Behavioral Threat Assessment: Why Threat Classification Matters
- Dr. Chris Taylor

- 36 minutes ago
- 5 min read

As a former Dean of Students and BIT Chair, I constantly worried about how we applied our often-limited resources. Most of those resources, as anyone who has sat around a BIT/CARE table knows, are the people at that table, and most of them already wear two or three other hats. Add in the fact that there are typically plenty of cases competing for the team's attention, and figuring out where to put our time and energy becomes a pretty important part of the work.
I learned that one of the biggest mistakes I could make was assuming every threat deserved the same response. When a student says something alarming, it's natural for staff, parents, and administrators to focus on the worst-case scenario. I've certainly done it. The problem is that not every threat carries the same level of risk, and treating them as though they do can actually make schools less effective at preventing violence. If everything gets our highest-level response, we haven't really prioritized anything.
That idea sits at the heart of behavioral threat assessment, whose purpose has never been to predict the future with certainty. Instead, it helps multidisciplinary teams distinguish between situations requiring intensive intervention and those that can be addressed through less restrictive, supportive responses. A newly published multistate study, Violence Following a Threat Assessment: Do Threat Classification and School Safety Measures Matter?, offers some encouraging evidence that trained teams can make that distinction with a meaningful degree of accuracy.
The study examined 2,349 threat assessment cases from 166 schools across five states using the Comprehensive School Threat Assessment Guidelines (CSTAG). Much of the public conversation about school safety understandably focuses on the worst possible outcomes, so one of the first things that caught my attention was how rarely those outcomes occurred. Ninety percent of the cases did not result in an attempted attack. Even among the relatively small number that did, most involved physical assaults rather than catastrophic acts of targeted violence. Only seven cases, approximately 0.3% of all threat assessments, resulted in a serious injury, and no shootings or stabbings occurred within the study sample.
For those of us doing this work, though, I think the more interesting finding is what happened when the researchers looked at how the threats had been classified. Students whose threats were classified as serious substantive or very serious substantive were dramatically more likely to engage in an attack than students whose threats were classified as transient or not threats at all. Overall, the odds of an attack were roughly twenty times greater for serious threats than for non-serious threats.
That gets us back to the BIT/CARE table and all those people wearing multiple hats. For teams juggling multiple reports at a time, classification is part of how we decide where our time, attention, and resources belong. I have always thought there is some art to this. We are dealing with human behavior, incomplete information, context, and situations that can change as new information comes in. Two experienced team members can look at the same initial report and have somewhat different reactions to it. A structured process doesn't eliminate professional judgment, and I wouldn't want it to. It gives that judgment some structure and gives the team a common way to work through what it knows.
Rather than simply asking whether someone is “dangerous,” a structured threat assessment process allows us to consider context, intent, circumstances, behavior, and other information available to the team. Sometimes that leads to an intensive response. Sometimes it leads to something much less restrictive and more supportive. The important part is that the response grows out of the assessment rather than out of the anxiety generated by the original report.
Although this particular study focused on K-12 schools, I think the broader lesson extends pretty easily to higher education. Whether your institution calls its group a behavioral threat assessment team, a BIT, or a CARE team, one of its greatest strengths lies in its ability to triage concerns effectively. Collecting reports is important, but the real value comes from figuring out what those reports mean, what additional information is needed, and what intervention best matches the level of concern.
This can get harder than it sounds. A concerning social media post may look very different once the team understands what happened before it. A statement that initially sounds frightening may turn out to have been made in frustration with no intent or movement toward violence. On the other hand, something that doesn't sound particularly dramatic on first reading can become much more concerning when it is combined with a developing grievance, fixation on a target, significant losses, planning, or other behaviors. The initial report gets us to the table. It shouldn't necessarily determine what we do once we get there.
One other finding from the study caught my attention. The researchers examined whether schools with safety personnel or anonymous reporting systems experienced fewer attacks following threat assessments. Neither factor, by itself, was independently associated with lower attack rates. I would be careful about reading too much into that. It isn't evidence that safety personnel or anonymous reporting systems lack value, and both can be important parts of a school's prevention efforts. It does remind us, however, that there probably isn't one thing we can buy, install, or staff that will prevent violence on its own.
Threat assessment has always made more sense to me as a layered process. Educators, mental health professionals, safety personnel, administrators, and others bring different information and different ways of looking at a case. Reporting systems help get information to them. Security measures can help manage particular risks. Policies create options and boundaries. None of those things replaces the others, and none is especially useful if the people responsible for making sense of the information don't have a good process for doing it.
So, when I look at this study from a BIT/CARE perspective, I come away with a few questions I think are worth asking of our own teams. Are we consistently distinguishing between lower-risk and higher-risk cases, or have our responses started to look fairly similar regardless of classification? Once we classify a concern, do our interventions actually match the level of risk? When new information comes in, are we willing to reconsider our initial assessment? And have we invested as much in strengthening the team's decision-making process as we have in technology, security measures, reporting tools, and the other things that are much easier to point to when someone asks what we're doing about safety?
I would probably add one more question that is easy to overlook: Do we ever go back and see how we did? Not whether we perfectly predicted what happened, because that isn't the standard. Did the student stabilize? Did the situation escalate? Did additional information change our understanding of the case? Looking backward occasionally can tell us quite a bit about how we are making decisions going forward.
Good threat assessment has never been about predicting the future. We don't get that kind of certainty. It is about making good decisions with the information we have in front of us and being willing to change those decisions when the information changes. Studies like this don't replace professional judgment. What they can do is give us greater confidence that a structured, multidisciplinary process helps teams distinguish among very different kinds of threats and put limited resources where they are most needed. For those of us who have sat around a crowded BIT/CARE table wondering which case needs our attention first, that is useful evidence to have.
