The 2026 Guide to Threat Assessment Approaches for Law Enforcement
In the law enforcement industry, accurately identifying and responding to threats is critical to maintaining safe spaces. Whether it involves reacting to active threats in real time or strengthening long-term predictive capabilities, threat detection and awareness are vital strategies to prevent violent incidents and reduce risk. Officers and agencies must protect against potential cyber attacks and ransomware, the influence of malign nation-states, transnational organized crime, and the ongoing risk of lone-wolf attacks.
But threat assessment means different things to different people, and the definition of threat assessment varies widely across fields. Security professionals, police, military personnel, psychologists, and school counselors all conduct tasks they describe as threat assessment. While all these tasks are predictive in nature, the methods and objectives differ. Understanding which type of threat you're trying to assess, and for what purpose, is the first step toward building an effective response.
For example, judges conduct threat risk assessments to assess whether someone poses a general danger to the public, while law enforcement typically concentrates on assessing imminent or immediate threats as part of the behavioral threat assessment and management (BTAM) process.
This guide was first published in 2019. I wrote it because I was having trouble differentiating between all the different types of threat assessment. It turns out that lots of people use the term to describe different techniques. Sometimes the term is used interchangeably with “risk assessment,” but that term does not fit in many circumstances.
Since its publication, this guide has proven to be one of our most popular posts. Between 2020 and 2026, 6,389 people from all over the world read this post. For a small company like us, this is awesome. We are proud to be helping police everywhere implement strategies that can help them protect their communities.
I hope you find this resource useful too. Don’t hesitate to reach out if we can help you or your organization.
Threat Assessment Approaches
Before diving into threat assessment, it’s important to clarify the specific problem you aim to address.
Are you looking to:
Plan for and protect facilities, soft targets, and critical infrastructure against terrorist attacks, insider threats, or natural disasters?
Equip your officers to observe and detect behavior-based threats and respond to individuals who pose immediate danger, such as active shooters?
Safeguard your computer networks, systems, and servers from attacks by malicious actors?
Identify, assess, and intervene with individuals who may commit targeted or instrumental violence, such as a mass shooting?
Evaluate a specific individual’s risk for violent behavior?
You can use this infographic to figure out which section will be most helpful to you:
1. The Security Threat and Risk Assessment
In the security and protection industry, threat assessment involves evaluating and analyzing potential risks that could compromise the safety of critical infrastructure and the people associated with a specific site or facility. It can also be a crucial tool for those seeking to protect soft targets from targeted violence.
This process focuses on identifying existing protective measures and vulnerabilities at facilities and implementing strategies to reduce those vulnerabilities and enhance safety. Assessments evaluate things like physical security, cybersecurity, and staffing protocols.
There are a broad range of threats that can affect a particular site or location, including:
External hazards: Natural disasters, fires, and other environmental risks;
Nonviolent and violent criminal threats: Theft, threats toward staff, active shooter incidents, or terrorist threats;
Potential accidents: Issues stemming from improper building maintenance or unsafe working conditions;
Cyber threats: Hacking, data breaches, ransomware, or other malicious activity targeting IT systems;
Operational disruptions: Threats that could impact telecommunications, transportation, or the delivery of essential services at the site.
Security Threat Risk Assessment at a School
For a security risk assessment, let’s take the example of an elementary or high school. Potential threats to a school could include natural disasters, active shooter incidents, or accidents arising from improper safety precautions. Each of these threats requires a different response. Visit Ready.gov to access emergency response plans for these different types of incidents.
This security threat risk assessment includes not only identifying potential threats but also assessing the likelihood of their occurrence. Just because something can happen doesn’t mean it will.
The Vulnerability Assessment
Following the security risk threat assessment is the vulnerability assessment, which has two parts.
Identifying assets and people at risk: This involves determining the critical assets—such as buildings, equipment, and personnel—that may be impacted. This includes an estimation of financial impacts that could result if the location were attacked and unable to provide services.
Evaluating target attractiveness and defenses: For intentional attacks, this step assesses how attractive the target may be to potential attackers. It also examines the current level of defenses in place to mitigate targeted attacks.
In schools, common security gaps include challenges in securing entry and access points, insufficient security measures due to budget constraints (such as limited surveillance/camera systems or a lack of security personnel), and insufficient training or experience among school staff in handling security-related incidents.
