What’s an alternative to threat modeling? If there was no TM, what the world would have been?

I agree with Hendrik. Threat Modeling has always been around!

Recently a group of us was teaching kids how to threat model at DEF CON. We provided a simple scenario: a picnic in the park, or a day at the beach, etc. The kids seemed to intuitively understand the concept to mean identifying problems that could ruin their day. Shark attacks, tornados, missing sunscreen, cars breaking down, it was all there!

They key is that our experiences and shared knowledge greatly improve the quality and applicability of threat modeling. It does’t matter if the kids learned about the dangers of sharks from a book, or about needing sunscreen from a parent, the knowledge was shared and they could apply it. They were able to imagine and mitigate a danger that they did not have to experience first hand.

The alternative is that without more formal threat modeling, we have less opportunity to mitigate and imagine dangers until we experience them first hand, one by one, industry by industry.

2 Likes