Threats are potentials for damage to assets, caused or by threat agents. This answers the question who is causing risk.

Read: A risk is a threat to an asset that makes use of a specific type of vulnerability the asset has (or might have).
Our threat catalogue is based on the catalogue of elementary threats of the German Bundesamt für Sicherheit in der Informationstechnik BSI.
- Attack
- Coercion, extortion or corruption
- Contamination, dust, corrosion
- Data loss
- Denial of service
- Destruction of equipment or data carriers
- Disasters in the surrounding area
- Disclosure of sensitive information
- Eavesdropping
- Electromagnetic interference
- Failure of devices or systems
- Failure or disruption of communication networks
- Failure or disruption of service providers
- Failure or disruption of supply networks
- Fire
- Harmful side effects of IT-based attacks
- Identity theft
- Incorrect or improper use of devices, systems and applications
- Information gathering (espionage)
- Information or products from unreliable sources
- Interception of compromising emissions
- Loss of devices, data carriers or documents
- Loss of integrity of sensitive information
- Major events in the vicinity
- Malfunction of devices or systems
- Malicious programs (malware)
- Manipulation of hardware or software
- Manipulation of information
- Message injection
- Misuse of authorisations
- Misuse of personal data
- Natural disasters
- Non-repudiation (denial of actions)
- Poor planning or lack of adaptation
- Power failure or disruption
- Resource shortage
- Sabotage
- Social engineering
- Software vulnerabilities or errors
- Staff shortages
- Theft of equipment, data carriers or documents
- Unauthorised entry into premises
- Unauthorised intrusion into IT systems
- Unauthorized use or administration of devices and systems
- Unfavourable climatic conditions
- Violation of laws or regulations
- Water