The 2026 Guide to Threat Assessment Approaches for Law Enforcement

In the law enforcement industry, accurately identifying and responding to threats is critical to maintaining safe spaces. Whether it involves reacting to active threats in real time or strengthening long-term predictive capabilities, threat detection and awareness are vital strategies to prevent violent incidents and reduce risk. Officers and agencies must protect against potential cyber attacks and ransomware, the influence of malign nation-states, transnational organized crime, and the ongoing risk of lone-wolf attacks. 

But threat assessment means different things to different people, and the definition of threat assessment varies widely across fields. Security professionals, police, military personnel, psychologists, and school counselors all conduct tasks they describe as threat assessment. While all these tasks are predictive in nature, the methods and objectives differ. Understanding which type of threat you're trying to assess, and for what purpose, is the first step toward building an effective response.

For example, judges conduct threat risk assessments to assess whether someone poses a general danger to the public, while law enforcement typically concentrates on assessing imminent or immediate threats as part of the behavioral threat assessment and management (BTAM) process.

Police officers conducting a contact related to threat assessment

This guide was first published in 2019. I wrote it because I was having trouble differentiating between all the different types of threat assessment. It turns out that lots of people use the term to describe different techniques. Sometimes the term is used interchangeably with “risk assessment,” but that term does not fit in many circumstances.  

Since its publication, this guide has proven to be one of our most popular posts. Between 2020 and 2026, 6,389 people from all over the world read this post. For a small company like us, this is awesome. We are proud to be helping police everywhere implement strategies that can help them protect their communities. 

I hope you find this resource useful too. Don’t hesitate to reach out if we can help you or your organization.

Threat Assessment Approaches

Before diving into threat assessment, it’s important to clarify the specific problem you aim to address.

Are you looking to:

  1. Plan for and protect facilities, soft targets, and critical infrastructure against terrorist attacks, insider threats, or natural disasters?

  2. Equip your officers to observe and detect behavior-based threats and respond to individuals who pose immediate danger, such as active shooters? 

  3. Safeguard your computer networks, systems, and servers from attacks by malicious actors?

  4. Identify, assess, and intervene with individuals who may commit targeted or instrumental violence, such as a mass shooting?

  5. Evaluate a specific individual’s risk for violent behavior?

You can use this infographic to figure out which section will be most helpful to you:

Infographic helping readers identify which threat assessment approach best fits their needs
 

1. The Security Threat and Risk Assessment

In the security and protection industry, threat assessment involves evaluating and analyzing potential risks that could compromise the safety of critical infrastructure and the people associated with a specific site or facility. It can also be a crucial tool for those seeking to protect soft targets from targeted violence.

This process focuses on identifying existing protective measures and vulnerabilities at facilities and implementing strategies to reduce those vulnerabilities and enhance safety. Assessments evaluate things like physical security, cybersecurity, and staffing protocols.

There are a broad range of threats that can affect a particular site or location, including:

  • External hazards: Natural disasters, fires, and other environmental risks; 

  • Nonviolent and violent criminal threats: Theft, threats toward staff, active shooter incidents, or terrorist threats; 

  • Potential accidents: Issues stemming from improper building maintenance or unsafe working conditions;

  • Cyber threats: Hacking, data breaches, ransomware, or other malicious activity targeting IT systems;

  • Operational disruptions: Threats that could impact telecommunications, transportation, or the delivery of essential services at the site. 

Security Threat Risk Assessment at a School

For a security risk assessment, let’s take the example of an elementary or high school. Potential threats to a school could include natural disasters, active shooter incidents, or accidents arising from improper safety precautions. Each of these threats requires a different response. Visit Ready.gov to access emergency response plans for these different types of incidents.

Graphic illustrating the types of threats and risks relevant to school security assessments

This security threat risk assessment includes not only identifying potential threats but also assessing the likelihood of their occurrence. Just because something can happen doesn’t mean it will.

The Vulnerability Assessment

Following the security risk threat assessment is the vulnerability assessment, which has two parts.

