The short answer
A security risk and threat assessment is a structured evaluation of who or what could cause harm to an organisation, its leaders, or their families — and how exposed they currently are. It covers two distinct disciplines: behavioural threat assessment, which evaluates whether an identified person is moving toward violence, and security risk assessment, which evaluates the vulnerability of people, sites, and operations.
Two disciplines, one name — and the confusion is expensive
Ask three firms for a "threat assessment" and you will get three different products. One will send a behavioural specialist to evaluate a named individual — a terminated employee, a fixated correspondent, a person making veiled statements. Another will walk your building and report on cameras, doors, lighting, and access control. A third will hand you a cyber report about phishing and credential exposure.
All three are legitimate. They answer entirely different questions, and the reason clients end up with the wrong one is that they asked with the wrong noun. This matters commercially as well as practically: the search term itself is ambiguous, which is why enterprise cyber vendors and physical-security firms compete on the same phrase.
The useful distinction is between **person-directed** and **place-directed** work. Behavioural threat assessment asks: is this specific individual on a pathway toward violence, and what do we do about it? Security risk assessment asks: where is this organisation, this executive, or this family exposed, and what would it take to reduce that exposure? A serious engagement usually needs both, but they are commissioned differently, staffed differently, and produce different documents.
Behavioural threat assessment: the discipline of the pathway
Behavioural threat assessment rests on a finding that is now well established in the research: people who commit targeted violence rarely snap. They move along an observable path — grievance, ideation, planning, preparation, breach — and they leave signals along the way.
The U.S. Secret Service's National Threat Assessment Center, which has worked in this field for roughly a quarter of a century, examined 173 incidents of targeted violence in *Mass Attacks in Public Spaces: 2016–2020*. Its central conclusion is that attackers displayed observable warning signs of their intentions beforehand, and that many had a history of violence and a connection to the place they attacked. NTAC's prevention argument follows directly: harm is averted when someone notices a concerning behaviour, reports it, and an organisation is capable of acting on the report.
That last clause is where most companies fail. The signals are usually noticed by somebody — a colleague, a supervisor, a receptionist. What is missing is a route for that observation to reach anyone competent to evaluate it, and a decision-maker willing to act before the situation is unambiguous. A behavioural threat assessment provides the evaluation. A threat management process provides the route.
The output is not a verdict on whether someone is "dangerous" in the abstract. It is a structured judgement about a specific person in a specific context at a specific moment, with recommended interventions — and, critically, a plan for monitoring, because the assessment expires as circumstances change.

Security risk assessment: where the exposure actually is
The place-directed side asks a different question. Given what this organisation is, who it employs, where it operates, and who its principals are, what is realistically likely to happen and how badly would it hurt?
For a corporation that spans physical sites, access control, incident response, insider risk, and the security implications of hiring and termination practices. For an executive it extends to travel patterns, residence, digital footprint, and the extent to which their movements are predictable from public information. For a family office it reaches further still — into household staff, contractors with routine access, and the exposure created by a principal's public profile. That last category is why this work sits so close to due diligence for family offices: the same trusted-insider risk appears in both.
A credible assessment is uncomfortable to read. It should tell you which of your existing controls are decorative, which risks you are accepting whether you know it or not, and what the two or three changes are that would actually move the exposure — usually a much shorter list than a vendor selling equipment would produce.
This is now a legal exposure, not only a security question
Under Section 5(a)(1) of the Occupational Safety and Health Act — the General Duty Clause — an employer must provide a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." There is no federal standard specific to workplace violence, so OSHA enforces it through this clause.
The operative word is *recognized*. An employer that has already experienced violence, or that has become aware of threats, intimidation, or other indicators, is on notice — and from that point the absence of a prevention programme becomes difficult to defend. To sustain a citation OSHA must show the hazard was recognised, that it was likely to cause serious harm, and that feasible means existed to reduce it materially.
That authority was tested and upheld recently. In *Cedar Springs Hospital v. OSHRC* (10th Cir., 13 February 2026) and its companion *UHS of Delaware v. OSHRC*, the Tenth Circuit affirmed OSHA's power to cite employers for workplace-violence hazards under the General Duty Clause, rejecting the argument that oversight by the Centers for Medicare and Medicaid Services displaced OSHA's independent responsibility for employee safety.
The practical implication for general counsel is straightforward. Once a company knows about a credible threat, a documented assessment and a reasoned response are not merely good security practice — they are the record that demonstrates the hazard was taken seriously. Doing nothing, or handling it informally, leaves no such record.
When to commission one
Assessments are usually triggered rather than scheduled, and the common triggers are recognisable.
