Behavioral Threat Assessment: A Practical Guide for 2026
By Josh C.
Adults aged 60 and older filed 201,266 complaints and reported $7.75 billion in losses in 2025, according to reporting on the FBI's 2025 IC3 data. That figure changes how we should think about behavioral threat assessment. It isn't only a school security process or a response to an explicit threat. It's a disciplined way to recognize harmful behavior early, understand what it may mean, and choose a proportionate intervention before a person, organization, or family suffers preventable harm.
Behavioral threat assessment works best when people treat it as a repeatable process rather than an instinctive judgment. The strongest programs focus on observable actions, communications, context, and escalation. They don't label people based on age, diagnosis, background, personality, or appearance. They ask what happened, what changed, what the person appears capable of doing, and what support or control could reduce the risk.
That distinction matters in schools, workplaces, care settings, and households. It also matters as scammers use impersonation, urgent scripts, manipulated audio, and coordinated fraud networks to pressure victims. This guide explains the discipline in practical terms, then shows how teams can apply the same reasoning to live scam detection, older-adult vulnerability, insider risk, and workplace escalation.
What Behavioral Threat Assessment Really Means in 2026
The $7.75 billion reported loss among adults aged 60 and older in 2025 represents more than a cybersecurity problem. It shows how fraudsters manipulate behavior at scale. They create urgency, impersonate trusted authorities, isolate victims from family, and push them toward irreversible financial decisions. The FBI-related reporting on older-adult cybercrime shows why prevention must begin before money moves.
Behavioral threat assessment is a structured, evidence-based process for identifying, evaluating, and managing actions or communications that may signal harm to people, assets, or information. A student researching a target and sending a detailed threat may require assessment. An employee combining grievance fixation with attempts to access restricted systems may require it as well. In a family, repeated scam calls followed by concealed financial activity can signal that an older adult needs prompt support and protection.
The process works like a smoke alarm with a response plan. A signal starts inquiry, not a verdict. Screening asks whether a risk factor exists. Behavioral threat assessment examines what a specific person or pattern is doing, whether the behavior is moving toward harm, and which intervention fits the circumstances.
The U.S. Secret Service National Threat Assessment Center established NTAC in 1998, and its approach was widely adapted for schools by the early 2000s. In a national analysis of the 2017–18 school year, 80% of U.S. public schools reported conducting at least one threat assessment, with 14,869 assessments recorded. Of those, 1,472, or about 10%, reached the highest threat-level classification at some point, while fewer than 1% ended in an actual violent or harmful event. School officials reported 42 cases involving an event such as attempted harm to self or others. These findings support assessment as a prevention system, not a prediction-only tool.

The four operating pillars
A program that teams can run consistently rests on four connected pillars:
- Indicators: Observable behaviors, communications, changes, and circumstances.
- Process: Consistent intake, inquiry, analysis, intervention, and follow-up.
- People: A multidisciplinary group with assigned responsibilities.
- Governance: Privacy rules, documentation standards, review procedures, and accountability.
In 2026, these pillars must cover physical and digital settings. AI-generated impersonation, coordinated scam networks, remote-workplace access, social media, email, and phone conversations can all provide behavioral evidence. Technology can surface patterns. Trained people still interpret context, protect privacy, and decide what action to take.
Behavioral Threat Assessment vs Risk and Security Assessments
These three activities often overlap, but they answer different questions. A risk assessment examines broad threats, probability, and impact. A security assessment tests controls and vulnerabilities. Behavioral threat assessment begins with a person, message, or behavior pattern that needs closer judgment.
Use this decision lens:
- Choose a risk assessment when you're setting strategy, identifying important assets, or deciding which threats deserve investment.
- Choose a security assessment when you're checking whether access controls, policies, facilities, and technical safeguards work as intended.
- Choose behavioral threat assessment when a specific behavior, communication, or escalation pattern creates concern about likely harm.
A team may begin with a risk assessment and discover that insider misuse deserves attention. A security assessment may then reveal weak access reviews. Behavioral threat assessment becomes appropriate when an identified employee begins combining unusual access activity with threatening communications or grievance-driven escalation.
| Dimension | Risk Assessment | Security Assessment | Behavioral Threat Assessment |
|---|---|---|---|
| Purpose | Understand broad threats and potential impact | Validate safeguards, controls, and vulnerabilities | Evaluate a person or behavior pattern linked to possible harm |
| Inputs | Assets, scenarios, vulnerabilities, business priorities | Policies, system settings, facilities, records, control tests | Reports, communications, observed conduct, context, history |
| Output | Risk register, priorities, treatment options | Findings, control gaps, remediation actions | Written judgment, management plan, monitoring steps |
| Who runs it | Risk, compliance, leadership, or safety professionals | Security, audit, technical, or compliance personnel | Multidisciplinary team with behavioral and operational expertise |
| Typical timeframe | Planning cycle or major change | Review cycle, audit, or control change | Triggered by a concerning report and continued through follow-up |
A useful internal guide is a real-time risk assessment framework, particularly when an unfolding call, message, or access event requires immediate triage. The framework shouldn't replace a formal assessment, but it can help a designated responder capture facts while the situation develops.