  • Identifying assets and people at risk: This involves determining the critical assets—such as buildings, equipment, and personnel—that may be impacted. This includes an estimation of financial impacts that could result if the location were attacked and unable to provide services.  

  • Evaluating target attractiveness and defenses: For intentional attacks, this step assesses how attractive the target may be to potential attackers. It also examines the current level of defenses in place to mitigate targeted attacks. 

In schools, common security gaps include challenges in securing entry and access points, insufficient security measures due to budget constraints (such as limited surveillance/camera systems or a lack of security personnel), and insufficient training or experience among school staff in handling security-related incidents.

Schools often incorporate advanced technology into their security procedures. Learn more about the benefits and potential pitfalls of some of these security approaches in our recent blog posts:

2. Active Threat Assessment

Law enforcement professionals operate in complex environments where they must rapidly interpret human behavior and make decisions under uncertain and often high-pressure conditions. Behavioral threats may emerge during patrol operations, calls for service, investigative encounters, traffic stops, and public interactions. These situations require officers to recognize behavioral indicators early while maintaining officer safety, public trust, and effective policing. Observation and threat assessment are foundational expectations in law enforcement, but are rarely taught as a structured, repeatable skill.

In law enforcement, threat assessment can refer to the process of observing, identifying, and reacting to potential imminent and immediate threats. These threats may target your officers, the public, or both. At Second Sight, we use the term “active threat assessment” to describe our structured, repeatable observation process that strengthens systematic observation and visual threat detection skills during patrol and public interactions. This process helps officers recognize behavioral threat indicators during evolving encounters and distinguish benign behavior from deviations that may signal emerging threats.

Graphic introducing Second Sight's active threat assessment methodology for law enforcement

The Active Threat Assessment Methodology

Observation is a foundational expectation in law enforcement, but it is often assumed rather than formally taught as a structured, repeatable skill. In policing environments, extensive training exists around tactical response, officer safety procedures, and investigative techniques, but the ability to systematically observe behavior is equally critical.

Active threat assessment refers to the structured, repeatable observation process that helps officers systematically observe their environment, recognize threatening behavioral indicators earlier during encounters, and make more informed decisions about how to respond.

In this approach, an observer, such as one of your officers, systematically scans their environment, identifies behavioral deviations that do not align with the environment, and distinguishes benign behavior from deviations that might signal emerging threats. Using this process, officers can identify pre-incident behaviors, or threat indicators, including those associated with individuals carrying weapons or preparing for violence. Recognizing these indicators helps officers identify a potential person of interest (POI) who warrants closer observation.

Visual threat detection techniques can help your officers consistently recognize meaningful behavioral deviations, interpret behavioral indicators, and clearly articulate what they observed and why it led them to act. Supervisors and agency leadership receive stronger documentation explaining why officers made particular decisions during rapidly evolving situations. This shift replaces inconsistent, intuition-based observation with a structured, teachable observation process that standardizes how officers recognize and interpret behavior across the agency, improves the quality and consistency of information supporting investigations, and enhances defensibility of actions taken during critical incidents.

Potential Users of Active Threat Assessment

A wide spectrum of law enforcement professionals can use Second Sight's active threat assessment approach, including:

Campus safety at higher-education institutions

School safety personnel at K-12 schools

Patrol officers, investigators, and agency leadership within law enforcement agencies

Second Sight offers active threat assessment training for law enforcement professionals through our Threat Awareness for Law Enforcement program. To date, Second Sight has delivered the 8-hour Threat Awareness program to thousands of security and law enforcement professionals worldwide. Because knowledge and skills gained through training can decay over time, a 1-hour refresher is also offered 6-12 months after the initial session to reinforce key concepts.

In our recent article, “Recognizing and Responding to Threats in the Real World,” we discuss feedback from 143 law enforcement and security professionals who completed the refresher training. When asked how frequently participants used the skills taught during the program, 1 in 2 participants indicated they used these skills everyday. In addition, 79% used the skills at least weekly, and 91.6% used the skills at least monthly. 96.5% of this group also reported an improved ability to articulate their decisions.