A specific person has appeared: a terminated employee whose exit was hostile, a customer or claimant whose communications have escalated, a fixated individual contacting an executive directly, or a domestic situation that has begun to reach the workplace. These call for behavioural assessment, quickly.
Or the organisation's own posture has changed: an expansion into unfamiliar jurisdictions, a layoff or restructuring, litigation or an investigation that has drawn attention, an executive whose public profile has risen sharply, a family office professionalising after a liquidity event. These call for risk assessment.
There is also the case where a board or insurer simply asks whether the company has assessed its exposure, and the honest answer is no. That is a legitimate reason to commission one, provided the resulting document is treated as a plan rather than as evidence of compliance.
What a credible assessment produces
A serious deliverable is short, specific, and prioritised. It states what was examined and what was not, so the limits are explicit. It distinguishes what is known from what is inferred. It ranks findings by realistic likelihood and consequence rather than listing every conceivable scenario. And it gives a small number of recommendations sequenced by what should happen this week, this quarter, and this year.
Two things should make you suspicious. The first is a report that recommends primarily what the assessor also sells — an assessment that concludes you need a great deal of the assessor's equipment or manpower is not independent advice. The second is a document with no expiry: a threat picture is a snapshot, and one written eighteen months ago about a person or a site describes conditions that may no longer hold.
Where the assessment identifies a named individual, it should also say plainly what is *not* yet known about them — and what investigative work would resolve it. That is often where this work connects to investigative services: confirming an identity, a location, a firearms interest, or a litigation history turns an ambiguous concern into something that can be acted on.
Where this meets executive protection
Assessment and protection are frequently sold together and are not the same thing. Executive protection is the standing capability — the detail, the secure travel, the residential measures. Assessment is what determines whether that capability is warranted, at what level, and for whom.
Commissioning protection without assessment is how organisations end up paying for visible security that addresses the wrong risk — a close-protection detail for a principal whose actual exposure is a predictable routine and an over-shared digital footprint. Assessment first is both cheaper and more accurate, and it gives the protective programme something to be calibrated against.
Fortaris approaches this from the intelligence side rather than the manpower side. The firm's security services and risk advisory practice is built around evaluating exposure and advising corporations and family offices on what genuinely reduces it — including, often, the conclusion that a smaller and quieter measure will do more than a larger and more visible one.
Key takeaways
- "Threat assessment" names two different disciplines: behavioural assessment of a specific person on a pathway toward violence, and security risk assessment of an organisation's, executive's, or family's exposure. Buying the wrong one is the most common error in this category.
- Targeted violence is preceded by observable warning signs. The Secret Service's NTAC, reviewing 173 incidents in Mass Attacks in Public Spaces: 2016–2020, found attackers displayed them beforehand — so the binding constraint is usually an organisation's ability to receive and act on a report, not the absence of signals.
- OSHA enforces workplace violence through the General Duty Clause, §5(a)(1). Once an employer is aware of threats it is on notice, and the Tenth Circuit affirmed that authority in Cedar Springs Hospital v. OSHRC (13 February 2026) — making a documented assessment part of the legal record, not just good practice.
- A credible assessment is short, prioritised, explicit about its limits, and carries an expiry date. Be wary of any report whose recommendations consist mainly of what the assessor also sells.
- Assessment should precede protection. It determines whether a protective programme is warranted and at what level — commissioning protection first is how organisations buy visible security that addresses the wrong risk.
Frequently asked
What is the difference between a threat assessment and a security risk assessment?
A behavioural threat assessment is person-directed: it evaluates whether a specific identified individual is moving along a pathway toward violence, and what interventions are appropriate. A security risk assessment is place-directed: it evaluates how exposed an organisation, executive, or family is across sites, travel, access, digital footprint, and insider risk. They are commissioned differently and produce different documents. Serious matters often need both, but asking for the wrong one is the most common mistake in this category.
Do people who commit targeted violence really give warning signs?
Yes, and this is one of the better-established findings in the field. The U.S. Secret Service's National Threat Assessment Center examined 173 incidents in Mass Attacks in Public Spaces: 2016–2020 and found that attackers displayed observable warning signs of their intentions beforehand, with many having a history of violence and a connection to the location attacked. The practical problem is rarely that nobody noticed — it is that there was no route for the observation to reach anyone able to evaluate it, and no willingness to act before the situation became unambiguous.
Is a company legally required to assess workplace violence risk?