Schools often incorporate advanced technology into their security procedures. Learn more about the benefits and potential pitfalls of some of these security approaches in our recent blog posts:
-
If you are interested in learning more about security threat risk assessment, here are some great resources.
CISA’s Infrastructure Security and Resilience Assessments
Plan ahead for potential emergencies by developing procedures for crisis communications, emergency response, and evacuation.
Access free tools specific to school risk assessment:
The Department of Education’s REMS Site Assess App, which is a mobile app available on iOS and Android that helps schools conduct their own risk assessments.
The web-based K-12 School Security Assessment Tool (SSAT), which helps administrators evaluate their school’s existing security measures and identify areas for improvement.
2. Active Threat Assessment
Law enforcement professionals operate in complex environments where they must rapidly interpret human behavior and make decisions under uncertain and often high-pressure conditions. Behavioral threats may emerge during patrol operations, calls for service, investigative encounters, traffic stops, and public interactions. These situations require officers to recognize behavioral indicators early while maintaining officer safety, public trust, and effective policing. Observation and threat assessment are foundational expectations in law enforcement, but are rarely taught as a structured, repeatable skill.
In law enforcement, threat assessment can refer to the process of observing, identifying, and reacting to potential imminent and immediate threats. These threats may target your officers, the public, or both. At Second Sight, we use the term “active threat assessment” to describe our structured, repeatable observation process that strengthens systematic observation and visual threat detection skills during patrol and public interactions. This process helps officers recognize behavioral threat indicators during evolving encounters and distinguish benign behavior from deviations that may signal emerging threats.
The Active Threat Assessment Methodology
Observation is a foundational expectation in law enforcement, but it is often assumed rather than formally taught as a structured, repeatable skill. In policing environments, extensive training exists around tactical response, officer safety procedures, and investigative techniques, but the ability to systematically observe behavior is equally critical.
Active threat assessment refers to the structured, repeatable observation process that helps officers systematically observe their environment, recognize threatening behavioral indicators earlier during encounters, and make more informed decisions about how to respond.
In this approach, an observer, such as one of your officers, systematically scans their environment, identifies behavioral deviations that do not align with the environment, and distinguishes benign behavior from deviations that might signal emerging threats. Using this process, officers can identify pre-incident behaviors, or threat indicators, including those associated with individuals carrying weapons or preparing for violence. Recognizing these indicators helps officers identify a potential person of interest (POI) who warrants closer observation.
Visual threat detection techniques can help your officers consistently recognize meaningful behavioral deviations, interpret behavioral indicators, and clearly articulate what they observed and why it led them to act. Supervisors and agency leadership receive stronger documentation explaining why officers made particular decisions during rapidly evolving situations. This shift replaces inconsistent, intuition-based observation with a structured, teachable observation process that standardizes how officers recognize and interpret behavior across the agency, improves the quality and consistency of information supporting investigations, and enhances defensibility of actions taken during critical incidents.
Potential Users of Active Threat Assessment
A wide spectrum of law enforcement professionals can use Second Sight's active threat assessment approach, including:
Campus safety at higher-education institutions
School safety personnel at K-12 schools
Patrol officers, investigators, and agency leadership within law enforcement agencies
Second Sight offers active threat assessment training for law enforcement professionals through our Threat Awareness for Law Enforcement program. To date, Second Sight has delivered the 8-hour Threat Awareness program to thousands of security and law enforcement professionals worldwide. Because knowledge and skills gained through training can decay over time, a 1-hour refresher is also offered 6-12 months after the initial session to reinforce key concepts.
In our recent article, “Recognizing and Responding to Threats in the Real World,” we discuss feedback from 143 law enforcement and security professionals who completed the refresher training. When asked how frequently participants used the skills taught during the program, 1 in 2 participants indicated they used these skills everyday. In addition, 79% used the skills at least weekly, and 91.6% used the skills at least monthly. 96.5% of this group also reported an improved ability to articulate their decisions.
-
Description text goes heTo learn more about active threat assessment, check out our companion posts:
“Empowering Prevention: Lessons Learned from Brown University Shooting,” which highlights the importance of noticing pre-attack indicators; and
“Identifying Concealed Weapons at Protests,” which applies active threat assessment in the context of mass gatherings.
