Skip to main content
Category: Risk Analysis and Quantification

Threat

Simply put

A threat is any circumstance or event that has the potential to cause harm to an organization, its operations, or its assets. Threats can come from outside the organization or from within, such as an insider misusing their authorized access. On its own, a threat represents a source of potential harm rather than harm that has already occurred.

Formal definition

In risk management, a threat is any circumstance or event with the potential to adversely impact organizational operations (including mission, functions, image, or reputation), organizational assets, individuals, or other organizations. A threat is a source or agent of potential harm and should be distinguished from vulnerability (a weakness that a threat may exploit) and from risk (the effect of uncertainty on objectives, commonly assessed in terms of the likelihood a threat materializes and its resulting impact). Threats may be external or internal; an insider threat, for example, is the potential for an insider to use their authorized access or understanding of an organization to harm that organization. The scope and treatment of specific threats vary by context, sector, and jurisdiction; this entry does not address implementation, tooling, or legal definitions applicable in criminal contexts.

Why it matters

The concept of a threat sits at the foundation of risk assessment. Because a threat is a source of potential harm rather than harm that has already occurred, identifying and cataloguing threats is what allows an organization to reason about what could go wrong before it does. Without a clear inventory of the circumstances and events that could adversely impact operations, assets, individuals, or reputation, risk assessments lack the raw material needed to estimate likelihood and impact and to prioritize treatment.

Precision matters here because threat is frequently conflated with related but distinct concepts. A threat is not the same as a vulnerability, which is a weakness that a threat may exploit, nor is it the same as risk, which is commonly understood as the effect of uncertainty on objectives and is typically assessed in terms of how likely a threat is to materialize and the severity of its resulting impact. Treating these terms as interchangeable can distort an organization's understanding of its exposure and lead to misdirected controls.

Threats may originate outside the organization or from within. Insider threats, defined by CISA as the potential for an insider to use their authorized access or understanding of an organization to harm that organization, illustrate why threat identification cannot focus solely on external actors. The scope and treatment of specific threats vary considerably by context, sector, and jurisdiction, so what constitutes a material threat in one setting may not be relevant in another.

Who it's relevant to

Risk managers
Risk managers use threat identification as a core input to risk assessment, distinguishing threats from vulnerabilities and from risk itself in order to estimate likelihood and impact and to prioritize treatment. A well-maintained understanding of relevant threats supports more defensible risk registers and assessments.
Security and insider threat programs
Professionals responsible for physical, personnel, or information security must account for both external threats and insider threats, the latter being the potential for someone with authorized access or organizational knowledge to cause harm. Recognizing that insiders can pose threats shapes access, monitoring, and mitigation approaches.
Governance and compliance professionals
Those overseeing governance structures and compliance obligations rely on a clear articulation of threats to operations, assets, and reputation to ensure that policies and controls address relevant sources of potential harm. Because the scope of material threats varies by sector and jurisdiction, this audience must confirm which threats are applicable to their specific context.

Inside Threat

Threat source or actor
The origin of a potential harm, which may be human (such as a malicious insider or external attacker), environmental (such as a natural hazard), or systemic (such as a process failure). Threat sources may be intentional or accidental.
Threat event or action
The specific act or occurrence through which a threat source may cause harm, such as exploitation of a vulnerability, unauthorized access, or disruption of a service.
Target or asset
The organizational asset, objective, or resource that a threat could affect, such as information, systems, people, or operational continuity.
Relationship to vulnerability
A threat commonly becomes consequential where it can act upon a vulnerability. In many risk frameworks, threat and vulnerability are assessed together to estimate the likelihood of an adverse event.
Contribution to risk
Within risk management, a threat is typically one input to risk, alongside likelihood and impact. A threat represents potential harm rather than the assessed risk itself.

Common questions

Answers to the questions practitioners most commonly ask about Threat.

Is a threat the same thing as a risk?
No. A threat is a potential source or cause of harm, whereas a risk is the effect of uncertainty on objectives, commonly expressed as a combination of the likelihood of an event and its consequence. A threat is one input into risk assessment; it is not the risk itself. A given threat may give rise to several distinct risks depending on the assets, vulnerabilities, and objectives involved, and a threat that faces no exploitable vulnerability or valued asset may present little or no risk.
Does 'threat' only apply to cybersecurity?
No. While the term is prominent in information security, where it often refers to actors or events that may exploit vulnerabilities in systems, it is used more broadly across risk management. Threats may be natural, environmental, financial, operational, legal, reputational, or human in origin. The narrower cyber usage is a specialized application, not the full scope of the concept.
How should we distinguish a threat from a vulnerability when documenting risks?
It is common to treat the threat as the potential source or cause of harm and the vulnerability as the weakness or gap that the threat could exploit. When documenting, describe the threat (what could cause harm), the vulnerability (the condition that permits it), and the asset or objective affected as separate elements. Keeping these distinct supports clearer risk statements and helps target controls at the right point, though frameworks vary in the terminology and structure they prescribe.
Where can we source information to identify relevant threats?
Organizations commonly draw on a mix of internal and external inputs, which may include incident and loss history, control assessments, staff and subject-matter expertise, industry information-sharing arrangements, regulatory and supervisory guidance, and, for security contexts, threat intelligence feeds. The appropriate sources depend on jurisdiction, sector, and organization size. Selecting and validating sources is an organizational judgment; this entry does not endorse specific tools or providers.
How often should threats be reviewed or reassessed?
Many risk management approaches treat threat identification as an ongoing rather than one-off activity, with periodic reviews supplemented by reassessment when significant changes occur, such as new systems, processes, regulations, or notable incidents. The specific cadence typically depends on the organization's risk profile, applicable requirements, and the volatility of the threat environment, and is set through internal policy rather than a universal rule.
Which line of responsibility owns threat identification?
Responsibilities differ by organization, but in the three lines model described by the IIA, operational management in the first line typically identifies and manages threats within its activities, second-line functions such as risk and compliance provide oversight, frameworks, and challenge, and the third-line internal audit provides independent assurance over how threats are identified and managed. Assurance functions evaluate the process; they do not own the management of the threats themselves.

Common misconceptions

A threat and a risk are the same thing.
A threat is a potential source or cause of harm, whereas risk, in many frameworks, reflects the combination of likelihood and impact of that harm materializing against objectives. A threat is typically an input to a risk assessment rather than the risk itself.
A threat and a vulnerability are interchangeable terms.
A threat is the potential cause of harm, while a vulnerability is a weakness that a threat may exploit. They are distinct but related concepts, and many methodologies assess them jointly to estimate likelihood.
Threats are always deliberate and external.
Threats may be intentional or accidental and may originate internally, externally, or from environmental and systemic sources. Treating threats as only deliberate external acts can leave significant exposures unaddressed.

Best practices

Maintain a clear distinction between threats, vulnerabilities, and risks in assessments, documenting each as a separate element so their relationships remain traceable.
Identify threat sources across the full range of categories, including human, environmental, and systemic, and both intentional and accidental origins, to avoid gaps in coverage.
Assess threats in relation to the specific assets or objectives they could affect, rather than in the abstract, so that relevance to organizational context is preserved.
Use qualified likelihood estimates that consider both the threat and any corresponding vulnerability, recognizing that a threat with no exploitable weakness may carry lower risk.
Periodically review and update threat identification, as threat sources and events can change with the operating environment, technology, and organizational activities.
Coordinate threat identification with the appropriate lines of responsibility, keeping management's risk identification distinct from independent assurance activities that evaluate it.
Promotional banner highlighting failures found in PCI audits and how to spot the gaps