Practical rule: Risk tells you where to look, security tells you what is exposed, and behavioral threat assessment tells you how a specific pattern may develop.
Mature safety programs use all three. They don't treat behavioral assessment as a substitute for good locks, sound identity verification, access governance, or emergency response. They use it to connect human behavior with the controls and resources designed to reduce harm.
Warning Behaviors and Core Components to Know
Warning behaviors are not proof of future violence or fraud. They're observable signals that deserve context and structured inquiry. NTAC materials report that among 173 mass attacks examined, 76% of offenders showed behaviors that elicited concern and 46% showed a change in behavior before the attack (NTAC materials). Those findings support early attention, not stereotyping.
Four behavior clusters
Pathway behaviors show movement from idea toward capability. Planning, researching a target, acquiring materials, rehearsing access, or testing a system can matter more than a vague angry comment. A school team might note searches about a specific location. A security team might notice attempts to obtain credentials or map restricted areas.
Fixation involves an increasingly obsessive focus on a person, grievance, institution, or cause. The concern grows when the subject repeats the grievance, expands the audience, rejects reasonable resolution, and spends more effort pursuing the target. Ordinary frustration usually allows competing interests to remain visible. Fixation narrows attention.
Identification appears when someone adopts the identity, language, symbols, or methods of attackers. Copying past offenders, writing a manifesto, collecting related media, or describing oneself as a warrior can signal a shift in self-concept. The behavior needs careful interpretation because interest alone doesn't establish intent.
Last-resort behavior can include leakage, final messages, giving away possessions, settling affairs, or communicating that there's no remaining option. These signals require immediate attention because they may accompany a perceived deadline or narrowing set of choices.
Scam-specific signals
Fraud creates a fifth practical cluster. An older adult who receives a “grandchild in trouble” call may show sudden urgency, secrecy about finances, repeated contact with an unknown caller, unusual payment requests, or pressure to bypass family and bank verification. One isolated change may have an innocent explanation. Several linked changes deserve a calm check-in.
Peer-reviewed work on older adults describes scam susceptibility as multifactorial, involving cognitive health, psychological wellbeing, and financial or health literacy rather than age alone (peer-reviewed research on older-adult scam susceptibility). That distinction helps caregivers ask better questions without treating an older person as incapable.
Program components
A functioning program needs a multidisciplinary team, structured intake, behavior-based inquiry, a case management system, an intervention menu, and an accountability loop. A family may use a smaller version with a trusted relative, bank contact, clinician, or social worker. An organization may include HR, legal, security, IT, and mental health professionals.
For a practical explanation of how conversational cues can reveal manipulation, see this guide to conversation analysis.

A Step-by-Step Framework Your Team Can Run
A team needs more than a list of warning signs. It needs a workflow that produces the same basic records regardless of who receives the first report. The following six stages create that repeatability.
1. Intake and triage
A designated point person logs the report, preserves the original message or observation, records the date and source, and screens out clearly non-credible noise. The case advances when the report includes a concrete behavior, target, threat, escalation, or vulnerability signal.
Responsible role: Intake coordinator or duty manager.
Artifact: Initial report and triage decision.
2. Information gathering
The assigned investigator collects context through witness interviews, document review, direct observation, relevant records, and permitted digital-footprint checks. The investigator separates firsthand facts from assumptions and records contradictions instead of smoothing them away.
Responsible role: Case lead, supported by HR, school staff, IT, or a caregiver.
Artifact: Source log and timeline.
3. Behavior analysis
The team maps actions against established warning-behavior indicators. It asks whether the subject has identified a target, developed capability, communicated intent, experienced a destabilizing change, or shown movement toward a deadline.
Responsible role: Multidisciplinary assessment team.
Artifact: Behavior analysis worksheet with evidence references.
4. Threat rating
The team assigns a low, medium, or high rating only after writing the rationale. The label matters less than the explanation. A low rating can still require support, while a high rating can require urgent protective action and outside coordination.