3. The Cyber-security Threat Risk Assessment
The same threat risk assessment process applies to cybersecurity, a critical component of overall risk management. A cybersecurity threat risk assessment focuses on protecting access to data and personal information, networks, software (e.g., internal communications or data management systems), as well as any hardware (e.g., your officers’ laptops and mobile phones).
A cyberattack is any deliberate attempt to gain unauthorized access to a network, computer system, or device. Attackers typically aim to steal, modify, expose, or destroy data and other assets using a variety of techniques.
One increasingly common type of cyberattack is ransomware. Ransomware is a form of malware that is installed on a system without the user’s knowledge or permission, often via websites, emails, or file attachments. Once infected, the ransomware locks and encrypts the user’s data, files, and systems, rendering them inaccessible or unusable until a ransom is paid to the attacker.
Ransomware can have dire consequences. Once data is compromised, there’s no guarantee the victim will get it back, even if they pay the ransom. Cybercriminals may still withhold or destroy the files.
In recent years, there has been a significant increase in the number of ransomware attacks, with several high-profile incidents occurring in hospitals, schools, and even government agencies. According to industry surveys conducted by Sophos in 2024, an estimated 67% of healthcare organizations, 80% of schools, and 69% of government agencies have experienced ransomware attacks. These incidents disrupt critical services, endanger lives, and cause devastating financial consequences.
-
To learn more about how to protect your organization against ransomware, check out the following resources:
NIST’s quick start guide to combating ransomware,
CISA’s best practices for protecting against and responding to ransomware attacks, and
The U.S. Ransomware Task Force’s #StopRansomware Guide.
The basic steps of a cybersecurity threat risk assessment are:
Identify the potential systems that are at risk.
Identify specific threats for each system (e.g., unauthorized access, misuse of information, data leakage or exposure, service disruptions).
Evaluate inherent risks and determine what potential consequences could result if threats materialize.
Analyze existing controls and measures in place to prevent, detect, mitigate, or compensate for threats.
Determine how well current safeguards successfully reduce risk and mitigate threats.
Evaluate the probability of a threat occurring based on existing controls.
Combine impact and likelihood to determine overall risk level and calculate a “risk rating.”
After the assessment, you will have a clearer understanding of existing cybersecurity controls and remaining vulnerabilities. From there, you can implement additional security measures to mitigate potential risks.
-
For information on how to apply cybersecurity best practices to public safety organizations, check out:
CISA’s resources for emergency services personnel
The International Association of Chiefs of Police (IACP)’s Law Enforcement Cyber Center
Free modules from CISA to help you implement cybersecurity best practices in your organization.
4. Threat Assessment for Instrumental Violence
Instrumental violence refers to acts or threats of targeted violence that are planned and purposeful, such as a targeted attack or mass shooting. For example, in a workplace setting this could involve an employee who has made threats against colleagues or has been involved in recent altercations. In a school setting, this could involve a student who has made threats against classmates or staff or exhibited expressions of intent to harm.
Threat assessment for instrumental violence is incident- and subject-specific, meaning it evaluates the likelihood that a particular individual will carry out a specific attack. This growing field is often referred to as Behavioral Threat Assessment and Management (BTAM) or Threat Assessment and Threat Management (TATM). For a general overview of this approach, check out the National Threat Evaluation and Reporting Program’s Behavioral Approach to Violence Prevention.
BTAM often occurs in team settings and can involve school administrators, community members, law enforcement, and mental health workers. You can learn more about threat assessment teams from recent research published by the National Counterterrorism Innovation, Technology, and Education Center (NCITE).
If you are looking to implement BTAM at your organization, the National Threat Evaluation and Reporting (NTER) Program offers courses for both trainers and trainees:
Behavioral Threat Assessment and Management (BTAM) Train-the-Trainer Program for public entities
The National Association of School Psychologists (NASP) outlines a broad framework for identifying and intervening with potentially violent individuals who exhibit risk factors for instrumental violence. In some instances, authorized personnel can use databases to access information about specific individuals to assess their risk factors.
A key authority in this area is the U.S. Secret Service National Threat Assessment Center (NTAC). In their 2023 report, Mass Attacks in Public Places, they found that many mass attackers share common characteristics, including personal grievances, history of criminal behavior, history of substance abuse or mental health symptoms, and other stressors such as financial instability. Additionally, many attackers exhibited concerning behaviors or made threatening statements before the attack. Being able to recognize these situational and behavioral indicators is essential for averting such attacks. For more information, check out the RAND corporation’s guidance on how to recognize potential warning signs of a mass attack and assess threat severity.
