Technology · Security · Component
Threat model
What is worth protecting, who might want it, and the plausible routes by which harm could arrive.
The deliverable
What it is
A threat model turns a general worry into a list that can be prioritised. It names what matters to an attacker — customer data, payment flows, credentials, systems whose loss would stop trading — and the likely adversaries and routes for each.
The assets themselves are recorded once, in the asset register under Business Assets and in the system landscape; the threat model refers to those entries and adds the attacker’s view. The resulting risks are rated here and reported into the enterprise risk register under Governance, where appetite is set.
One level in
What it is made of
Each element is a constituent part of the component. Follow one to see the attributes it carries.
Assets in scope
The systems and information whose compromise would do the most harm, referenced from the existing registers.
3 attributes: Asset · Harm if compromised · Priority
LearnThreat scenarios
Plausible routes to harm — phishing, ransomware, a compromised supplier, an insider — described concretely.
3 attributes: Scenario · Threat source · Likelihood
LearnRisk rating
Likelihood and impact for each scenario, and the reference under which it is reported to the enterprise register.
3 attributes: Rating · Enterprise risk reference · Reviewed
Learn
Write the scenarios as stories. A named route to harm can be tested against controls; a risk category cannot.
The other components in security
Security control baseline
The recognised set of security controls the organisation has adopted, tailored to its threats, with the honest status of each.
LearnIdentity and access arrangements
How people and systems prove who they are, what privileged accounts exist, and how access follows people as they join, move and leave.
LearnBackup and recovery plan
What is backed up, how quickly each critical system must return, and dated evidence that restoring actually works.
Learn