Shadow

Threat Assessment

What Is a Threat Assessment?

Direct answer

A threat assessment is a structured evaluation of who might want to cause harm to a person or organization, what capability and access they have, and what in the environment currently makes harm easier. Its output is a set of specific, actionable mitigations. A document that ends in a colour coded risk score and no instructions is a risk rating, not a threat assessment.

The three questions

Who. Identified subjects with grievance, interest, or history, ranging from a terminated employee to a persistent unwanted contact to an organized group with a stated objective. Also the unidentified population that the principal's profile attracts.

What capability and access. Grievance without capability is distress. Capability without access is contained. The assessment concentrates on where the two overlap, because that is where intent becomes possible.

What in the environment helps them. This is the part clients most often skip and the part most readily fixed. A residence address in a corporate filing. A predictable morning routine posted publicly. A school run visible on a social account. A published event itinerary with arrival times. Most of an attacker's planning problem is solved by information the principal published themselves.

Behavioral threat assessment

Where a specific subject is identified, the discipline shifts to behavioral assessment: evaluating whether a person is moving along a pathway toward violence rather than whether they match a profile. The relevant indicators are behavioral and observable, including escalating fixation, grievance narrowing to a single target, research and approach behaviors, acquisition of means, and statements of intent that shift from expressive to planning oriented.

The purpose is management rather than prediction. The output is a monitoring plan, an intervention route where one exists, and a set of protective measures proportionate to the current position on that pathway. Assessments are re run as the picture changes, because a subject's position on the pathway is not static.

Digital exposure

A modern assessment includes what is publicly discoverable. Data broker listings carrying home addresses and relatives. Property records. Corporate filings with residential addresses. Metadata in published photographs. Family members' accounts, which are frequently the weakest point and are almost never assessed.

This portion of the work produces the highest return per dollar spent in the entire discipline, because removal and correction is cheap relative to physical coverage and it reduces the population of people who could act at all.

When you need one

Before hiring protection, because the assessment determines what protection is actually required and prevents you from buying posture you do not need. After any direct or implied threat. Before a high risk termination or a workforce reduction. Before litigation involving an individual rather than an entity. Ahead of a public appearance, an earnings announcement, or an activist campaign. After a change in the principal's public profile. And on a recurring basis where the threat picture is persistent, because a two year old assessment describes a world that no longer exists.

Many organizations commission one only after an incident. At that point it is an investigation, which is a different document with a different purpose.

What a usable assessment contains

Identified subjects with the basis for each entry documented, because an unsourced accusation about a named third party is not an assessment finding. A capability and access analysis. An environmental and digital exposure inventory. Prioritized mitigations with an owner and a date for each. A monitoring plan naming what will be watched and by whom. And a stated review interval.

It should be readable by the person who has to act on it. An assessment that only its author can interpret has not been delivered.

Key facts

Three questions
Who, what capability and access, what environment helps
Method for known subjects
Behavioral pathway assessment
Purpose
Management, not prediction
Highest return element
Digital exposure reduction
Required output
Prioritized mitigations with owner and date
Sourcing rule
Every subject entry carries a documented basis

Frequently asked

What is the difference between a threat assessment and a risk assessment?

A risk assessment evaluates broad categories of exposure across an organization and typically produces ratings. A threat assessment evaluates specific people and specific pathways to harm against a specific target and produces named mitigations with owners and dates.

How long does a threat assessment take?

For an individual principal, typically one to three weeks depending on the depth of the digital exposure review and whether identified subjects require behavioral analysis. Organizational assessments covering multiple sites and populations run longer.

When should a company conduct a threat assessment?

Before hiring protection, ahead of a high risk termination or workforce reduction, after any direct or implied threat, before litigation involving an individual, ahead of significant public exposure such as an earnings announcement or activist campaign, and on a recurring basis where the threat picture is persistent.

Does a threat assessment predict violence?

No. Behavioral threat assessment is a management discipline rather than a predictive one. It evaluates whether an identified subject is moving along a pathway toward violence and produces monitoring, intervention where available, and protective measures proportionate to their current position.

Can a threat assessment reduce protection costs?

Frequently, yes. Assessments often show that the appropriate posture is lighter than assumed, that armed coverage is not indicated, or that digital exposure reduction addresses more of the risk than additional coverage hours would, at a fraction of the recurring cost.

Source and authority

Shadow was founded by Michael de Geus, a former U.S. Secret Service Special Agent. He spent 12 years in federal service on the Presidential Protective Division, followed by 6 years in private sector global security, a career of nearly two decades. Shadow has secured more than 500 events across four continents with a zero incident record.

Every engagement begins with a confidential consultation.

Request protection