For resources specific to law enforcement, check out the following:
CISA’s tips for securing public gatherings
The Joint Counterterrorism Assessment Team’s First Responder Toolbox for Threat Assessment and Management
Threat Assessment in Schools
When it comes to preventing instrumental violence in schools, a nuanced approach is best. This process involves assessing students for multiple factors, including motives, communications, access to weapons, stressors, emotional problems, and developmental issues. For a deeper dive into this approach, check out our post on school behavioral threat assessment.
One alarming trend on the rise is the false reporting of attacks at schools and universities. These hoax calls are part of a coordinated “swatting” campaign that exploits the widespread fear of school shootings. Swatting involves making false reports of violent situations, such as a bomb threat or active shooter, to elicit a police response to a particular location, preferably by a SWAT team.
These incidents can be extremely dangerous, as they put the lives of individuals at risk and prompt law enforcement to respond aggressively, unaware that the situation is a hoax. The fear and trauma caused by the sudden, intense police response can have lasting psychological effects on those involved. Additionally, these incidents occupy emergency resources, potentially delaying response times for real emergencies.
-
For more general information on instrumental violence in schools, check out the following resources:
Our companion posts, “Identifying Active Threats in Schools” and “School Behavioral Threat Assessment”
CISA’s guide for responding to a swatting incident in K-12 schools
SchoolSafety.gov resources for preventing and mitigating targeted violence
The National Behavioral Intervention Team Association (NABITA)’s behavioral threat assessment tool
University of Illinois Chicago (UIC) Violence Prevention Plan for universities
5. The Violence Threat Risk Assessment
Violence threat risk assessments are used to better understand an individual’s tendency toward violence and estimate their likelihood to engage in violent behavior in the future. These assessments help practitioners and intervention providers make informed decisions about risk mitigation, supervision, and treatment options for potentially dangerous individuals. This is often referred to simply as a “violence risk assessment” or just “risk assessment.”
The difference between this approach and the instrumental approach in the previous section (e.g., BTAM) is that this approach evaluates an individual’s general tendency toward violence, while the instrumental approach predicts the likelihood of a specific attack on a specific target.
Typically, violence risk assessments are conducted by qualified clinical professionals rather than law enforcement. There are different types of violence threat risk assessments designed to predict different types of risks, ranging from domestic violence to terrorism. Some of these rely on the judgment of professionals, while others are actuarial-based.
Structured professional judgment (SPJ) approaches involve a systematic evaluation of risk factors by professionals who apply their expertise and judgment to assess an individual's level of risk.
One benefit of the SPJ approach is that professionals examine a wide range of aggravating and mitigating factors and can offer more personalized assessments. However, some criticize the SPJ approach for being too subjective and inconsistent when making risk evaluations due to variations in professional judgment and individual biases.
Well-known SPJ approaches include:
Actuarial-based risk assessment instruments (RAIs) use statistical methods and a scoring system to predict future risk, rather than relying on input from professionals. These tools use predetermined risk indicators that are informed by historical data and criminological theory to generate a numerical score, which reflects an individual’s likelihood of committing a specific act in the future.
In contrast with SPJ approaches, RAIs are consistent in making predictions based on the same inputs, as they rely on predetermined formulae to assess risk. However, there are concerns about their potential to outperform human judgment, as RAIs don’t adapt well to uncommon circumstances, and they often include static factors (such as being a male) that cannot be changed. Relatedly, if historical data is biased, the algorithm might perpetuate biases.
Commonly used actuarial-based RAIs include:
Ultimately, selecting the “best” risk assessment tool for a situation depends on the nature of the risk being assessed (e.g., violent extremism, general violence), the characteristics of the population being assessed (e.g., age, gender), and the setting or context of the assessment (e.g., school, correctional facility).
For a comprehensive approach to risk management for public entities, check out the Public Risk Innovation, Solutions, and Management (PRISM) framework. This framework covers all aspects of risk identification, assessment, and management, and includes various resources to assist organizations in various types of risks.
