# Is there value in doing threat modeling even for existing applications?

**URL:** <https://threatmodelingconnect.discourse.group/t/is-there-value-in-doing-threat-modeling-even-for-existing-applications/37>\
**Category:** Techniques & Tooling\
**Created:** [November 19, 2022, 8:00am UTC](https://threatmodelingconnect.discourse.group/t/is-there-value-in-doing-threat-modeling-even-for-existing-applications/37 "2022-11-19T08:00:00Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![community\_migration](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/community_migration/32/366_2.png) [@community\_migration](https://threatmodelingconnect.discourse.group/u/community_migration)\
**Post date:** [November 19, 2022, 8:00am UTC](https://threatmodelingconnect.discourse.group/t/is-there-value-in-doing-threat-modeling-even-for-existing-applications/37/1 "2022-11-19T08:00:00Z")

</div>

Original post by @cbentue

It’s clear that there’s value in doing Threat Modeling a new application at design time, but what about existing applications? If the application is already deployed and ready, would you apply threat modeling for a specific security task? Thank you in advance.
