Technology · Security · Component

Threat model

What is worth protecting, who might want it, and the plausible routes by which harm could arrive.

The deliverable

What it is

A threat model turns a general worry into a list that can be prioritised. It names what matters to an attacker — customer data, payment flows, credentials, systems whose loss would stop trading — and the likely adversaries and routes for each.

The assets themselves are recorded once, in the asset register under Business Assets and in the system landscape; the threat model refers to those entries and adds the attacker’s view. The resulting risks are rated here and reported into the enterprise risk register under Governance, where appetite is set.

One level in

What it is made of

Each element is a constituent part of the component. Follow one to see the attributes it carries.

  1. Assets in scope

    The systems and information whose compromise would do the most harm, referenced from the existing registers.

    3 attributes: Asset · Harm if compromised · Priority

    Learn
  2. Threat scenarios

    Plausible routes to harm — phishing, ransomware, a compromised supplier, an insider — described concretely.

    3 attributes: Scenario · Threat source · Likelihood

    Learn
  3. Risk rating

    Likelihood and impact for each scenario, and the reference under which it is reported to the enterprise register.

    3 attributes: Rating · Enterprise risk reference · Reviewed

    Learn

Write the scenarios as stories. A named route to harm can be tested against controls; a risk category cannot.