The shortcut that always had an answer
I removed the step that turned one industry classification into another. About one answer in five was confidence it had no basis for. Last updated: 2026-08-22
I removed a piece of this site that was quietly making things up. It was a crosswalk: a lookup table that turned an industry code from one system (NAICS) into an economic-sector code from another (the LSEG business classification, TRBC). It always returned an answer. That was the problem. When I replaced the lookup with a step that classifies each industry directly, about one answer in five turned out to be confidence the shortcut had no basis for.
Measured 2026-07-25 across the actor target-sector classifications authored by the extractor, against the codes the retired crosswalk would have produced for the same industries.
What a crosswalk is, and why it flatters itself
A crosswalk is a fixed table: NAICS 22 (Utilities) becomes TRBC 59 (Utilities), NAICS 522 (Banking) becomes TRBC 5510 (Banking and Investment Services), and so on. It is convenient. Feed it a code from one taxonomy and it hands back a code in the other, every time. But the two taxonomies were built by different people for different purposes, and they do not partition the economy the same way. Forcing one onto the other invents a precision that neither system actually claims.
Two failures follow, and they run in opposite directions. Sometimes the table maps to a sector that is close but wrong. More often it answers confidently where an honest look at the specific industry would shrug. In this data, the shortcut asserted an economic sector for roughly one industry in five where the direct pass, reading what the industry actually is, declined to commit to one.
The clean example
Take the group commonly tracked as Sandworm, which public reporting associates with attacks on electric utilities and on government bodies. The old shortcut turned the "Public Administration" industry code into the TRBC sector for "Institutions, Associations and Organizations." That is the bucket for trade groups and nonprofits. It is not government. Classified directly, the same target lands in "Government Activity," which is a distinct sector in this taxonomy and the correct one. The shortcut was not being subtle; it was applying a rule that had no way to tell a ministry from a membership association.
This is a rule here, not a one-off
The principle is simple and it is now a standing rule for this site: every mapping between frameworks is authored directly for that pair. I do not chain one mapping through another to reach a third, and I do not run a generic crosswalk to fill in a taxonomy I did not measure. Where a direct mapping does not exist, the honest output is nothing. An absent value beats a derived one, because a derived value looks like knowledge and is really just a rule firing.
This is the same reason our vulnerability pages stopped deriving compliance-control mappings by chaining a weakness through two intermediate frameworks, and the same reason we map weaknesses to attack techniques directly rather than through the public chain that loses most of its links along the way. Each of those chains reads as data. Each is really a guess wearing a lab coat.
Why a buyer should care
If a product shows you a precise readout of which sectors an actor targets, or which control a vulnerability maps to, ask one question: was that classified, or was it derived. Derived precision is the kind you cannot audit. It will be internally consistent and often plausible, and it will be wrong in ways you have no way to see, because the error is baked into a table you never get to inspect. For a resource constrained team that is going to act on the readout, the difference between a measured answer and a manufactured one is the difference between a decision and a coin flip with good posture.
The takeaway
Removing the crosswalk made this site show fewer sector labels, not more. About one in five of those labels are now blank where they used to be filled. That is the improvement. The blanks are honest, and the labels that remain are ones I can defend one entry at a time. A system that can say "I do not know" is worth more than one that always has an answer.