There is no federal standard specific to workplace violence, but OSHA enforces it under the General Duty Clause, Section 5(a)(1) of the OSH Act, which requires a workplace free from recognized hazards likely to cause death or serious physical harm. The word that matters is "recognized": an employer that has experienced violence or become aware of threats is on notice. In February 2026 the Tenth Circuit affirmed OSHA's authority to cite employers on this basis in Cedar Springs Hospital v. OSHRC and a companion case, rejecting the argument that another regulator's oversight displaced OSHA's role.
When should we commission an assessment?
Most are triggered rather than scheduled. Person-specific triggers include a hostile termination, an escalating customer or claimant, a fixated individual contacting an executive, or a domestic situation reaching the workplace — these need behavioural assessment quickly. Organisational triggers include expansion into unfamiliar jurisdictions, restructuring or layoffs, litigation drawing attention, a sharp rise in an executive's public profile, or a family office professionalising after a liquidity event. A board or insurer asking whether exposure has been assessed is also a legitimate trigger.
What should the final report actually contain?
It should be short, specific, and prioritised: what was examined and what was not, what is known versus inferred, findings ranked by realistic likelihood and consequence rather than an exhaustive list of scenarios, and a small number of recommendations sequenced across this week, this quarter, and this year. It should also carry an expiry — a threat picture is a snapshot, and an assessment written eighteen months ago may describe conditions that no longer hold.
How do we know the assessment is independent?
Look at what the recommendations point toward. If the conclusions consist largely of buying the assessor's own equipment or manpower, the document is a sales proposal in a different format. Independent advice frequently recommends less rather than more — a change in routine, a reduction in what is published about an executive, a fix to how concerns are reported internally — because those are often the measures that move exposure most per dollar spent.
Does an assessment cover cyber risk as well?
Usually only where it intersects with physical exposure. "Threat assessment" is also used by the cybersecurity industry to mean something different, which is a genuine source of confusion when buying. Physical and behavioural assessment will consider an executive's digital footprint — what a motivated person could learn about their movements, residence, and family from public sources — because that directly shapes physical exposure. Full network and information-security assessment is a separate discipline and should be commissioned as such.
Should we get an assessment before hiring executive protection?
Yes, in almost every case. Assessment determines whether a protective programme is warranted, at what level, and for whom. Buying protection first is how organisations end up funding visible security that addresses the wrong risk — for example a close-protection detail for a principal whose real exposure is a predictable routine and an over-shared digital footprint. Assessment first is cheaper, more accurate, and gives the protective programme a baseline to be calibrated against.
Sources & further reading
- U.S. Secret Service, National Threat Assessment Center — Mass Attacks in Public Spaces: 2016–2020 — NTAC's analysis of 173 incidents of targeted violence. Finds that attackers displayed observable warning signs of their intentions beforehand, that many had a history of violence and an affiliation with the location attacked, and that intervention depends on concerns being reported and acted upon. NTAC has worked in behavioural threat assessment for roughly 25 years.
- Occupational Safety and Health Act of 1970, Section 5(a)(1) — the General Duty Clause — Requires employers to furnish a workplace "free from recognized hazards that are causing or are likely to cause death or serious physical harm." In the absence of a workplace-violence-specific federal standard, this is the provision OSHA uses to enforce workplace violence prevention. A citation requires showing a recognised hazard, likelihood of serious harm, and feasible means of material abatement.
- Cedar Springs Hospital, Inc. v. Occupational Safety and Health Review Commission, No. 24-9519 (10th Cir., 13 February 2026); companion case UHS of Delaware v. OSHRC, No. 24-9521 — The Tenth Circuit affirmed OSHA's authority to cite employers for workplace-violence hazards under the General Duty Clause, rejecting the argument that oversight of patient safety by the Centers for Medicare and Medicaid Services displaces OSHA's independent responsibility for employee safety.
- U.S. Department of Justice / FBI — Behavioral Threat Assessment Center and the pathway-to-violence model — The operational basis for behavioural threat assessment: targeted violence is generally preceded by a progression through grievance, ideation, planning, preparation, and breach, which creates opportunities for observation and intervention rather than prediction of dangerousness in the abstract.
- ASIS International — enterprise security risk management and workplace violence prevention standards — The professional standards framework for organisational security risk assessment: identifying assets, threats, vulnerabilities and consequences, and prioritising mitigation by likelihood and impact rather than by exhaustive scenario listing.
- OSHA — Workplace Violence enforcement guidance — Sets out that an employer which has experienced acts of workplace violence, or become aware of threats, intimidation or other indicators showing potential for violence, is on notice of the risk and should implement a prevention programme combining engineering controls, administrative controls, and training.

