Repeatedly trying possible credentials or keys.

Processes for restoring systems after major failures.

All possible points through which a system can be attacked.

Using stolen credentials against other services.

Ability to maintain critical operations during disruption.

Malicious software.

Trying a small set of passwords across many accounts.

Target time for restoring service after disruption.

Malware that can replicate by attaching to other files.

Attack attempting to make a service unavailable.