3. The Cyber-security Threat Risk Assessment

The same threat risk assessment process applies to cybersecurity, a critical component of overall risk management. A cybersecurity threat risk assessment focuses on protecting access to data and personal information, networks, software (e.g., internal communications or data management systems), as well as any hardware (e.g., your officers’ laptops and mobile phones).

A cyberattack is any deliberate attempt to gain unauthorized access to a network, computer system, or device. Attackers typically aim to steal, modify, expose, or destroy data and other assets using a variety of techniques.

One increasingly common type of cyberattack is ransomware. Ransomware is a form of malware that is installed on a system without the user’s knowledge or permission, often via websites, emails, or file attachments. Once infected, the ransomware locks and encrypts the user’s data, files, and systems, rendering them inaccessible or unusable until a ransom is paid to the attacker.

Ransomware can have dire consequences. Once data is compromised, there’s no guarantee the victim will get it back, even if they pay the ransom. Cybercriminals may still withhold or destroy the files.

In recent years, there has been a significant increase in the number of ransomware attacks, with several high-profile incidents occurring in hospitals, schools, and even government agencies. According to industry surveys conducted by Sophos in 2024, an estimated 67% of healthcare organizations, 80% of schools, and 69% of government agencies have experienced ransomware attacks. These incidents disrupt critical services, endanger lives, and cause devastating financial consequences.

Computer network or server environment representing the cybersecurity threat and risk assessment process

The basic steps of a cybersecurity threat risk assessment are:

  1. Identify the potential systems that are at risk.

  2. Identify specific threats for each system (e.g., unauthorized access, misuse of information, data leakage or exposure, service disruptions).

  3. Evaluate inherent risks and determine what potential consequences could result if threats materialize.

  4. Analyze existing controls and measures in place to prevent, detect, mitigate, or compensate for threats.

  5. Determine how well current safeguards successfully reduce risk and mitigate threats.

  6. Evaluate the probability of a threat occurring based on existing controls.

  7. Combine impact and likelihood to determine overall risk level and calculate a “risk rating.”

After the assessment, you will have a clearer understanding of existing cybersecurity controls and remaining vulnerabilities. From there, you can implement additional security measures to mitigate potential risks.

4. Threat Assessment for Instrumental Violence

Instrumental violence refers to acts or threats of targeted violence that are planned and purposeful, such as a targeted attack or mass shooting. For example, in a workplace setting this could involve an employee who has made threats against colleagues or has been involved in recent altercations. In a school setting, this could involve a student who has made threats against classmates or staff or exhibited expressions of intent to harm.

Workplace or public setting representing the context for threat assessment related to instrumental and targeted violence

Threat assessment for instrumental violence is incident- and subject-specific, meaning it evaluates the likelihood that a particular individual will carry out a specific attack. This growing field is often referred to as Behavioral Threat Assessment and Management (BTAM) or Threat Assessment and Threat Management (TATM). For a general overview of this approach, check out the National Threat Evaluation and Reporting Program’s Behavioral Approach to Violence Prevention.

BTAM often occurs in team settings and can involve school administrators, community members, law enforcement, and mental health workers. You can learn more about threat assessment teams from recent research published by the National Counterterrorism Innovation, Technology, and Education Center (NCITE). 

If you are looking to implement BTAM at your organization, the National Threat Evaluation and Reporting (NTER) Program offers courses for both trainers and trainees:

The National Association of School Psychologists (NASP) outlines a broad framework for identifying and intervening with potentially violent individuals who exhibit risk factors for instrumental violence. In some instances, authorized personnel can use databases to access information about specific individuals to assess their risk factors.

A key authority in this area is the U.S. Secret Service National Threat Assessment Center (NTAC). In their 2023 report, Mass Attacks in Public Places, they found that many mass attackers share common characteristics, including personal grievances, history of criminal behavior, history of substance abuse or mental health symptoms, and other stressors such as financial instability. Additionally, many attackers exhibited concerning behaviors or made threatening statements before the attack. Being able to recognize these situational and behavioral indicators is essential for averting such attacks. For more information, check out the RAND corporation’s guidance on how to recognize potential warning signs of a mass attack and assess threat severity.

