New 2026 Ransomware Report: Why Every Year Becomes the Worst Year on RecordRead the Report
BlackKite: Home
Menu
Back to Glossary

Adversary Susceptibility Index™ (ASI™)

The Adversary Susceptibility Index is Black Kite's threat-actor monitoring capability. It maps specific threat actors and their known tactics, techniques, and procedures against a vendor's digital footprint to identify whether and how a named adversary could target that organization. Where the Ransomware Susceptibility Index® (RSI™) quantifies ransomware likelihood broadly, the ASI zeroes in on specific threat groups.

The Adversary Susceptibility Index™ (ASI™) is a Black Kite rating that measures how exposed a specific company is to a specific named threat actor. Rather than describing general risk, it matches an adversary group's confirmed targeting patterns and known techniques against a company's observable weaknesses, producing a per-actor view of vendor exposure.

ASI exists because a risk score doesn't tell you who is coming. A rating can say a vendor is weak. It can't say that the weakness it carries is the exact one a group currently running a campaign against your sector prefers to exploit. ASI turns passive risk ratings into actionable threat intelligence by naming the adversary, and for a third party risk management team that naming is what makes prioritization possible.

What Does the Adversary Susceptibility Index Measure?

It measures the fit between an adversary and a target. ASI takes what's known about a threat group, including who it targets and how it operates, and evaluates how well a given company matches the profile of the organizations that group successfully attacks.

This is a different question from general security posture. A vendor can look reasonable in aggregate and still be a strong match for one particular group, because that group specializes in exactly the weakness the vendor has. Volt Typhoon, Black Basta, and APT29 don't target the same organizations or use the same techniques, so a single risk number can't tell you how exposed a vendor is to any of them individually.

The output is per-actor rather than singular. A company carries an ASI rating across multiple tracked adversaries, which lets a risk team sort a vendor population by exposure to whichever group currently matters.

How Does ASI Map Threat Actors to Specific Vendors?

It maps them by comparing adversary tradecraft against vendor attack surface. Black Kite's threat actor monitoring capability builds the rating from three layers, and each one answers a question the layer above it raises.

Threat Actor Intelligence Narrows the Field

The first layer establishes which adversaries are relevant to you at all. Threat groups concentrate on particular regions and industries, so identifying the actors that target your sector and geography removes most of the global threat picture before any vendor analysis begins.

Threat Actor Profiles Supply the Technical Match

The second layer is the adversary profile itself, covering confirmed targeting patterns, the specific vulnerabilities that group exploits, and their tactics, techniques, and procedures mapped to the MITRE ATT&CK framework. That profile is what gets compared against each vendor's observable attack surface. Where an actor is known to exploit a class of internet-facing system, vendors running exposed instances of it rise.

Granular Visibility Shows the Reasoning

The third layer is the part that makes the rating usable in a conversation. ASI is visualized across multiple threat actors at once, and every rating carries its mapped findings and the direct reasoning behind the score. A vendor argues with a score. A vendor responds to evidence that a named group exploits the exact service they have exposed.

What Does ASI Surface That a Vendor List Cannot?

It surfaces the shape of the exposure, not just its size. Filtering a vendor population by a single adversary reveals patterns that a vendor-by-vendor review never produces, and two of them are structural risks Black Kite treats as core differentiators.

  • Concentration risk: when one adversary's profile lights up an unusual share of your vendors at once, you're looking at a shared dependency rather than a coincidence.
  • Cascading risk: an actor that reaches a vendor rarely stops there, and mapping actor exposure across tiers shows how far a single compromise would travel.

Scale is what makes the narrowing necessary. Black Kite's 2026 Supply Chain Vulnerability Report tracked Qilin across 89 countries with 1,066 victims, Akira across 55 countries with 692, and Clop across 52 countries with 522. These groups run campaigns, not opportunistic hits, and campaigns have shapes a risk team can anticipate.

How Is ASI Different From the Ransomware Susceptibility Index®?

ASI is organized around who attacks. RSI™ is organized around what happens. One indexes adversaries, the other indexes an outcome.

The Ransomware Susceptibility Index® predicts how likely a company is to suffer a ransomware attack, whoever carries it out. It's the right instrument when the concern is business interruption from encryption and extortion, which is the most common way a vendor stops functioning without warning.

The Adversary Susceptibility Index is the right instrument when the concern is a particular group. That happens more often than it used to. A government advisory names an actor targeting critical infrastructure. A sector peer is breached and attribution points at a known group. In each case the question isn't general susceptibility but exposure to that specific adversary. Most mature programs use both. RSI shapes the standing oversight tier. ASI drives the response when a named group becomes relevant.

Why Does Knowing Which Adversary Targets a Vendor Change Your Response?

Because adversaries are predictable in ways that generic risk is not. A group that consistently gains access through exposed remote services and moves laterally with a documented set of tools gives you a specific list of things to check and a specific list of things to ask your vendor to close.

Remediation Requests Become Concrete

You're asking a vendor to close the exposures a known group actually uses rather than to improve their posture generally. That request has a finish line the vendor can see.

Detection Improves on Vendor Integrations

The actor's techniques map to behaviors your own security team can hunt for, specifically on the integrations that vendor holds into your environment.

Escalation Becomes Defensible

Telling an executive that a critical vendor matches the profile of an actively campaigning group is an argument that survives a budget conversation. A generic risk score is not.

How Do Teams Use ASI When a Threat Actor Becomes Active?

They use it to convert a public advisory into a vendor-specific action list within hours. When an agency publishes a warning about a named group, the useful question is never what the group does in general. It's which of our vendors look like the ones this group has already compromised.

The sequence is straightforward in a platform built for it:

  • Filter the vendor population by alignment with that actor's tools, tactics, and procedures.
  • Sort by exposure level and check the mapped findings behind each ASI rating.
  • Send the actor-specific findings to those vendors with a remediation request tied to the exposures that matter for this campaign.
  • Raise monitoring on the integrations those vendors hold into your environment.

Speed is the constraint. The 2026 Supply Chain Vulnerability Report found that the median handoff from initial access to a ransomware operator has fallen to 22 seconds, down from eight hours in 2022. Once an adversary reaches a vendor, the time available to act on that vendor is gone.

The downstream stakes justify the effort. A nation-state group compromising a managed service provider isn't primarily a problem for the provider. It's a problem for every organization whose systems that provider administers, and those organizations own the breach, the notification, and the recovery. Adversary mapping sits alongside Black Kite's wider vulnerability threat intelligence for exactly that reason. The Black Kite Cyber Villains and Threat Actors Dossier documents how these groups select and pursue targets across vendor ecosystems.

See also: Think Like a Hacker for Successful TPRM