Threat
A threat is any circumstance or event that has the potential to cause harm to an organization, its operations, or its assets. Threats can come from outside the organization or from within, such as an insider misusing their authorized access. On its own, a threat represents a source of potential harm rather than harm that has already occurred.
In risk management, a threat is any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, or other organizations. A threat is a source or agent of potential harm and should be distinguished from vulnerability (a weakness that a threat may exploit) and from risk (the effect of uncertainty on objectives, commonly assessed in terms of the likelihood a threat materializes and its resulting impact). Threats may be external or internal; an insider threat, for example, is the potential for an insider to use their authorized access or understanding of an organization to harm that organization. The scope and treatment of specific threats vary by context, sector, and jurisdiction; this entry does not address implementation, tooling, or legal definitions applicable in criminal contexts.
Why it matters
The concept of a threat sits at the foundation of risk assessment. Because a threat is a source of potential harm rather than harm that has already occurred, identifying and cataloguing threats is what allows an organization to reason about what could go wrong before it does. Without a clear inventory of the circumstances and events that could adversely impact operations, assets, individuals, or reputation, risk assessments lack the raw material needed to estimate likelihood and impact and to prioritize treatment.
Precision matters here because threat is frequently conflated with related but distinct concepts. A threat is not the same as a vulnerability, which is a weakness that a threat may exploit, nor is it the same as risk, which is commonly understood as the effect of uncertainty on objectives and is typically assessed in terms of how likely a threat is to materialize and the severity of its resulting impact. Treating these terms as interchangeable can distort an organization's understanding of its exposure and lead to misdirected controls.
Threats may originate outside the organization or from within. Insider threats, defined by CISA as the potential for an insider to use their authorized access or understanding of an organization to harm that organization, illustrate why threat identification cannot focus solely on external actors. The scope and treatment of specific threats vary considerably by context, sector, and jurisdiction, so what constitutes a material threat in one setting may not be relevant in another.
Who it's relevant to
Inside Threat
Common questions
Answers to the questions practitioners most commonly ask about Threat.
