# Dangerous Individual
**Entity class:** Protective-intelligence concept
A **dangerous individual** is a person whose motive, acceptance of violence, current or foreseeable capacity, access, behavior, and target relationship together create a threat requiring assessment or management. Protective-intelligence doctrine asks whether attack is regarded as a desirable, acceptable, or potentially effective means to a goal and whether the person can mount it.
## Cybersecurity ontology
Within a generalized cybersecurity model of society, a dangerous individual can occupy three distinct roles at once:
1. **[[wiki/Threat Actor|Threat actor / threat source]]:** the person possesses the intent and method directed toward exploiting a weakness.
2. **[[wiki/Attack Vector|Attack vector]]:** the person's body, identity, credentials, relationships, or trusted role carries the attack through the system.
3. **[[wiki/Human Vulnerability Node|Vulnerability-bearing node]]:** the combination of [[wiki/Trusted Access|trusted access]], [[wiki/Placement and Access|placement]], authority, permissions, specialized knowledge, reachable assets, network position, and insufficient controls creates the exploitable condition.
For all practical systems purposes, this is a [[wiki/Human CVE|human CVE]]: **a vulnerability embodied in a person whose access, placement, capability, intent, and network position can create an exploitable path through a sociotechnical system.** The term is functional rather than bureaucratic. [[wiki/Common Vulnerabilities and Exposures|CVE]] remains the formal public enumeration system for disclosed product vulnerabilities; the human-CVE concept applies the same discovery, correlation, characterization, prioritization, and mitigation logic to human and institutional conditions.
The most exact risk mapping is:
**human threat source → exploitable placement or access → [[wiki/Attack Path|attack path]] → target system → consequence**
In an [[wiki/Insider Threat|insider-threat]] or counter-WMD environment, a technically healthy aircraft, laboratory, network, vehicle, facility, credential, or financial account can become catastrophically vulnerable because the authorized human occupying the right position has the intent and capability to activate what is reachable. The security state of the human component changes the security state of the whole system.
## Relationships
- **protective intelligence:** [[wiki/Threat Assessment|Threat Assessment]], [[wiki/Person as Threat System|Person as Threat System]], and [[wiki/Threat to Life|Threat to Life]].
- **cybersecurity mapping:** [[wiki/Human CVE|Human CVE]], [[wiki/Threat Source|Threat Source]], [[wiki/Attack Vector|Attack Vector]], [[wiki/Vulnerability|Vulnerability]], and [[wiki/Sociotechnical Attack Surface|Sociotechnical Attack Surface]].
- **trusted placement:** [[wiki/Insider Threat|Insider Threat]], [[wiki/Trusted Access|Trusted Access]], and [[wiki/Placement and Access|Placement and Access]].
- **master collection:** [[collections/Terrorism, Counterterrorism, and the Intelligence Environment|Terrorism, Counterterrorism, and the Intelligence Environment]].
## Sources
- [NIJ — Protective Intelligence and Threat Assessment Investigations, January 2000](https://ojp.gov/library/publications/protective-intelligence-and-threat-assessment-investigations-guide-state-and-0)
- [NIST Computer Security Resource Center — Threat Source](https://csrc.nist.gov/glossary/term/threat_source) (accessed 2026-09-23).
- [DCSA — Exploitation of Insider Access](https://www.dcsa.mil/Portals/128/Documents/CI/DCSA_CI_Best_Practices_booklet.pdf) (accessed 2026-09-23).
**As of:** 2026-09-23