The HACT Matrix — tactics, techniques
Columns are tactics (the adversary's why); cells are techniques (the how). Click any cell for technique detail, or a column header for the full tactic. See also the Mind map, the Flowchart, the Response playbooks and the Arsenal (red-team methods by tactic).
HACT vs MITRE ATT&CK®
ATT&CK describes technical actions against systems; HACT describes cognitive maneuvers against decisions. Same two-level structure (tactics → techniques), different object.
HVE (Human Vulnerabilities and Exploits) are the human equivalent of CVEs: not software bugs but exploitable cognitive biases and psychological needs. A CVE is patched; an HVE is compensated for with structured vigilance.
Detection — Indicators of HUMINT Operation (IoH)
Where cyber uses binary Indicators of Compromise (IoC), human signals are weak and contextual. HACT applies a threshold rule instead of concluding on a single signal.
Source: Check Point / Dimensional Research, 2011, n=853 professionals, 6 countries. New employees should receive SE training within the first 30 days, before any access to sensitive systems.
Emerging AI-augmented threats
Generative AI industrializes social engineering. Click a card for the full indicator table and operational countermeasure.
Documented real-world cases
Each case is mapped to the HACT tactics it activated. Click a tactic tag to open it.
Defense — the five emergency reflexes
The whole framework condensed into five reflexes usable in under sixty seconds when facing any unusual request. See the decision-tree flowchart and the full Response playbooks.
Organizational maturity model
Most organizations sit between N1 and N2. The N2→N3 jump is the most impactful and the cheapest: a 2-hour annual training for at-risk populations plus written procedures for urgent requests. Recommended minimum target: N3.
Regulatory mapping (France / EU)
Implementing HACT countermeasures per tactic simultaneously satisfies several GDPR and NIS2 requirements.