Cybersecurity Glossary
Threat Modelling
Thinking through how something could be attacked, before it is built or deployed.
What Threat Modelling means
Threat modelling asks four questions about a system: what are we building, what could go wrong, what will we do about it, and did we do a good enough job. It works on a whiteboard, takes an hour or two, and is most valuable at design time when changes are still cheap.
Why Threat Modelling matters for small businesses and nonprofits
For a small organisation this is the cheapest security activity available. Applied to a new website, a new integration or a new supplier connection, it consistently catches issues that would otherwise be found in production.
What to do about Threat Modelling
- Run a short session whenever you add a system that handles money or personal data
- Draw the data flows first, since most issues appear at the boundaries
- Record the decisions, including the risks you chose to accept
Not sure where you stand on this?
We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.