Skip to main content
Category: Threat Intelligence & Simulation

Threat Source

Also known as: Threat Agent, Threat Agent/Source
Simply put

A threat source is any person, group, system, condition, or event that could cause harm to an organization's information or assets. It may act deliberately, such as an attacker exploiting a weakness, or accidentally, such as a situation that unintentionally triggers a vulnerability. Identifying threat sources is a foundational step in understanding what an organization needs to defend against.

Formal definition

A threat source is the intent and method targeted at the intentional exploitation of a vulnerability, or a situation and method that may accidentally trigger a vulnerability. It encompasses categories of people, objects, conditions, systems, or events that represent potential sources of harm to information assets, including intentional adversaries and accidental or environmental causes. In NIST usage, the terms 'threat source' and 'threat agent' are treated as synonymous rather than hierarchical; practitioners should be aware that some non-authoritative sources incorrectly describe a threat agent as a subcomponent of the threat source. Insider threats (individuals with authorized access or organizational knowledge who may cause harm) are one recognized class of threat source. Threat source identification is typically an input to risk assessment activities, informing how likely and impactful a given threat scenario may be, though it does not by itself quantify risk.

Why it matters

Identifying threat sources is foundational to any credible risk assessment because an organization cannot meaningfully prioritize defenses against threats it has not first named. A threat source frames the question of who or what could cause harm, whether a deliberate adversary exploiting a vulnerability or an accidental condition or event that unintentionally triggers one. Without this step, risk decisions tend to be reactive and tool-driven rather than grounded in an understanding of what the organization actually needs to defend against.

A common expert correction is the treatment of the relationship between 'threat source' and 'threat agent.' Some non-authoritative sources describe a threat agent as a subcomponent of a threat source, but in NIST usage the two terms are treated as synonymous rather than hierarchical. Practitioners relying on the hierarchical interpretation may build risk models that do not align with authoritative definitions, which can create confusion when mapping to frameworks or communicating with auditors and stakeholders.

Threat sources also include categories that are easy to overlook, such as insider threats. CISA defines insider threat as the potential for an insider to use their authorized access or understanding of an organization to harm that organization. Because insiders operate with legitimate access, they represent a recognized class of threat source that purely perimeter-focused defenses may fail to address, reinforcing why threat source identification must be deliberate and comprehensive rather than assumed.

Who it's relevant to

Virtual and Fractional CISOs
Security leaders engaged to build or mature a risk program rely on threat source identification as an early governance step. A vCISO typically directs how an organization enumerates and categorizes threat sources as an input to risk assessment, while advising rather than assuming accountability for the resulting risk decisions, which generally remain with the client organization and its officers.
Risk and Compliance Teams
Teams responsible for risk assessments use threat source identification to frame what an organization must defend against. Because a threat source informs but does not quantify risk, these teams must combine it with vulnerability and impact analysis to produce meaningful risk conclusions, and should use authoritative definitions to avoid misalignment during audits or framework mapping.
Executive and Board Stakeholders
Business leaders benefit from understanding threat sources as a business risk concept rather than a purely technical one. Recognizing that threat sources include deliberate adversaries, accidental conditions, and insiders with authorized access helps executives set defensible priorities and understand where organizational cooperation and access to stakeholders shape the value of the resulting risk analysis.

Inside Threat Source

Threat Source (Threat Agent)
The entity or circumstance that initiates or has the potential to initiate a threat event. In NIST usage (e.g., SP 800-30 Rev 1, NIST IR 7298), the terms threat source and threat agent are treated as synonymous rather than as a parent and sub-component. A threat source may be an intentional actor, an accidental cause, a structural failure, or an environmental condition.
Adversarial Sources
Intentional actors seeking to exploit an organization's assets, such as external attackers, criminal groups, competitors, or malicious insiders. These sources have intent, capability, and targeting characteristics that can be assessed when evaluating risk.
Non-Adversarial Sources
Sources that cause harm without malicious intent, including accidental actions by authorized users, structural failures of equipment or software, and environmental factors such as natural disasters or power loss.
Characterizing Attributes
Descriptive properties used to assess a threat source. For adversarial sources these often include capability, intent, and targeting; for non-adversarial sources they often include range of effects or likelihood of occurrence.
Relationship to Threat Events and Vulnerabilities
A threat source is distinct from a threat event (the action or occurrence) and from a vulnerability (the weakness exploited). The threat source is the origin that acts upon or triggers a threat event, which in turn may exploit a vulnerability.

