%20matter.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fmitre-attack-mapping-guide)[](mailto:?subject=MITRE%20ATT%26CK%20Guide%3A%20Mapping%20Controls%20to%20Real%20Adversary%20Behaviour&body=How%20to%20use%20MITRE%20ATT%26CK%20properly%3A%20tactics%2C%20techniques%20and%20sub-techniques%2C%20the%20Enterprise%20and%20ICS%20matrices%2C%20coverage%20mapping%20without%20self-deception%2C%20and%20why%20version%20changes%20matter.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Flearn%2Fguides%2Fmitre-attack-mapping-guide)

![MITRE ATT&CK Guide: Mapping Controls to Real Adversary Behaviour](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/guides/mitre-attack-mapping-guide.jpg)

Standards & Frameworks 

Why it matters

## What this means for organisations holding critical data

How to use MITRE ATT&CK properly: tactics, techniques and sub-techniques, the Enterprise and ICS matrices, coverage mapping without self-deception, and why version changes matter.

**On this page**[What ATT&amp;CK is](#section-0)[The structure](#section-1)[How to build a mapping that is n…](#section-2)[What a heat map does not tell you](#section-3)[Using ATT&amp;CK with frameworks…](#section-4)[Techniques that architecture ans…](#section-5)[Frequently asked questions](#section-6)

On this page

1.  [What ATT&amp;CK is](#section-0)
2.  [The structure](#section-1)
3.  [How to build a mapping that is not self-flattering](#section-2)
4.  [What a heat map does not tell you](#section-3)
5.  [Using ATT&amp;CK with frameworks that do certify](#section-4)
6.  [Techniques that architecture answers better than detection](#section-5)
7.  [Frequently asked questions](#section-6)

**Written by Mark Fermor.** MITRE ATT&CK is the most widely used vocabulary for describing what attackers actually do. It is also one of the most widely misused, usually by being treated as a scorecard. This guide covers what it is, how to map to it honestly, and what a mapping does not tell you.

## What ATT&CK is

ATT&CK is a curated, publicly available knowledge base of adversary tactics and techniques observed in real intrusions. It is maintained by MITRE and organised into matrices, principally Enterprise, Mobile and ICS. It is not a framework of security outcomes, not a compliance standard, and not a threat intelligence feed. Nothing certifies against it.

It is also not static. MITRE revises and versions the matrices, adding techniques, renaming them, restructuring them into sub-techniques and deprecating others. Any mapping you build is a snapshot against a version, and needs periodic review or it silently decays.

## The structure

-   **Tactics** are the adversary's objectives, such as Initial Access, Execution, Persistence, Privilege Escalation, Defense Evasion, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration and Impact.
-   **Techniques** are how an objective is achieved, each with an identifier such as T1566 for Phishing.
-   **Sub-techniques** refine a technique into specific variants, which matters because detection coverage is usually variant-specific.
-   **Groups and Software** record which named threat actors and tools have been observed using which techniques.
-   **Mitigations and Data Sources** connect techniques to defensive measures and to the telemetry needed to see them.

For operational technology, the ICS matrix is the relevant one. Its tactics include Inhibit Response Function and Impair Process Control, which have no Enterprise equivalent and which capture the outcomes that actually matter in a plant.

## How to build a mapping that is not self-flattering

1.  **Start from threat, not from the whole matrix.** Select the groups and software plausibly relevant to your sector and geography, and work from the techniques they are recorded as using.
2.  **Separate detection from prevention.** "Covered" usually conflates the two. Record, per technique, whether you would prevent it, detect it, or only find it afterwards in forensics.
3.  **Anchor claims to data sources.** If the telemetry that a technique requires is not collected and retained, coverage is theoretical.
4.  **Validate by emulation.** Purple team exercises and atomic tests convert an assumption into evidence. A control that is enabled but misconfigured looks identical to a working one on a heat map.
5.  **Record the version.** State which ATT&CK version the mapping was built against and when it will be reviewed.
6.  **Weight by consequence.** A partially covered Impact technique that would halt production matters more than full coverage of a Discovery technique.

