Threat Modelling
Structured design-time analysis of threats, trust boundaries and mitigations.
What it is
Threat modelling systematically asks what can go wrong in a design: mapping data flows and trust boundaries, identifying threats (using approaches like STRIDE), and agreeing mitigations before building. It is the highest-leverage security activity in the lifecycle — an hour in design saves weeks in rework.
Coverage
- System decomposition and data-flow diagrams
- Trust boundary identification
- STRIDE-based threat enumeration
- Mitigation design and risk acceptance
- Team enablement and facilitation training
How we deliver
- Scope — system and depth agreed.
- Model — collaborative modelling workshops.
- Enumerate — threats per component and flow.
- Mitigate — controls with owners.
- Enable — train your teams to repeat it.
Outcomes
- Design risks found early
- Prioritised mitigation backlog
- Teams able to self-serve
- Security input developers respect