Common questions

Answers to the questions practitioners most commonly ask about Threat Source.

Is a threat source the same thing as a threat agent, or is one part of the other?
In many authoritative sources, including NIST publications such as SP 800-30 Rev 1 and NIST IR 7298, the terms threat source and threat agent are treated as synonymous rather than hierarchical. A prior framing that positioned a threat agent as a subordinate component of a threat source overstates a distinction that these references do not draw. In practice, both terms describe the entity or circumstance that initiates or has the potential to initiate a threat event. Some organizations do adopt their own layered taxonomies, so a virtual CISO typically confirms which definitions a client's frameworks use rather than assuming a universal hierarchy.
Does a threat source always mean a malicious attacker?
No. A common misconception is that a threat source is exclusively an adversarial human actor. Threat sources are generally categorized more broadly and may include adversarial sources such as individuals, groups, or organizations, as well as accidental sources like human error, structural sources such as equipment or software failure, and environmental sources including natural events. Treating the concept as only malicious attackers can narrow a risk assessment and cause a program to overlook non-adversarial sources that also warrant consideration.
How does identifying threat sources fit into a risk assessment a virtual CISO would guide?
Threat source identification is typically an early input to a risk assessment, informing which threat events are plausible and which vulnerabilities could be exploited. A virtual CISO often facilitates this step by helping stakeholders enumerate relevant adversarial, accidental, structural, and environmental sources appropriate to the organization's context. The vCISO generally advises on the methodology and prioritization, while the client organization supplies the operational knowledge of its systems and environment. The quality of this step depends heavily on stakeholder access and organizational cooperation.
Who is accountable for acting on the threat sources a vCISO helps identify?
A virtual CISO advises on which threat sources are relevant and how to prioritize associated risks, but accountability for accepting, mitigating, or transferring those risks usually remains with the client organization and its officers. The vCISO directs and recommends; decisions about resource allocation and risk acceptance are generally organizational choices. This separation of responsibility from accountability should be reflected in the engagement scope so that expectations about who owns the resulting risk decisions are clear.
How should threat sources be documented so they remain useful over time?
Threat sources are often documented within a risk register or threat assessment that links each source to relevant threat events, affected assets, and applicable vulnerabilities. In many engagements a virtual CISO recommends recording enough context, such as source category and rationale, to support periodic review, since the relevance of sources may change as the environment, threat landscape, or business evolves. Documentation value depends on organizational maturity and on the discipline to revisit and update it rather than treating it as a one-time exercise.
What is out of scope for a virtual CISO when it comes to threat sources?
A virtual CISO typically provides governance, strategy, and risk-level guidance on identifying and prioritizing threat sources, but generally does not perform hands-on operational activities such as continuous threat monitoring, threat intelligence feed administration, or active incident response execution unless those tasks are explicitly contracted. Conflating a vCISO with a managed security service provider or an in-house SOC is a common mistake; the vCISO advises on how threat source analysis should inform the program rather than operating the tooling that detects those sources in real time.

Common misconceptions

A threat agent is a component or subset of a threat source, forming a hierarchy.
In standard NIST usage (SP 800-30 Rev 1, FIPS 200, NIST IR 7298), threat source and threat agent are treated as synonymous terms, not as a parent concept and its component. They refer to the same idea: the entity or circumstance that initiates a threat.
Threat sources are always malicious human attackers.
Threat sources include non-adversarial origins such as accidental user error, structural failures, and environmental events. Limiting the concept to malicious actors understates the risks an organization should evaluate.
Identifying threat sources is a purely technical exercise handled by security tools.
Characterizing threat sources is a governance and risk-assessment activity that informs strategy and decision-making. It requires business context and judgment, not just tooling, which is why it typically falls within the advisory scope of security leadership.

Best practices

Use consistent, standards-aligned terminology and treat threat source and threat agent as synonymous rather than inventing a hierarchy between them.
Distinguish threat sources from threat events and vulnerabilities so that risk assessments attribute cause, action, and weakness correctly.
Catalog both adversarial and non-adversarial threat sources so accidental, structural, and environmental origins are not overlooked.
Characterize adversarial sources by capability, intent, and targeting, and characterize non-adversarial sources by range of effects or likelihood, to support more meaningful risk analysis.
Revisit and update the threat source inventory periodically, since relevant sources shift with changes to the organization, its environment, and its exposure.
Ensure that the assessment of threat sources feeds into governance and risk decisions, recognizing that a virtual CISO can advise on and direct this work while accountability for the resulting decisions typically remains with the client organization.