Skip to main content
Category: Business Continuity

Threat and Hazard Identification

Also known as: THIRA, Threat and Hazard Identification and Risk Assessment
Simply put

Threat and Hazard Identification is the part of a risk assessment process in which a community identifies the potential threats and hazards that could affect it, such as natural events, before evaluating their possible consequences. In U.S. emergency preparedness, it forms the opening stage of the Threat and Hazard Identification and Risk Assessment (THIRA) process, which is administered by FEMA. It is used to help communities understand their risks and inform related capability and resource planning.

Formal definition

Threat and Hazard Identification refers to the systematic identification of potential threats and hazards that could impact a community, and it is embedded within FEMA's Threat and Hazard Identification and Risk Assessment (THIRA), a standardized, coordinated risk assessment process supporting national preparedness. Sources describe THIRA variously as a three-step or four-step process; the number of steps cited in the evidence differs, so practitioners should confirm the current FEMA methodology rather than rely on a single figure. Within THIRA, threat and hazard identification precedes the assessment of potential consequences and the derivation of capability targets and resource requirements. This entry addresses the U.S. emergency management context reflected in the evidence; it does not cover implementation specifics, tooling, or applications outside that federal preparedness framework.

Why it matters

Threat and hazard identification is the foundational step that shapes the reliability of a community's entire preparedness planning effort. If potential threats and hazards are not identified accurately and comprehensively at the outset, subsequent stages of the risk assessment process, including the evaluation of potential consequences and the derivation of capability targets and resource requirements, are likely to rest on an incomplete picture. Within FEMA's Threat and Hazard Identification and Risk Assessment (THIRA), this identification step precedes and informs the more detailed analysis that follows.

Because THIRA is described as a standardized and coordinated process used to measure risk and capability across the nation, consistent threat and hazard identification also supports comparability of risk information among communities and helps align local understanding with broader national preparedness objectives. This standardization is intended to help communities articulate the threats and hazards most relevant to them before committing planning resources.

It should be noted that the evidence describes THIRA inconsistently as a three-step and as a four-step process, reflecting differences among sources. Practitioners relying on THIRA for formal planning should confirm the current FEMA methodology rather than depend on any single characterization, and should treat this entry as covering the U.S. emergency management context only.

Who it's relevant to

Emergency Management and Preparedness Professionals
Community and state emergency managers use threat and hazard identification as the entry point to the THIRA process, helping them understand the risks their communities face and informing subsequent capability and resource planning. State-level offices, such as those administering emergency management programs, apply the THIRA process to identify capability targets and resource requirements.
Risk Management Practitioners
Those responsible for community risk assessment rely on structured threat and hazard identification to establish a comprehensive basis for evaluating potential consequences. Because sources differ on whether THIRA is a three-step or four-step process, these practitioners should confirm the current FEMA methodology before applying it.
Consultants and Advisors Supporting Communities
Advisory professionals supporting communities in preparedness planning apply THIRA as a systematic process to identify potential threats and hazards and assess their potential consequences, helping clients align local risk understanding with the standardized, nationally coordinated approach administered by FEMA.

Inside THIRA

Threat Identification
The process of recognizing potential sources of harm arising from intentional or adversarial acts, such as cyberattacks, fraud, or physical security breaches. Threats typically involve an actor with intent or capability directed against the organization.
Hazard Identification
The process of recognizing potential sources of harm arising from non-adversarial conditions or events, such as natural events, equipment failures, or safety conditions. Hazards commonly lack an intentional actor and stem from circumstances rather than deliberate action.
Source and Cause Analysis
Examination of the origins and conditions that give rise to identified threats and hazards, supporting later stages of risk assessment. This step characterizes what could cause harm rather than quantifying the associated risk.
Scope and Context Definition
Establishing the boundaries, assets, objectives, and operating environment against which threats and hazards are considered. Scope commonly varies by jurisdiction, industry, and organization size.
Documentation and Register Input
The recorded outputs of identification, which typically feed a risk register or similar record for subsequent assessment, treatment, and monitoring. Identification precedes, and does not replace, analysis and evaluation.

Common questions

Answers to the questions practitioners most commonly ask about THIRA.

