What makes it different
Most attacks are opportunistic and aim for quick money. APT groups choose specific targets, such as governments, defence, energy, technology companies and their suppliers, and are patient. They use custom tools, zero day exploits and spear phishing, move slowly through the network and rely on legitimate tools to avoid detection.
Why smaller companies are affected
An SME is rarely the final target, but it can be the way in. APT groups often compromise suppliers, software vendors or service providers to reach their real objective, which is why supply chain security and TPRM have become regulatory priorities.
How they are tracked
Security researchers give APT groups names or numbers and document their techniques in frameworks like MITRE ATT&CK. This threat intelligence helps defenders know which techniques to look for.
Defending against them
No single control stops a determined APT. What makes the difference is reducing the time an attacker can stay hidden: continuous monitoring with EDR and a SIEM, a SOC that investigates unusual behaviour, strong identity controls, network segmentation and logs kept long enough to investigate.




