The idea
A threat actor is a person or group whose actions can harm an information system. Motivation, capability and opportunity affect the threat they present.
Examples include financially motivated criminals, state-linked groups, ideologically motivated attackers and malicious insiders. An authorised account can also be misused after it is compromised.
People and mistakes
Accidental actions can create security incidents, but an error does not make someone a malicious actor. Clear guidance, usable controls and a supportive reporting culture help people respond safely.
A defensive question
Instead of assuming every attacker is highly sophisticated, ask: who might target this service, what would they want, and which opportunities are available? This supports proportionate decisions about controls.
Further reading
The NCSC’s 10 Steps to Cyber Security provides a starting point for managing organisational cyber risk.