Security spending without one is guesswork, and it reliably goes to whatever was in the news. A threat model forces the awkward questions early: what is actually valuable here, who would want it, what are they willing to spend, and which of our controls would survive that. A competitor, a bored teenager and a ransomware crew are three different budgets and three different answers.
It does not need to be elaborate. A page naming the assets, the plausible attackers, the ways in and the controls that address them is enough to change decisions, and it is most useful during design, when changing the architecture is still cheap. Written afterwards, it tends to describe and justify what was already built.
Related terms
Penetration test
An authorised, scoped attempt to break into a system, done to find out what an attacker could actually achieve.
Security audit
A systematic review of a system against a standard or a set of criteria, aiming for coverage rather than for a way in.
Purple team
Running the attack and the defence as one exercise, so every fix is verified against the technique that found the hole.
The bench this belongs to
CybersecurityPurple Team: the same person writes the exploit and closes the hole. Most agencies only harden, which means hardening against a threat nobody tested.
