The reference desk / In practice

Threat

A person, process, or event that might cause a loss to an asset.

What it means

A threat is a possible cause of harm, not necessarily an attacker. Malicious activity, human error, equipment failure, and environmental events can all threaten a service or its information. It helps to distinguish a threat source from a threat event: a criminal group is a source, while using stolen credentials to read records is an event.

A useful threat description connects that possible event to an asset and a consequence. Avoid stopping at labels such as “insider” or “ransomware.” Ask what could actually happen in this environment, which conditions make it plausible, and what evidence supports spending attention on it.

AN ILLUSTRATIVE SCENARIO

A council records office

A council stores important case records in a building with a history of basement flooding. The potential flood is a threat even though no malicious actor is involved. A separate threat scenario involves someone using a stolen staff account to download those records. The office assesses both scenarios, recognizing that physical storage choices and account permissions create different weaknesses. A single anti-malware product would not address both paths to harm.

Put it to work

  1. Identify the assets and service outcomes that matter, then consider malicious, accidental, technical, and environmental sources of disruption or misuse.
  2. Write plausible threat events with a clear action and consequence, using relevant local evidence and trustworthy external information.
  3. Connect each event to the conditions and weaknesses it could use, then assess likelihood, impact, and suitable safeguards with the asset owner.

How to check your work

Review a threat statement with someone who operates the service. They should understand the event, recognize the affected asset and consequence, and identify the evidence and assumptions behind its inclusion.

Connect the ideas

  • Vulnerability

    A weakness in a system, process, or person that makes a loss easier to cause.

  • Exploit

    A method or code that uses a vulnerability to cause an unauthorized effect.

  • Risk

    The potential for harm, assessed using what could happen, how likely it is, its impact, and what remains uncertain.

  • Likelihood

    How plausible it is that a threat will cause a loss in this environment, given exposure and evidence.

Explore a field lesson

Find your next idea.

Tip: press / to open search. Escape closes this window.