For resources specific to law enforcement, check out the following: 

Threat Assessment in Schools

When it comes to preventing instrumental violence in schools, a nuanced approach is best. This process involves assessing students for multiple factors, including motives, communications, access to weapons, stressors, emotional problems, and developmental issues. For a deeper dive into this approach, check out our post on school behavioral threat assessment.

School building or campus illustrating the context for instrumental violence prevention and swatting incident awareness

One alarming trend on the rise is the false reporting of attacks at schools and universities. These hoax calls are part of a coordinated “swatting” campaign that exploits the widespread fear of school shootings. Swatting involves making false reports of violent situations, such as a bomb threat or active shooter, to elicit a police response to a particular location, preferably by a SWAT team.

These incidents can be extremely dangerous, as they put the lives of individuals at risk and prompt law enforcement to respond aggressively, unaware that the situation is a hoax. The fear and trauma caused by the sudden, intense police response can have lasting psychological effects on those involved. Additionally, these incidents occupy emergency resources, potentially delaying response times for real emergencies. 

5. The Violence Threat Risk Assessment

Violence threat risk assessments are used to better understand an individual’s tendency toward violence and estimate their likelihood to engage in violent behavior in the future. These assessments help practitioners and intervention providers make informed decisions about risk mitigation, supervision, and treatment options for potentially dangerous individuals. This is often referred to simply as a “violence risk assessment” or just “risk assessment.”

The difference between this approach and the instrumental approach in the previous section (e.g., BTAM) is that this approach evaluates an individual’s general tendency toward violence, while the instrumental approach predicts the likelihood of a specific attack on a specific target.

Graphic illustrating structured professional judgment and actuarial-based approaches to violence risk assessment

Typically, violence risk assessments are conducted by qualified clinical professionals rather than law enforcement. There are different types of violence threat risk assessments designed to predict different types of risks, ranging from domestic violence to terrorism. Some of these rely on the judgment of professionals, while others are actuarial-based.

Structured professional judgment (SPJ) approaches involve a systematic evaluation of risk factors by professionals who apply their expertise and judgment to assess an individual's level of risk.

One benefit of the SPJ approach is that professionals examine a wide range of aggravating and mitigating factors and can offer more personalized assessments. However, some criticize the SPJ approach for being too subjective and inconsistent when making risk evaluations due to variations in professional judgment and individual biases. 

Well-known SPJ approaches include:

Actuarial-based risk assessment instruments (RAIs) use statistical methods and a scoring system to predict future risk, rather than relying on input from professionals. These tools use predetermined risk indicators that are informed by historical data and criminological theory to generate a numerical score, which reflects an individual’s likelihood of committing a specific act in the future.

In contrast with SPJ approaches, RAIs are consistent in making predictions based on the same inputs, as they rely on predetermined formulae to assess risk. However, there are concerns about their potential to outperform human judgment, as RAIs don’t adapt well to uncommon circumstances, and they often include static factors (such as being a male) that cannot be changed. Relatedly, if historical data is biased, the algorithm might perpetuate biases.

Commonly used actuarial-based RAIs include:

Ultimately, selecting the “best” risk assessment tool for a situation depends on the nature of the risk being assessed (e.g., violent extremism, general violence), the characteristics of the population being assessed (e.g., age, gender), and the setting or context of the assessment (e.g., school, correctional facility).

For a comprehensive approach to risk management for public entities, check out the Public Risk Innovation, Solutions, and Management (PRISM) framework. This framework covers all aspects of risk identification, assessment, and management, and includes various resources to assist organizations in various types of risks. 

What’s Next?

All of these approaches to risk assessment are essential for protecting our community and ensuring different aspects of public safety. Depending on your specific needs, any of these approaches to threat and security assessment may be relevant to your officers.

As a next step, consider exploring some of the resources provided in this post, or check out some of our programs available for law enforcement.

Previous
Previous

Enhancing Security in the Gaming and Hospitality Industry

Next
Next

5 Threat And Risk Assessment Approaches for Security Professionals in 2026