Is threat and hazard identification the same as risk assessment?
No. Threat and hazard identification is typically a precursor step focused on recognizing and cataloging potential sources of harm, whether intentional threats or naturally occurring or accidental hazards. Risk assessment is the broader process that follows, in which identified threats and hazards are analyzed for likelihood and potential impact against objectives and then evaluated. Identification produces the inputs; assessment interprets them. Treating the two as interchangeable can lead to skipping the analytical and evaluative work that turns a list of hazards into prioritized, actionable risk information.
Does identifying a threat or hazard mean an organization has actually reduced its risk?
Not on its own. Identification improves awareness and supports subsequent analysis, but it does not treat or mitigate anything by itself. Risk reduction depends on later steps such as assessment, selection of controls or other treatment options, and implementation and monitoring of those measures. Identification is a necessary but not sufficient condition for managing risk, and a comprehensive inventory of threats and hazards should not be mistaken for evidence that residual risk has been lowered.
How can an organization structure a threat and hazard identification exercise?
Approaches commonly combine multiple techniques rather than relying on a single method. These may include structured workshops with subject matter experts, review of historical incident and loss data, scenario analysis, checklists drawn from relevant frameworks, and environmental or external scanning. Distinguishing deliberate threats from non-deliberate hazards during the exercise can help ensure both categories receive attention. The specific structure typically varies by organization size, sector, and jurisdiction, and this entry does not prescribe a particular methodology or tool.
Who should be involved in identifying threats and hazards?
Participation commonly spans those with operational knowledge of the areas under review, since first-line personnel often have direct visibility of exposures. Risk and compliance functions in a second-line capacity may facilitate and provide methodology, consistency, and challenge. Where independent assurance functions are involved, their role is typically to evaluate the adequacy of the identification process rather than to own it, preserving the separation between management activities and assurance. The appropriate mix depends on organizational structure and the scope of the exercise.
How often should threat and hazard identification be repeated?
Frequency is typically driven by the volatility of the environment and the significance of the activities involved. Many organizations combine periodic reviews with event-triggered reassessment following incidents, significant operational changes, new products or processes, or shifts in the external threat landscape. A static, one-time exercise may become outdated as conditions change. The suitable cadence varies by sector, jurisdiction, and risk profile, and this entry does not specify a mandatory interval.
How should the outputs of threat and hazard identification be documented and used?
Outputs are commonly captured in a structured form, such as a register or inventory, that records the identified threats and hazards and supports traceability into subsequent assessment and treatment steps. Clear documentation can aid consistency, review, and reporting to governance bodies. The identification record is generally an input to, not a substitute for, analysis, prioritization, and decision-making. Specific tooling, template design, and reporting formats are out of scope for this entry and depend on organizational preferences and requirements.

Common misconceptions

Threats and hazards are interchangeable terms.
The two are commonly distinguished: threats typically imply an intentional or adversarial actor, while hazards generally arise from non-adversarial conditions or events. Conflating them can obscure the appropriate treatment approach.
Identifying threats and hazards is the same as assessing risk.
Identification is an early step that recognizes potential sources of harm. Assessing likelihood and impact, evaluating against risk criteria, and determining residual risk are separate subsequent stages in most risk management processes.
A single, universal list of threats and hazards applies to all organizations.
Relevant threats and hazards typically depend on jurisdiction, industry, assets, and organizational context. A list appropriate for one setting may be incomplete or misleading in another.

Best practices

Define the scope, assets, objectives, and operating context before beginning identification so that the exercise reflects the organization's actual environment.
Distinguish clearly between adversarial threats and non-adversarial hazards when recording items, as this often informs how they are subsequently analyzed and treated.
Draw on multiple perspectives and sources, engaging relevant functions and subject-matter input to reduce blind spots in what is identified.
Record identified threats and hazards in a structured register that can feed subsequent assessment, treatment, and monitoring activities.
Tailor identification to the applicable jurisdiction, industry, and organization size rather than relying on generic or universal lists.
Treat identification as an iterative activity, revisiting it periodically and when the context, assets, or objectives change.
Promotional banner for the Pentest Readiness checklist download