Responsible role: Team chair with documented agreement or dissent.
Artifact: Written risk judgment and escalation threshold.
5. Intervention planning
The team chooses controls and support that match the behavior. Options may include counseling referral, family contact, access changes, bank intervention, workplace separation, safety planning, law enforcement liaison, or closer monitoring. The plan must name who acts, by when, and what evidence will show whether the action worked.
Responsible role: Management-plan owner.
Artifact: Intervention plan with assigned tasks.
6. Follow-up and closure
The case remains active until the team checks whether behavior changed and whether new information alters the assessment. Scheduled review dates prevent a case from disappearing after the immediate crisis. Closure should record the reason, unresolved concerns, retained records, and lessons for future cases.
Responsible role: Case manager and team chair.
Artifact: Review notes, closure decision, and improvement actions.
A written process also protects against inconsistent decisions. A 2025 national school survey found that 51% of schools lacked formal standard operating procedures, fewer than half provided annual training, and resource constraints and parental disengagement were common barriers (State of BTAM 2025). Adoption alone doesn't prove operational quality.
Real-World Scenarios Where the Framework Applies
A 72-year-old retiree receives a phone call from someone claiming to represent her bank. The caller says a criminal is moving money through her account and insists she must wire funds immediately to a “protected” account. The caller tells her not to speak with her daughter because family members may be involved.
The intake record should capture the exact timeline, phone number, requested payment method, claimed identity, instructions, and any money already sent. The assessment doesn't need to decide whether the caller is sincere. It identifies a connected pattern, urgent pressure, authority impersonation, secrecy, and a request to bypass ordinary verification.
The intervention is practical: pause the transfer, contact the bank through a trusted channel, preserve messages and transaction details, and involve a family member or appropriate reporting agency with the older adult's consent. Follow-up can add call-screening rules, account alerts, and a family verification plan. The FTC's 2024–2025 report on protecting older consumers describes a multipronged federal approach involving law enforcement, rulemaking, and consumer education, reinforcing the need to combine immediate protection with reporting and education.
A different pattern appears at work. A mid-level employee whose reviews were once positive begins describing every management decision as a personal attack. The employee repeatedly returns to one grievance, searches for information about a supervisor's schedule, sends escalating messages, and asks coworkers to validate a narrative of persecution.
The team doesn't diagnose the employee or treat anger as proof of danger. It logs the timeline, interviews relevant witnesses, reviews permitted records, checks access needs, and evaluates whether grievance fixation is moving toward planning or capability. HR, security, legal, and a qualified mental health professional can then coordinate an intervention, such as a supported meeting, access review, workplace safety plan, and structured return-to-work check.
Schools face a related challenge because online behavior can quickly affect the physical community. Guidance on psychological safety in classrooms can help educators pair reporting and response systems with trust, belonging, and supportive communication.
Legal, Ethical, and Privacy Boundaries to Respect
Behavioral threat assessment must protect people without turning concern into punishment. Teams should identify the laws and policies that apply to the setting, including workplace, education, healthcare, caregiving, and disability-accommodation requirements. Monitoring communications requires appropriate notice, consent, authority, or another valid legal basis.
Collect the minimum necessary information for the decision. Privacy frameworks such as HIPAA and GDPR may apply depending on the setting and data involved. A family caregiver may document a bank call and a requested transfer, but shouldn't circulate unrelated medical details. A security team may need access records, but shouldn't gather broad personal data without a defined purpose.
| Setting | Required Records | Privacy Rule |
|---|---|---|
| Family caregiving | Dates, caller claims, requested actions, transaction details, observed changes | Share only with the older adult's consent or where an urgent legal or safety basis applies |
| Workplace | Reports, messages, interviews, access events, decisions, interventions | Limit access to authorized personnel and follow employment, monitoring, and accommodation rules |
| School or care setting | Incident reports, interviews, support plans, notifications, review notes | Follow education, health, child-protection, and disability privacy requirements |
Documentation should survive an audit. Record dates, sources, direct observations, decisions, dissent, and rationale. Distinguish fact from interpretation, redact unnecessary identifiers, and preserve original evidence when it may be shared with law enforcement. A chain of custody should show who collected, stored, accessed, or transferred each item.
Bias mitigation belongs in every review. The team should ask whether it's reacting to behavior or to identity, disability, age, culture, communication style, or protected activity. Accommodation and support may reduce risk more effectively than exclusion, while clear escalation paths ensure that urgent thresholds aren't delayed by uncertainty.