-
For more information on violence threat risk assessment, check out the following resources:
Open-access digital book Violent Extremism: A Handbook of Risk Assessment and Management by Caroline Logan, Randy Borum, and Paul Gill, published in 2023
The American Psychological Association (APA)’s Guidelines for Psychological Evaluation and Assessment
The Peace Officer Psychological Screening Manual, courtesy of California’s Commission on Peace Officer Standards and Training (POST)
The Department of Defense’s report on predicting violent behavior
Database of risk assessment tools, courtesy of the Berkman Klein Center
What’s Next?
All of these approaches to risk assessment are essential for protecting our community and ensuring different aspects of public safety. Depending on your specific needs, any of these approaches to threat and security assessment may be relevant to your officers.
As a next step, consider exploring some of the resources provided in this post, or check out some of our programs available for law enforcement.
-
Advancing Pretrial Policy & Research (APPR). (2026). “How the PSA Works.” Accessed June 2026 from https://www.advancingpretrial.org/how-the-psa-works/.
American Psychological Association (APA). (2020). APA Guidelines for Psychological Assessment and Evaluation. Accessed June 2026 from https://www.apa.org/about/policy/guidelines-psychological-assessment-evaluation.pdf
Berkman Klein Center. (2026). Risk Assessment Tool Database. Accessed June 2026 from https://criminaljustice.tooltrack.org/tools
Capellan, J.A., & Jiao, A.Y. (2019). Deconstructing Mass Public Shootings: Exploring Opportunities for Intervention. Rowan University: Rockefeller Institute of Government. Accessed June 2026 from https://rockinst.org/wp-content/uploads/2019/10/10-24-19-Deconstructing-Mass-Shootings-Brief-1.pdf
Criminal Intelligence Coordinating Council (CICC). (2016). Understanding Digital Footprints: Steps to Protect Personal Information. Global Advisory Committee: U.S. Department of Homeland Security. Accessed June 2026 from https://bja.ojp.gov/sites/g/files/xyckuh186/files/media/document/Understanding_Digital_Footprints-09-2016.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2014). Emergency Services Sector Roadmap to Secure Voice and Data Systems. Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/sites/default/files/publications/emergency-services-sector-roadmap-to-secure-voice-and-data-systems-032014-508.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2015). Emergency Services Sector-Specific Plan. Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/sites/default/files/publications/emergency-services-sector-specific-plan-112015-508_0.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2017). A Guide to Securing Networks for Wi-Fi, Version 1.0. Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/uscert/sites/default/files/publications/A_Guide_to_Securing_Networks_for_Wi-Fi.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2019). Emergency Services Sector Landscape, Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/sites/default/files/publications/emergency-services-sector-landscape-082019-508.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2020). Cyber Essentials Toolkits. Accessed June 2026 from https://www.cisa.gov/resources-tools/resources/cyber-essentials-toolkits
Cybersecurity and Infrastructure Security Agency (CISA). (2022). Guide to Getting Started with a Cybersecurity Risk Assessment. Accessed June 2026 from https://www.cisa.gov/sites/default/files/2024-09/24_0828_safecom_guide_getting_started_cybersecurity_assessment_2022_final_508C.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2022). Ransomware Response Checklist. Accessed June 2026 from https://www.cisa.gov/sites/default/files/publications/Ransomware_Response_Checklist_508.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2023). #StopRansomware Guide. Accessed June 2026 from https://www.cisa.gov/sites/default/files/2025-03/StopRansomware-Guide%20508.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (2024). Anonymized Threat Response Guidance: A Toolkit for K-12 Schools. Accessed June 2026 from https://www.cisa.gov/sites/default/files/2024-10/ATRGToolkit508_V2.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (N.d.). “Critical Infrastructure Assessments.” Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/critical-infrastructure-assessments
