Skip to content

Cyber Threat

What is Cyber Threat?

A potential cyber attack that could compromise information systems, data, or services through exploitation of vulnerabilities.

Information Security

Each of these is named in at least one of the same controls as cyber threat. The number is how many controls name both.

What the standards actually require on cyber threat

Requirements naming cyber threat across 6 standards, quoted from the control text.

NIST SP 800-15010 controls

Organize, store, and manage collected cyber threat information to support analysis, correlation, and retrieval.

SP800-150-STORE · Organize and Store Cyber Threat Information
DORA4 controls

Financial entities shall classify ICT-related incidents and determine their impact based on criteria including the number/relevance of clients and transactions affected, geographical spread, data losses, criticality of services affected, and economic impact;

DORA-Art.18 · Classification of ICT-related incidents and cyber threats
NIS2 Directive3 controls

This duty is triggered by a threat rather than an incident. Where a significant cyber threat could affect the recipients of the entity's services, the entity must without undue delay communicate to those potentially affected recipients any measures or remedies...

nis2-directive::Art.23.2 · Tell affected service recipients about significant cyber threats and the remedies open to them

The manufacturer shall demonstrate processes to monitor for, detect, and respond to cyber attacks, cyber threats, and vulnerabilities on vehicle types, including the capacity to analyse and respond to information from the field.

R155-CSMS-MONITOR · Monitoring of cyber threats, vulnerabilities, and attacks

Types of cyber threats. The company should identify the types of cyber threats (untargeted and targeted, including malware, phishing, social engineering and OT-specific threats) that could affect ship systems.

BIMCO-2.2 · Types of cyber threats

Questions people ask about cyber threat

What is Cyber Threat?
A potential cyber attack that could compromise information systems, data, or services through exploitation of vulnerabilities.
Why is Cyber Threat important for compliance?
Cyber Threat is a key concept in Information Security. Understanding cyber threat helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Cyber Threat?
Cyber Threat appears in the requirement text of NIST SP 800-150, DORA, NIS2 Directive, NIST Cybersecurity Framework 2.0, UNECE WP.29 R155. Across these standards we have identified 22 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Cyber Threat?
Explore our compliance framework pages to see how cyber threat applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Cyber Threat applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.