Before closing a case, ask: What must we record, what should we redact, who needs to know, and when should counsel or emergency responders join the process?
How AI and Screening Tools Extend the Model
AI can extend behavioral threat assessment into ordinary interactions, where human reviewers can't watch every call, email, message, or account event. The technology is useful when it detects patterns such as unusual timing, device changes, transaction sequences, scripted pressure, or repeated attempts to bypass verification.
A layered model works well:
- Call screening can flag urgency cues, authority impersonation, manipulative scripts, and known scam patterns before a person answers.
- Email filtering can identify phishing payloads, unusual sender behavior, suspicious links, and language designed to create panic.
- Routine monitoring can surface meaningful deviations, such as sudden financial activity or a sharp change in communication habits, when the person has agreed to that support.
- Case platforms can combine alerts into a reviewable timeline rather than leaving each signal in a separate system.
Technical reviews have reported that behavioral indicators, including evasive communication and CEO overconfidence, may precede financial irregularities by 6 to 24 months, while cited machine-learning studies reached 93% fraud-detection accuracy (behavioral analytics and forensic accounting review). These findings describe cited studies, not a guarantee for every tool or case.
Older-adult vulnerability signals
Caregivers should treat the following combination as a reason for a respectful check-in:
- Isolation: The person withdraws from family or trusted contacts.
- Bereavement: A recent loss changes emotional or practical support.
- New online activity: The person begins using unfamiliar platforms or investment services.
- Unsolicited contact: A new caller, “advisor,” romantic interest, or official reaches out unexpectedly.
- Sudden financial decisions: The person urgently transfers money, opens accounts, or hides transactions.
AI can sort volume and recall patterns continuously. It can't reliably determine intent, understand every family context, or show compassion when cognitive decline, grief, or fear affects communication. Human review must remain part of the decision.
Teams should route alerts into clear escalation tiers, preserve audit trails, and begin with one channel before adding more. A call-screening pilot can establish thresholds, ownership, and response times before email, SMS, and broader case aggregation are added. For the wider intelligence context, see this explanation of threat intelligence.

Role-Specific Checklists for Caregivers, Organizations, and Security Teams
Behavioral threat assessment becomes useful when each person knows the next action. These checklists should stay active, receive updates after real cases, and remain simple enough to use under pressure.
Caregivers and family members
- Watch routine changes: Note unusual secrecy, withdrawal, new contacts, or sudden financial activity.
- Verify unsolicited contact: End the call and use a trusted number for the bank, agency, family member, or provider.
- Ask without accusation: Invite the person to explain what happened before correcting or confronting them.
- Reduce exposure: Review what personal information is shared online and who can access financial details.
- Report suspected fraud: Preserve messages, numbers, payment records, and timelines before contacting the relevant institution or reporting channel.
- First seven days: Create a family verification phrase and a written list of trusted contact numbers.
Caregivers comparing safety technology can also consult this 3rd-i personal safety app review when evaluating options for family support.
Organizations and HR
- Write the policy: Define reportable behaviors, intake ownership, privacy limits, and emergency escalation.
- Train managers: Teach supervisors to document behavior rather than diagnose or label employees.
- Use a case record: Log every interaction, source, decision, intervention, and review date.
- Exercise the plan: Run tabletop scenarios involving workplace grievance, insider access, and online threats.
- Review communications: Check whether permitted monitoring and reporting processes identify escalation without excessive surveillance.
- First seven days: Appoint a case owner and publish a one-page intake form.
Security teams
- Map assets: Connect physical locations, systems, privileged access, and sensitive information to relevant insider-risk indicators.
- Join signal feeds: Coordinate physical security, identity, email, access, and incident-reporting data.
- Calibrate screening: Review false positives, missed signals, and escalation thresholds on a regular schedule.
- Preserve evidence: Maintain chain of custody and restrict case access to authorized personnel.
- Coordinate early: Bring legal counsel into decisions involving monitoring, discipline, disclosure, or disruptive action.
- First seven days: Select one recurring scenario and run the full intake-to-closure workflow as a tabletop exercise.
Gini Help offers AI-powered screening for calls, texts, and email, including an AI-first response to unknown callers and live analysis during calls a person answers. The service is available through Gini Help, and readers can also download the Gini Help app on Google Play or the Gini Help app on the App Store to add a practical screening layer for scam-related behavioral signals.
Start by documenting one real concern using the six-stage workflow, then assign a person to review it and set a follow-up date. For ongoing protection against suspicious calls, texts, and emails, visit Gini Help and choose the screening approach that fits your household or organization.