What Is Security Threat Modeling?

Due to the rapid advancement of technology, the increased risk of cyber-attacks and system breaches has become a day to day issue that constantly needs to be addressed. From running payment software to data collection to use of the cloud, every area of an organization needs to be aware of liabilities as well as put plans into place to protect against them. However, when it comes to IT and tech, many organizations see security as a complex problem that is so big and intimidating that they often become lost on how to start or where to focus vital resources.

And, to make the problem worse, understanding the actual threat model can be complex. The answer of most organizations is to seek help from cybersecurity specialists who immediately ask, “what is your threat model?”–a jarring question that in-and-of-itself is exceptionally difficult to answer. The truth is, ‘‘threat modeling” is obscure jargon that does not reference one thing specifically and has no agreed-upon standard within the tech security industry. Commonly thought of as the act of being prepared and prioritizing threats, if you do some research on the topic, you will quickly realize there are a variety of expert opinions, framework structures, and methodologies out there. Nevertheless, threat modeling is one of the most important parts of the day to day practice of security.

In the following article, we will take a look at what threat modeling is, undercover how to answer the above question with confidence, and why there are so many frameworks from which to choose.

What is Threat Modeling?

Intended to be used as a cost-effective tool to help software/IT teams implement features that protect systems, at its core threat modeling is very simple. According to Wikipedia, it is defined as “a process by which potential threats, such as structural vulnerabilities or the absence of appropriate safeguards, can be identified, enumerated, and mitigations can be prioritized. The purpose of threat modeling is to provide defenders with a systematic analysis of what controls or defenses need to be included, given the nature of the system, the probable attacker’s profile, the most likely attack vectors, and the assets most desired by an attacker.” It can technically be applied to any aspect of life, serving as the foundation of everything a security professional does.

With that, beyond the core of what threat modeling is, the complexity of answering “what is your threat model?” starts when addressing all the different technical aspects of your unique organization as well as keeping in mind how different causes combine to create new threats. In reality, there is an unlimited number of threats that could cause damage to the security of an organization. Daunting as it may sound, ultimately, the end result of a strong threat model is an overview of a system as well as profiles of attackers with goals, along with a full list of vulnerabilities, outside threats, and potential inside breaches.

What Most Threat Models Include

Due to the uniqueness in nature, most threat models do not look the same but generally include the following basics:

  • A description of the threat
  • A list of assumptions regarding the function of the software or organization that can be reviewed in the future
  • Vulnerabilities
  • Actions for each vulnerability
  • How to review and verify the vulnerabilities are being watched and are secure
Marcus Vance

Marcus Vance

Cybersecurity & Digital Privacy Researcher

Marcus Vance is a cybersecurity auditor and technology writer dedicated to educating the public about online safety, data privacy regulations, enterprise security, and emerging cyber threats.

Share this article