A potential cause of an unwanted incident that could harm an asset, such as malware, human error, or a natural event.
A threat is anything with the potential to cause harm to an asset. Threats can be deliberate, such as an attacker, accidental, such as human error, or environmental, such as fire or flood.
A threat only becomes a risk when it can act on a vulnerability. Understanding relevant threats helps an organization focus its controls where harm is most likely.