Threat Modeling

Threat modeling is the structured practice of identifying threats, attack paths, and appropriate mitigations for a specific system, application, or business process, typically performed during design and updated as systems evolve.

What Threat Modeling Actually Produces

A threat model documents what an adversary might attempt against a specific target, how they might attempt it, what damage would result, and what controls address the identified paths. It is the analytical bridge between abstract threat awareness and specific security decisions.

Common methodologies include STRIDE (Microsoft's spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege framework), PASTA (process-based approach), and attack tree modeling. Each has its own strengths, and mature programs often use several depending on the target and context.

Threat Modeling and MITRE ATT&CK

Modern threat models frequently incorporate MITRE ATT&CK techniques as reference, so identified attack paths use standardized vocabulary that connects to detection engineering, red teaming, and threat intelligence work.

When Threat Modeling Is Most Valuable

Threat modeling produces the highest value when performed early in system design, before controls are baked in and expensive to change. It also provides high value for critical systems as they evolve, and for specific scenarios in quantified programs where modeled loss depends on attack path assumptions.

Threat Modeling in CRQ

Threat models feed scenario analysis in CRQ. The identified attack paths, their likelihood, and the controls that address them are what shape frequency and severity distributions for modeled scenarios.

Related Terms

Turn Cyber Risk Into Financial Exposure the Board Can Act On

Security leaders are being asked to defend budgets, prioritize controls, and report cyber risk in the same terms as every other enterprise risk. Kovrr's CRQ Platform models loss scenarios, benchmarks control performance, and gives the C-suite a defensible view of where cyber sits on the balance sheet.