Threat
A threat is a credible cause with the potential to release a hazard and bring about the top event — the left-hand entry lines of a bowtie diagram. Each threat carries its own set of preventive barriers.
Threats answer the question "what could make the top event happen?" — internal corrosion, controller error, a phishing campaign, bearing failure, sustained excessive job demands. Each threat gets its own line on the left of the bowtie diagram, with its own chain of preventive barriers between it and the top event.
The standard test is credibility, not paranoia: a threat should be specific enough to defend against and realistic enough that someone in the room has seen it, or nearly seen it. "Human error" alone is too vague to barrier; "isolation error during maintenance on live pipework" points directly at the permit system, isolation verification, and supervision that must hold.
Threats are also where a bowtie stays honest about scale. Five to eight well-chosen threats usually cover a top event; twenty means the top event is probably set too early, or several threats are really the same one wearing different clothes.
Note the distinction with hazard: the hazard is the thing with energy or potential to harm (the flammable inventory, the moving aircraft, the sensitive dataset); a threat is a mechanism that releases it. The hazard belongs in the bowtie's header; the mechanisms belong on the lines.
Last reviewed 2026-08-09 · Back to the glossary
See the method in working software.
Six worked bowtie examples ship with the product — open one read-only, no sign-in, and read every control in full.