## What a heat map does not tell you

Three limitations are worth stating plainly. ATT&CK records observed behaviour, so novel or unreported techniques are absent by construction. Coverage of a technique says nothing about the speed of response, which is usually the variable that decides incident outcome. And an all-green matrix is a strong signal of optimistic self-assessment rather than strong defence.

## Using ATT&CK with frameworks that do certify

ATT&CK complements outcome frameworks rather than competing with them. Use [NIST CSF](/solutions/control/frameworks/nist-csf) 2.0 or the NCSC Cyber Assessment Framework to decide which outcomes matter and how they are governed; use ATT&CK to test whether the detection and response outcomes actually hold against behaviour seen in the wild. In an industrial context, pair the ICS matrix with ISA/[IEC 62443](/solutions/control/frameworks/iec-62443) zone and conduit design, since lateral movement techniques are precisely what a conduit definition constrains.

## Techniques that architecture answers better than detection

Some techniques are far more efficiently addressed by removing the opportunity than by improving the alert. Data Encrypted for Impact, Inhibit System Recovery, Exfiltration Over Web Services and Remote Services for lateral movement all depend on a reachable path existing at the moment of the attack.

This is the narrow area Firevault works on. **Control by Firevault** is a suite of nine purpose-built tools and techniques giving physical control over the paths into and across an estate, applied through Blueprints that treat a specific risk, which is relevant where a path used for lateral movement or command and control does not need to exist continuously. **[Offline Secure Storage](/offline-secure-storage)®** holds selected recovery and evidential material on storage that is physically disconnected when not in use, so that data which is disconnected at the time of an attack is not reachable by encryption for impact or by recovery inhibition while it remains disconnected.

That is a statement about reachability, not immunity. Detection, response and rehearsed recovery remain necessary, and the assessment of which paths can safely be governed is an availability and safety question first.

## Frequently asked questions

### Is ATT&CK a compliance framework?

No. It is a knowledge base of adversary behaviour. It informs compliance work but certifies nothing.

### Is it a threat intelligence feed?

No. It is curated and versioned rather than live, and it carries no indicators of compromise.

### Should we aim to cover every technique?

No. Prioritise by relevance to your threat model and by the consequence of the techniques that would hurt most.

### Enterprise or ICS matrix?

Both, where you run both estates. Intrusions into industrial environments typically begin in enterprise IT and cross into operations.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Control by Firevault governs the physical paths into your systems.**[Explore Control →](/solutions/control)

Keep a clean copy**Offline Secure Storage® holds a copy no attacker can reach.**[Why #OSS →](/why-oss)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

[Get started](/get-started)[Talk to the team](/demo)

**Custody**Named, access-controlled hardware in a Firevault Bunker 

**Evidence**Access windows and retrieval events are recorded 

**Separation**Physical isolation that satisfies offline copy requirements 

**Jurisdiction**Stored where your regulatory position requires 

## Continue learning

-   [
    
    ### ISA/IEC 62443 Guide: Zones, Conduits and Security Levels in Practice
    
    A practical guide to ISA/IEC 62443 for asset owners: how the series is structured, how zones and conduits are defined, what Security Levels mean, and how the standard relates to the Purdue Model.
    
    Read guide ](/learn/guides/iec-62443-guide)
-   [
    
    ### NCSC Cyber Assessment Framework Guide: Objectives, Principles and Evidence
    
    A practical guide to the NCSC Cyber Assessment Framework: the four objectives, the fourteen principles, how contributing outcomes are assessed, and what evidence satisfies an assessor.
    
    Read guide ](/learn/guides/ncsc-caf-guide)
-   [
    
    ### NIST CSF 2.0 Guide: The Six Functions and What They Ask You to Evidence
    
    A practical guide to the NIST Cybersecurity Framework 2.0: the six Functions including Govern, Tiers and Profiles, how to build a Current and Target Profile, and where physical controls contribute evidence.
    
    Read guide ](/learn/guides/nist-csf-2-0-guide)

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

![David Bailey](/assets/david-bailey-Dgqj8eaE.jpg)

![Kenny Phipps](/assets/kenny-phipps-CVyooRsR.jpg)

Online Now 

Concierge 

## Put this guide into practice

Ready to apply what you have learned? Explore how Control by Firevault governs the physical paths into your systems.

Takes about 2 minutes. No account needed.

Find Out

Free 2 mins No sign-up