Cybersecurity and Infrastructure Security Agency (CISA). (N.d.). “Cybersecurity for K-12 Education.” Accessed June 2026 from https://www.cisa.gov/topics/cybersecurity-best-practices/K12cybersecurity
Cybersecurity and Infrastructure Security Agency (CISA). (N.d.). School Security Assessment Tool (SSAT). K-12 School Security Guide Product Suite, Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/school-security-assessment-tool
Cybersecurity and Infrastructure Security Agency (CISA). (N.d.). Active Shooter Emergency Action Plan. Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/sites/default/files/publications/active-shooter-emergency-action-plan-112017-508v2.pdf
Cybersecurity and Infrastructure Security Agency (CISA). (N.d.). “Resilience Services.” Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/resilience-services
Cybersecurity and Infrastructure Security Agency (CISA). (N.d.). “Securing Public Gatherings.” Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/topics/physical-security/securing-public-gatherings
Defense Science Board (DSB). (2012). Predicting Violent Behavior. Task Force Report. U.S. Department of Defense. Accessed June 2026 from https://irp.fas.org/agency/dod/dsb/predicting.pdf
Douglas, K.S., Hart, S.D., Webster, C.D., & Belfrage, H. (2014). “HCR-20: The World’s Leading Violence Risk Assessment Instrument.” Mental Health Law and Policy Institute. Accessed June 2026 from http://hcr-20.com/
Duits, N., & Pressman, D.E. (2024). “The Violent Extremism Risk Assessment 2 Revised (VERA-2R).” Ministry of Justice and Security. Accessed June 2026 from https://www.vera-2r.nl/
Enang, I., Murray, J., Dougall, N., Aston, E., Wooff, A., Heyman, I., & Grandison, G. (2021). Vulnerability assessment across the frontline of law enforcement and public health: A systematic review. Policing and Society, 32(4), 1-20. Accessed June 2026 from https://doi.org/10.1080/10439463.2021.1927025
Harris, G.T., Rice, M.E., Quinsey, V.L., & Cormier, C.A. (2015). Violence Risk Appraisal Guide Revised (VRAG-R) Scoring Sheet. VRAG-R Official Website. Accessed June 2026 from http://www.vrag-r.org/wp-content/uploads/2021/12/VRAG-R-scoring-sheet-1.pdf
International Association of Chiefs of Police (IACP). (2017). Managing Cybersecurity Risk: A Law Enforcement Guide. Accessed June 2026 from https://www.iacpcybercenter.org/wp-content/uploads/2015/04/Managing_Cybersecurity_Risk_2017.pdf
International Association of Chiefs of Police (IACP). (2026). Law Enforcement Cyber Center. Accessed June 2026 from https://www.theiacp.org/resources/law-enforcement-cyber-center
Joint Counterterrorism Assessment Team (JCAT). (2023). Threat Assessment and Threat Management (TATM): Assessment and Management. First Responder’s Toolbox. Accessed June 2026 from https://www.dni.gov/files/NCTC/documents/jcat/firstresponderstoolbox/138cs_-_First_Responder_Toolbox_-_Threat_Assessment_and_Threat_Management_-TATM_-_A_Model_Critical_to_Terrorism_Prevention_3_of_3.pdf
Kropp, P.R., Hart, S.D. (2000). “Spousal Assault Risk Assessment (SARA) Guide.” Gender Empowerment Measures Repository. Accessed June 2026 from https://emerge.ucsd.edu/r_1plrabytih9j494/
Logan, C., Borum, R., & Gill, P. (2023). Violent Extremism: A Handbook of Risk Assessment and Management. UCL Press: London, UK. Accessed June 2026 from https://discovery.ucl.ac.uk/id/eprint/10179192/1/Violent-extremism.pdf
Mahendru, P. (2024). “The State of Ransomware in Healthcare 2024.” Sophos News. Accessed June 2026 from https://news.sophos.com/en-us/2024/07/30/the-state-of-ransomware-in-healthcare-2024/
Mahendru, P. (2024). “The State of Ransomware in State and Local Education 2024.” Sophos News. Accessed June 2026 from https://news.sophos.com/en-us/2024/07/11/the-state-of-ransomware-in-education-2024/
Mahendru, P. (2024). “The State of Ransomware in State and Local Government 2024.” Sophos News. Accessed June 2026 from https://news.sophos.com/en-us/2024/08/14/the-state-of-ransomware-in-state-and-local-government-2024/
