? => Nächster Eintrag.
? => Ahead:
On June 3 2026, eleven threat modeling enthusiasts from TMC DACH gathered in an informal setting to explore the fourth question of the four-question framework: “Did we do a good (enough) job?”
The format was a campfire session — not a talk where one person presents all the answers, but a collaborative exploration of different perspectives on a shared topic.
The Four Questions of Threat Modeling
The four questions from Shostack’s Four Question Framework are:
- What are we working on?
- What can go wrong?
- What are we going to do about it?
- Did we do a good (enough) job?
Lilith (@Laxarella), who facilitated the evening, had noticed that the fourth question often gets dropped entirely — so much so that the group jokingly referred to it as the “three-question framework.”
So what does it actually mean to have done a good job in threat modeling?
Approach: Is good job job simply the absence of bad job?
Lilith referenced the work of Hendrik, who in his project The Threat Modeling of Threat Modeling applied threat modeling methods to the threat modeling process itself. Further contributions on this can be found under the term Meta Threat Modeling.
A positive approach to the question asks: What does a good job look like? → How do we get there?
A negative approach identifies potential future problems (threats) with the process itself → and then works to prevent, avoid, detect, and remediate them. Or we first assess the risk: How likely is this to affect us? How bad would it be? Just as we are used to doing in threat modeling.
The two approaches are often dual sides of the same coin: the goal of having identified all significant threats is equivalent to not having missed any significant threat.
Group Work
The subsequent group exercise invited participants to contribute various aspects of good or bad threat modeling work to a shared Excalidraw canvas.
The template was intentionally open to both approaches — positive and negative.
Participants contributed a rich and colorful mix of perspectives on what makes threat modeling good or bad.
The mid-sized group turned out to be a real advantage: there was enough time to review and discuss every entry after the collection phase.
It became apparent that for some participants, “a good job” can look quite simple — while for others, the bar is considerably higher. Participants also shared their experiences from threat modeling sessions they had already run. Some were already satisfied if threat modeling was simply well-received by the people involved. Others wanted to go deeper, and only considered it good work once all identified threats had been properly discussed.
Key Takeaways
It was fascinating to see just how differently the fourth question can be — and is — interpreted. There was, however, one point that no one disagreed with: the minimum shared baseline was that the people involved come away with a positive attitude toward threat modeling. If useful insights were also gained within a reasonable timeframe, all the better!
The negative approach turned out to be more productive when it came to generating actionable solutions: positive contributions often created a warm, pleasant feeling (“oh, that’s nice”), but rarely led to the follow-up question: How do we actually get there? The negative framing was much better at driving that discussion. A different facilitation style might have drawn out different results here.


