◆ Mapping · Splunk/Cisco → TLCTC v2.3

Top 50 Cybersecurity Threats
Through the TLCTC Lens

Splunk/Cisco's report catalogs threats by what happens. TLCTC classifies by why compromise is possible — the generic vulnerability exploited. This comparison reveals the causal structure behind each threat.

Splunk asks
“What is the threat?”
TLCTC reveals
“Why does it work?”
TLCTC Cluster Distribution across Splunk's Threats

Taxonomy Critique: Six Problems in One List

The Splunk/Cisco report markets itself as a “Top 50” threat list, but it actually contains 53 entries that conflate at least six fundamentally different classification axes into one flat ranking. When causes, outcomes, actor labels, control failures, evasion techniques, and specificity levels are treated as interchangeable, the resulting list cannot answer the question it implies: “What should we defend against?”

6not threats (outcomes, actors, control failures)
5near-duplicate entries across chapters
7entries for a single TLCTC cluster (#9)
6different grouping axes across 8 chapters

Outcomes disguised as threats

Data exfiltration and ransomware encryption are consequences of compromise, not causes. Listing them as threats is like listing “bleeding” as a disease. TLCTC Axiom III: threats exist on the cause side; outcomes are Data Risk Events.

#2 Data Exfiltration #13 Data Exfil (Cloud) #39 Ransomware (partly)

Actor labels disguised as threats

“APT” describes who is attacking and how patient they are. “Insider Threat” describes where the attacker sits. Neither tells you which generic vulnerability is exploited. TLCTC Axiom IV: actor identity must never determine classification.

#1 APT #22 Insider Threat

Control failures disguised as threats

A misconfigured S3 bucket is not an attack — it is a door left open. The attack is what walks through the door. TLCTC Axiom V: control failures create exposure; exploitation is the threat.

#12 Cloud Misconfig #16 Exposed Databases #19 Shadow IT

Operational traits disguised as distinct threats

A “zero-day” is a patch-availability status, not a vulnerability class. “Polymorphic” describes an evasion wrapper. “Living off the land” describes tool selection. None of these change the generic vulnerability exploited — they are operational modifiers on real threats.

#5 Zero-Day Exploit #38 Polymorphic Malware #36 Living off the Land #37 Malware C2

Near-duplicate entries across chapters

The same concept appears multiple times under different surface labels, inflating the count and fragmenting detection logic. A “top 50” that double-counts is not a top 50.

#2 ≈ #13 Data Exfiltration #11 ≈ #15 Resource/Cryptojacking #14 ≈ #48 Insecure APIs / API Exploit #22 ≈ #23 Insider Threat / Misuse #34 overlaps #33 BYOVD

Granularity chaos: one cluster, seven entries

Social Engineering, Phishing, Spear Phishing, Smishing, BEC, Vishing/Deepfake, and SIM Hijacking all exploit the same generic vulnerability: human psychological susceptibility. The report gives 7 entries to #9 while #5 MitM, #6 Flooding, and #8 Physical get one each. Specificity is applied selectively — there is no consistent zoom level.

#41 BEC #42 Deepfake/Vishing #43 Phishing #44 SIM Hijacking #45 Smishing #46 Social Engineering #47 Spear Phishing

Inconsistent chapter grouping axes

The 8 chapters use at least 6 different organizing principles simultaneously. No two chapters apply the same classification axis, making cross-chapter comparison meaningless.

ChapterStated scopeActual grouping axis
Ch 1Advanced & EmergingNovelty / severity
Ch 2AI ThreatsTechnology domain
Ch 3Cloud & SaaSDeployment model
Ch 4Identity & CredentialTarget asset
Ch 5Network & InfrastructureOSI layer
Ch 6Malware & ExploitsTechnique category
Ch 7Phishing & Social EngineeringTechnique category
Ch 8Web & ApplicationAttack surface

Why this matters

A taxonomy that mixes classification axes cannot produce non-overlapping categories. Entries inevitably appear in multiple chapters (an API exploit is also a web attack, a cloud threat, and potentially an AI threat), duplicates inflate the count, and defenders cannot derive a finite set of controls from the list. TLCTC solves this with a single classification axis: the generic vulnerability exploited. Ten clusters. Non-overlapping. Every attack step maps to exactly one.

# Threat Chapter TLCTC Clusters Type Rules

Methodology & Key Principles

Each of Splunk/Cisco's threats was analyzed against the TLCTC v2.3 framework axioms and classification rules. The mapping follows these principles:

Source: "Top 50 Cybersecurity Threats", Splunk (a Cisco company), 2025. The report describes 53 individual threat entries across 8 chapters.