What is a "Threat Matrix" of adversary versus intent, and what does each axis represent?
A Threat Matrix maps types of adversary (rows) against types of target (columns) and fills each cell with the intent — the kind of harm that actor would pursue against that target.
* Threat Matrix — adversary types (rows) × target groups (columns); each cell names the intent, colour-coded. *
In this version the rows are adversary types — state/state-sponsored, criminals, terrorists, hacktivists, cyber vandals/script kiddies, insiders, and unintentional actions — and the columns are target groups: government, critical infrastructure, private companies, and citizens. Each cell names the intent, such as espionage, sabotage, disruption, system or information manipulation, information theft, outage/failure, or leak. WHY it helps: it turns "we have threats" into a structured grid where you can quickly read off who would target you and what they would try to do — the basis for picking a realistic threat actor in step 3.
Go deeper:
ENISA Threat Landscape — Europas jährlicher Überblick über Bedrohungsakteure (Staaten, Kriminelle, Hacktivisten …) und ihre Motive — die Evidenzbasis für eine solche Matrix.