Mayorkas, A.N. (2022). Summary of Resources for State, Local, Tribal, Territorial, and Campus Law Enforcement Partners. U.S. Department of Homeland Security. Accessed June 2026 from https://www.dhs.gov/sites/default/files/2022-04/22_0407_OSLLE_LE-resource-guide-signed_508.pdf
National Association for Behavioral Intervention and Threat Assessment (NABITA). (2014). “Threat Assessment Tool.” Accessed June 2026 from https://cdn.nabita.org/website-media/nabita.org/wordpress/wp-content/uploads/2014/04/2014-NaBITA-Threat-Assessment-Tool.pdf
National Association of School Psychologists (NASP). (2024). “Behavior Threat Assessment and Management (BTAM) Best Practice Considerations for K–12 Schools.” Accessed June 2026 from https://www.nasponline.org/resources-and-publications/resources-and-podcasts/school-safety-and-crisis/systems-level-prevention/threat-assessment-at-school/behavior-threat-assessment-and-management-(btam)-best-practice-considerations-for-k%E2%80%9312-schools
National Association of School Psychologists (NASP). (2015). “School Violence Prevention: Guidelines for Administrators and Crisis Teams.” Accessed June 2026 from https://www.nasponline.org/resources-and-publications/resources-and-podcasts/school-safety-and-crisis/school-violence-resources/school-violence-prevention/school-violence-prevention-guidelines-for-administrators-and-crisis-teams
National Institute for Occupational Safety and Health (NIOSH). (2026). “Violence Risk Assessment Tools.” Centers for Disease Control and Prevention. Accessed June 2026 from https://wwwn.cdc.gov/WPVHC/Nurses/Course/Slide/Unit6_8
National Institute of Standards and Technology (NIST). (2022). Getting Started with Cybersecurity Risk Management: Ransomware Joint Task Force Transformation Initiative, Risk Management Framework Team. Accessed June 2026 from https://csrc.nist.gov/files/pubs/other/2022/02/24/getting-started-with-cybersecurity-risk-management/final/docs/quick-start-guide--ransomware.pdf
National Threat Assessment Center (NTAC). (2019). Protecting America’s Schools: A U.S. Secret Service Analysis of Targeted School Violence. U.S. Secret Service: Department of Homeland Security. Accessed June 2026 from https://www.secretservice.gov/sites/default/files/2020-04/Protecting_Americas_Schools.pdf
National Threat Assessment Center (NTAC). (2021). Averting Targeted School Violence. U.S. Secret Service: Department of Homeland Security. Accessed June 2026 from https://www.secretservice.gov/sites/default/files/reports/2021-03/USSS%20Averting%20Targeted%20School%20Violence.2021.03.pdf
National Threat Assessment Center (NTAC). (2023). Mass Attacks in Public Spaces: 2016-2020. U.S. Secret Service: Department of Homeland Security. Accessed June 2026 from https://www.secretservice.gov/sites/default/files/reports/2023-01/usss-ntac-maps-2016-2020.pdf
National Threat Evaluation and Reporting (NTER). (2026). Foundations of Targeted Violence Prevention Bystander Awareness Training. Accessed June 2026 from https://www.dhs.gov/foundations-targeted-violence-prevention
National Threat Evaluation and Reporting (NTER). (2026). Master Trainer Program. Accessed June 2026 from https://www.dhs.gov/mtp
National Threat Evaluation and Reporting Program. (N.d.). Behavioral Approach to Violence Prevention. Office of Intelligence Analysis: Department of Homeland Security. Accessed June 2026 from https://sites.ed.gov/whhbcu/files/2022/01/Behavioral-Approach-to-Violence-Prevention.pdf
Nguyen, T. L., Scalora, M. J., & Bulling, D. (2024). Behavioral Threat Assessment and Management Programs: Practitioner-Informed Baseline Capabilities. National Counterterrorism Innovation, Technology, and Education Center (NCITE), Dept. of Homeland Security. Reports, Progress, and Research. 100. Accessed June 2026 from https://digitalcommons.unomaha.edu/ncitereportsresearch/100/
Occupational Safety and Health Administration (OSHA). (N.d.). “Evacuation Planning Matrix.” U.S. Department of Labor. Accessed June 2026 from https://www.osha.gov/emergency-preparedness/evacuation-matrix
