# Threat model

> A written answer to who would attack this, what they would want, and what would actually stop them.

Security spending without one is guesswork, and it reliably goes to whatever was in the news. A threat model forces the awkward questions early: what is actually valuable here, who would want it, what are they willing to spend, and which of our controls would survive that. A competitor, a bored teenager and a ransomware crew are three different budgets and three different answers.

It does not need to be elaborate. A page naming the assets, the plausible attackers, the ways in and the controls that address them is enough to change decisions, and it is most useful during design, when changing the architecture is still cheap. Written afterwards, it tends to describe and justify what was already built.

## Related terms

- https://dfieldsolutions.com/en/glossary/penetration-test.md
- https://dfieldsolutions.com/en/glossary/security-audit.md
- https://dfieldsolutions.com/en/glossary/purple-team.md

---

Source: https://dfieldsolutions.com/en/glossary/threat-model
DField Solutions — Dunakeszi, Hungary — dezso@dfieldsolutions.com
Booking: see https://dfieldsolutions.com/en/contact
