Which ATT&CK matrix scopes an estate whose flat segment mixes office hosts with building-automation controllers?
answer
- scope by asset group, not by estate
- naming a matrix names what is out of scope
- two denominators, never one blended figure
- the shared segment is the finding
- no authentication in the specification, so no patch
basics
~20 sBoth, scoped per asset group rather than per estate: Enterprise for the office hosts, ICS for the controllers. The decision matters because naming a matrix names which adversary goals are in scope, and therefore whose budget owns the gap between them.
solid answer
~50 sRefuse the single-matrix framing. Scope Enterprise over the office hosts and ICS over the building-automation controllers, and treat the shared broadcast domain as a named finding in its own right with an assigned owner. Choosing Enterprise alone is not a modelling shortcut — it is a decision that the plant-side goals, such as driving a process to a state nobody chose, are out of scope, which quietly makes them nobody's problem. Choosing ICS wholesale imports columns you cannot honestly claim to address for a print server, and drags in an asset owner who never agreed. The organisational sting is that the controllers usually sit under a facilities maintenance contract: their protocol has no authentication in the specification, so there is no patch and no setting, only a control class that removes reachability — a different budget from the one funding the assessment.
go deeper
Know that a mixed office and building-automation estate is not covered by one ATT&CK matrix, and that the controllers belong to the ICS matrix even when they share a network with laptops.
Explain why the split is per asset group and why results cannot be summed: the two matrices have different tactic columns and different technique populations, so there is no shared denominator.
Show that the shared broadcast domain is the finding, and reason about control class: with no authentication in the protocol specification there is nothing to patch, so only removing reachability changes the outcome.
Own the scope decision as an allocation of accountability — who signs for the accepted residual, whose contract has to change at renewal, and why one tidy matrix figure would have hidden the only item needing a budget holder.
## Why this is a decision and not a lookup An estate that is neither pure office nor pure plant forces a choice that looks technical and is mostly organisational. A flat office segment carries laptops, a print server, IP cameras and two building-automation controllers on one broadcast domain. Somebody asks which ATT&CK matrix the estate is measured against. Naming a matrix is naming a set of adversary goals you accept as in scope. That is why the answer allocates work and budget, and why it cannot be settled by asking which matrix has more techniques. ## What each single-matrix answer actually decides **Enterprise only.** Convenient, and it matches how the organisation is staffed. But the ICS matrix exists precisely because Enterprise has no columns for impairing process control or inhibiting a response function. Choosing Enterprise alone declares those goals out of scope for an estate that physically contains the devices they apply to. Nothing in the resulting document is false; the omission is the decision. **ICS only, or ICS wholesale.** Overcorrection. Applying the ICS matrix across an estate that is 95% laptops means claiming to address columns that have no meaning for a print server, and it changes who the document is addressed to. It also tends to import an asset owner — facilities, or their contractor — who was never asked and has no obligation under the assessment's terms of reference. **Both, per asset group.** The defensible answer. Enterprise scopes the office hosts, ICS scopes the two controllers, and the two results are reported against two named matrices with two denominators. No blended percentage, because there is no shared denominator to blend. ## The crossing point is the deliverable The interesting output of the split is not either mapping. It is the thing that falls between them: the shared broadcast domain. The adversary position that matters here is unauthenticated, on the segment, with no account anywhere — reachability is the whole of the access. A commodity criminal firing one public exploit at every reachable instance does not need to be sophisticated to reach a controller that will obey any protocol-legal command, because the control protocol's specification contains no authentication at all. That has a hard consequence for control selection. There is no patch, because nothing is broken. There is no setting to enable, because the specification never defined one. Credential controls do not apply, because there is no credential in the exchange. The only class of control that removes what this depends on is one that removes reachability between the office segment and the controllers. Every other class leaves the dependency intact. ## Where the organisational constraint bites Three constraints usually apply at once, and a principal-level answer names them rather than assuming them away: 1. **Ownership.** Building automation is frequently owned by facilities, not IT, and operated under a maintenance contract. The people who can change the controllers do not report to the people who commissioned the assessment. 2. **Contractual refusal.** Maintenance terms commonly prohibit configuration change and void support for anything the vendor did not install. The contractor can simply decline, and be within their rights. 3. **Replacement economics.** The controllers may have a fifteen-year service life and no authenticated successor product. "Replace them" is a capital project on someone else's plan, not a remediation item. So the achievable outcomes are usually: reduce reachability with something IT owns and can change unilaterally; accept the residual with a named accepting owner and a review date; and put an authentication requirement into the next contract renewal or refresh cycle, since that is the only moment the constraint moves. ## What to say in the room A strong answer does four things. It refuses the single-matrix question and says why the framing is the problem. It proposes scoping per asset group with two named denominators. It elevates the shared segment from an implementation detail to the finding, because that is where the two matrices meet and where the only effective control class sits. And it names an owner and a decision route for the part IT cannot fix — including the possibility that the correct outcome is a documented, accepted, reviewed risk rather than a fix. The failure mode to avoid is a tidy document. Picking one matrix produces a cleaner report and hides the one conclusion that needed a budget holder's signature.
- The facilities contractor refuses any change to the controllers. What is the deliverable then?A named, accepted residual risk with a review date, plus whatever reachability reduction IT can make unilaterally on its own side of the segment, plus an authentication requirement written into the next contract renewal or refresh. The point is that acceptance is a decision with an owner and a date, not the absence of one. An assessment that records refusal and stops has produced nothing anyone can act on.
- Why not report one blended percentage across both matrices for the board?Because there is no shared denominator. Enterprise and ICS have different tactic columns and different technique populations, so a blended figure is not comparable with anything, including your own previous figure if the asset mix shifts. Report two numbers against two named matrices. A single number is more legible and asserts something that is not true.
- Which ATT&CK matrix scopes the IP cameras and the print server on that same segment?Enterprise, in practice — they run general-purpose operating systems and network services, and the adversary goals against them are Enterprise goals. The reason to mention them at all is reachability: they sit on the same broadcast domain as the controllers, so they are candidate footholds for an unauthenticated attacker with nothing but segment access, which is what makes the segment itself the finding.
saying these in an interview costs you the question
- Picks one matrix to keep the report tidy
- Treats matrix choice as a modelling detail rather than a scope decision
- Blends Enterprise and ICS results into one percentage
- Assumes IT can change controllers under a facilities contract
- Recommends patching a protocol that never specified authentication