AiVibe

Cybersecurity & Compliance

Threat Modelling

A structured, design-stage activity that identifies what could go wrong with a system, which threats matter most and which mitigations are needed, by analysing its architecture, data flows and trust boundaries.

Threat modelling usually starts with a diagram of the system, often a data flow diagram showing processes, data stores, external entities and the trust boundaries between them. The team then works through a widely used four-question framework: what is being built, what can go wrong, what will be done about it, and whether the analysis was good enough. Classification schemes help enumerate threats; STRIDE, developed at Microsoft, covers spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.

Performed early, threat modelling finds design flaws that testing tools cannot, such as missing authentication between services or excessive trust in a device, at the point where they are cheapest to fix. The OWASP Top 10 2021 category for insecure design calls for it, and in industrial product development IEC 62443-4-1 requires a threat model as part of a secure development life cycle for components and systems.

Other methods include PASTA, LINDDUN for privacy threats and attack trees, while the MITRE ATT&CK knowledge base helps ground threats in observed attacker behaviour. A threat model is a living document that should be revisited when the architecture changes. Its value depends on involving developers, architects and operations staff, and on tracking the identified mitigations to completion.

Key points

Where AiVibe comes in

AiVibe is ISO/IEC 27001:2022 certified, and its security services include vulnerability assessment and penetration testing, code security analysis (SAST, DAST, IAST, SCA), compliance gap analysis and 24/7 monitoring; AiVedha.ai runs more than 170 automated website security checks.

Explore AiVibe’s work in Cybersecurity & Compliance →

Related terms

Ask AiMuruga can explain Threat Modelling for your plant, product or security programme, and draw how it fits.