GlossarySOC and monitoring

APT

Short answer

An APT (Advanced Persistent Threat) is a skilled, well resourced attacker, often linked to a state or a major criminal group, that gains access to a network and stays hidden for a long time to spy, steal data or prepare sabotage. The term also describes this type of long, targeted campaign.

What makes it different

Most attacks are opportunistic and aim for quick money. APT groups choose specific targets, such as governments, defence, energy, technology companies and their suppliers, and are patient. They use custom tools, zero day exploits and spear phishing, move slowly through the network and rely on legitimate tools to avoid detection.

Why smaller companies are affected

An SME is rarely the final target, but it can be the way in. APT groups often compromise suppliers, software vendors or service providers to reach their real objective, which is why supply chain security and TPRM have become regulatory priorities.

How they are tracked

Security researchers give APT groups names or numbers and document their techniques in frameworks like MITRE ATT&CK. This threat intelligence helps defenders know which techniques to look for.

Defending against them

No single control stops a determined APT. What makes the difference is reducing the time an attacker can stay hidden: continuous monitoring with EDR and a SIEM, a SOC that investigates unusual behaviour, strong identity controls, network segmentation and logs kept long enough to investigate.

Related terms

Keep reading on this topic

Continuous monitoring and response: EDR, SIEM, SOC operations, detection engineering and incident handling.

Go to the topic hub