| Category |
External Threats |
Internal Threats |
| Definition |
Threats that originate outside the organization’s network and target external-facing assets, people, or infrastructure |
Threats that originate within the organization, whether intentional or accidental, and occur inside the network perimeter |
| Examples |
Phishing attacks, domain spoofing, social media impersonation, malicious apps, dark web data sales, DDoS attacks, brand abuse |
Malware, ransomware, insider threats, credential misuse, misconfigured systems, compromised endpoints |
| Primary Motivation |
Financial gain, reputational damage, political or social causes, fraud, or disruption |
Data theft, monetary gain, sabotage, human error, or revenge |
| Attack Vector |
Outside-in: via the web, social media, app stores, email, or underground forums |
Inside-out: through compromised accounts, infected devices, internal access abuse, or employee mistakes |
| Detection Difficulty |
Often harder to detect without specialized tools; attacks happen beyond the firewall and on third-party platforms |
Generally easier to detect with enterprise-grade tools like SIEM, EDR, and XDR that monitor internal traffic and assets |
| Prevention Methods |
External threat intelligence, takedown services, brand and domain monitoring, social media protection, dark web monitoring |
Endpoint protection, employee training, access controls, patch management, firewalls, and behavioral analytics |
| Response Strategy |
Disruption and takedown of external threats, public attribution, digital footprint protection, continuous monitoring of external ecosystems |
Quarantine, patching, user offboarding, forensic investigation, system recovery, and containment within the network |
| Frequency |
Constant and opportunistic; increases with online exposure and brand recognition |
Less frequent but potentially more damaging when successful |
| Potential Damage |
Brand damage, customer trust erosion, data leaks, financial fraud, regulatory violations |
Operational disruption, ransom payouts, IP theft, compliance violations, financial loss |
| Real-World Examples |
Executive impersonation on social media, phishing sites using spoofed domains, stolen credentials on dark web forums, targeted DDoS on public services |
Ransomware attacks like NotPetya or LockBit, insider threats selling data, employees clicking malicious links on work devices |
| How ZeroFox Helps |
Detects and disrupts external threats with AI-driven intelligence, global takedown services, and analyst-vetted alerts beyond the perimeter |
Complements internal tools by surfacing external threats that may lead to internal compromise (e.g., leaked credentials or insider sales of access) |