Powis, B., Randhawa-Horne, K., & Bishopp, D. (2019). The Structural Properties of the Extremism Risk Guidelines (ERG22+): A Structured Formulation Tool for Extremist Offenders. Ministry of Justice and Security. Accessed June 2026 from https://assets.publishing.service.gov.uk/media/5d274ad140f0b61119a41cf1/the-structural-properties-of-the-extremism-risk-guidelines-ERG22.pdf
PRISM. (2026). Public Risk Innovation, Solutions, and Management: PRISM. Accessed June 2026 from https://www.prismrisk.gov/
RAND Corporation (N.d.). “In Depth: Databases to Support Threat Assessments.” Mass Attacks Defense Toolkit. Accessed June 2026 from https://www.rand.org/pubs/tools/TLA1613-1/toolkit/prevent/threat-assessment/databases.html
RAND Corporation (N.d.). “Threat Assessment: Finding and Putting Together the Puzzle Pieces.” Mass Attacks Defense Toolkit. Accessed June 2026 from https://www.rand.org/pubs/tools/TLA1613-1/toolkit/prevent/threat-assessment.html
RAND Corporation (N.d.).”Initial Detection: Through Increasing Tips and Leads and Information Sharing.” Mass Attacks Defense Toolkit. Accessed June 2026 from https://www.rand.org/pubs/tools/TLA1613-1/toolkit/prevent/initial-detection.html
Ready Campaign. (2026). “Business Impact Analysis.” Accessed June 2026 from https://www.ready.gov/business/planning/impact-analysis
Ready Campaign. (2026). “Crisis Communications Plans.” Accessed June 2026 from https://www.ready.gov/business/emergency-plans/crisis-communications-plans
Ready Campaign. (2026). “Disasters and Emergencies.” Accessed June 2026 from https://www.ready.gov/be-informed
Ready Campaign. (2026). “Emergency Plans.” Accessed June 2026 from https://www.ready.gov/business/emergency-plans
Ready Campaign. (2026). “Emergency Response Plan.” Accessed June 2026 from https://www.ready.gov/business/implementation/emergency
Ready Campaign. (2026). “Risk Assessment.” Accessed June 2026 from https://www.ready.gov/business/planning/risk-assessment
Risk Management Authority of Scotland. (2019). Level of Service Inventory Revised (LSI-R). Accessed June 2026 from https://www.rma.scot/wp-content/uploads/2023/01/Level-of-Service-Inventory-Revised-LSI-R.pdf
Robinson, P. (2024). “15 Most Common Types of Cyber Attack and How to Prevent Them.” Accessed June 2026 from https://www.lepide.com/blog/the-15-most-common-types-of-cyber-attacks/
Ruggiero, P., & Foote, J. (2011). Cyber Threats to Mobile Phones. U.S. Computer Readiness Team: Department of Homeland Security. Accessed June 2026 from https://www.cisa.gov/uscert/sites/default/files/publications/cyber_threats_to_mobile_phones.pdf
Savage, T.A. (2019). School-Based Behavioral Threat Assessment and Management: General Considerations. Presentation at the Minnesota School Psychologists Association: Plymouth, MN. Accessed June 2026 from https://www.youtube.com/watch?v=RXJj_bTRh5U
SchoolSafety.gov. (2025). “Targeted Violence.” Accessed June 2026 from https://www.schoolsafety.gov/targeted-violence
Slater, J. (2023). “Coordinated ‘Swatting’ Effort May Be Behind Hundreds of School Shooting Hoaxes.” Washington Post. Accessed June 2026 from https://www.washingtonpost.com/nation/2023/10/04/school-swatting-hoax-active-shooter/
State of California. (2024). Peace Officer Psychological Screening Manual. California Commission on Peace Officer Standards and Training. Accessed June 2026 from https://post.ca.gov/peace-officer-psychological-screening-manual
Threat Intelligence. (2024). “Understanding Threat and Risk Assessment: A Quick Guide.” Accessed June 2026 from https://www.threatintelligence.com/blog/threat-and-risk-assessment
University of Cincinnati Corrections Institute (UCCI). (ND). Ohio Risk Assessment System. Accessed June 2026 from https://cech.uc.edu/content/dam/refresh/cech-62/ucci/overviews/oras-overview.pdf
University of Illinois. (2026). “Violence Prevention Plan.” Office of Preparedness and Response, University of Illinois: Chicago. Accessed June 2026 from https://ready.uic.edu/planning/violence-prevention/
Virginia Department of Criminal Justice Service. (2018). Virginia Pretrial Risk Assessment Instrument (VPRAI) Instruction Manual, Version 4.5. Accessed June 2026 from https://www.dcjs.virginia.gov/sites/dcjs.virginia.gov/files/publications/corrections/virginia-pretrial-risk-assessment-instrument-vprai_2.pdf

