Skip to content
atlas

Threat

Anything that could harm the organisation - an attacker, a careless mistake, a fire or a power cut.

Draft - this entry has not been reviewed yet.

Formal

Any person, event or circumstance with the potential to cause harm to information or systems by damaging their confidentiality, integrity or availability. A threat does harm only when it meets a weakness it can use.

In plain English

Like a burglar in the neighbourhood or a storm in the forecast - it has not hurt you yet, but it could.

In practice

A Danish shipping company lists its threats - criminal groups sending phishing mails, staff mistakes, a supplier's remote access and flooding of the basement server room.

Why it matters

You cannot guard against what you have not named; knowing the threats tells you what to prepare for and what to ignore.

Technical deep dive

In formal risk methodology a threat is decomposed into a threat source and a threat event. NIST SP 800-30 Rev. 1 classifies sources into four types: adversarial (individuals, groups, organisations or states acting with intent), accidental (erroneous action by a user or administrator), structural (failure of equipment, software or environmental controls, such as a disk or an aircon unit), and environmental (natural or human-made disasters - fire, flood, power loss). This taxonomy matters because it keeps risk assessment honest: an organisation that models only hackers systematically underweights the accidental deletion, the failed backup and the flooded basement that cause a large share of real losses. A threat becomes consequential only in combination with a vulnerability it can act on and an asset of value; a threat with no corresponding weakness produces no risk.

For adversarial threats specifically, the discipline of threat modelling makes the analysis systematic. STRIDE enumerates categories of what can go wrong (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege); attack trees decompose a goal into steps; and the MITRE ATT&CK knowledge base catalogues the real-world tactics and techniques adversaries use, giving defenders a shared vocabulary for describing behaviour. NIST SP 800-30 assesses adversarial threat events along dimensions of capability, intent and targeting, so that a capable but uninterested actor and an eager but unskilled one are scored differently rather than lumped as "hackers".

Threat intelligence operationalises this at national and organisational level. In Denmark the Danish Resilience Agency (Styrelsen for Samfundssikkerhed, SAMSIK), which absorbed the Centre for Cyber Security (CFCS) in 2025, publishes recurring threat assessments (the national cyber threat picture), rating the threat from, for example, cyber crime and cyber espionage on a qualitative scale; these feed the threat identification step of a risk assessment. Distinguishing a threat from adjacent terms is essential to using any of this correctly: a threat is a potential cause of harm, a vulnerability is the weakness it would exploit, a threat actor is the specific adversary behind an adversarial threat, and risk is the combination of a threat's likelihood with its impact.

A recurring misconception is to conflate threat with risk and act on the scariest-sounding threat rather than the most probable and impactful one; the point of naming threats is to feed a structured assessment, not to drive spending by fear. Another is treating the threat catalogue as static - the threat landscape shifts as new actors, tools and dependencies appear, so threat identification is a repeated activity, not a one-off list. Finally, focusing only on external adversaries ignores the insider, the third-party supplier and the non-malicious failure, all of which the four-type taxonomy is designed to keep in scope.

Relationships

Don't confuse with
RiskSecurity incident
Mitigated by
Defence in depth

Sources & further reading

Standards & official texts

  • NIST SP 800-30 Rev. 1 - Guide for Conducting Risk Assessments · NIST

Course material

  • Cyber Security Fast Track - Ordliste

Where this data comes from

This entry was drafted by an AI from the sources above and has not yet been checked by a person. Treat it as a starting point, and check anything important against the sources.

See the review queueSuggest a correction on GitHubThis term as JSON

Mentioned in

Check yourself

Loading…

Atlas is in beta.