Subcapability 02 of 04 · Security Engineering

Threat Modeling

STRIDE and attack trees in design that identify threats before any code exists, eliminate forced redesign from production vulnerabilities and embed risk into architectural reasoning.

What is at stake

The team designed the partner integration without mapping what happens when the token is stolen. They discovered it in production, with a customer affected and a mandatory incident notification. Every architectural decision that ignores potential threats defers the cost of security to the moment of maximum impact.

What it is, in practice

A vulnerability discovered in production requires two simultaneous costs. The technical remediation cost, which in established architecture may require significant redesign. And the user impact cost, which in financial or healthcare systems carries regulatory consequence. Both are avoidable when the threat is identified before any code is written. The design stage is when changing a security decision costs a conversation, not a sprint of rework.

How we work

Measurable gains

What changes in the result when this subcapability matures.

Frequently asked questions

Who should conduct threat modeling: the security team or the product team?

The most effective threat modeling is conducted collaboratively. The product team knows the domain and use cases. The security team knows attack patterns. Security Champions in squads are the bridge that makes this process scalable without depending on a centralized specialist for each feature. The result of collaboration is a threat model that covers both technical threats and threats specific to the business context.

How frequently should the threat model be updated?

Each relevant architectural change justifies a review: new integration with an external system, new personal data flow, change in the authentication model, new public endpoint. Systems that do not change may have a semi-annual review. Systems in active development should have a review at each significant design sprint. The criterion is change in attack surface, not calendar.

How to choose between STRIDE and PASTA for threat modeling?

STRIDE is more suitable for teams starting with threat modeling: the six-category structure is direct and applicable to any type of system. PASTA adds business impact analysis and attack scenario simulation, making it more suitable for systems with high direct financial or regulatory risk exposure. For most contexts, STRIDE with MITRE ATT&CK as an adversary reference covers the necessary spectrum.

What is MITRE ATT&CK and how does it help in threat modeling?

MITRE ATT&CK is a knowledge base of tactics and techniques used by real adversaries, organized by attack phase. In threat modeling, ATT&CK helps ground threat hypotheses in observed adversarial behavior rather than generic theoretical threats. For each system, it is possible to identify which techniques from the matrix are relevant given the most likely adversary profile, making the analysis more precise and prioritized.

Does threat modeling apply only to new systems or also to legacy systems?

It applies to both, with different approaches. For new systems, threat modeling occurs during design. For legacy systems, it starts with a current-state threat model that maps the existing attack surface, identifies present and absent controls, and prioritizes remediation by risk. Many organizations discover, in their first threat model of a legacy system, threats that existed for years without associated controls.

Want clarity on where to invest first?

A complete technology capability assessment with an evolution roadmap connected to financial result.