Threat modelling is a structured security engineering process that identifies, enumerates, and prioritises potential threats to a system by reasoning systematically about adversaries, attack vectors, and mitigations before or during design. It produces an explicit model of what can go wrong, enabling security controls to be allocated proportionally to risk, and is applied across software, hardware, and AI systems throughout the development lifecycle.
Threat modelling is a proactive Risk Assessment discipline that systematically identifies assets, adversaries, Attack Vectors, and mitigations for a system, enabling security-by-design rather than reactive patching.
Content
- Threat modelling has roots in Microsoft’s security development lifecycle (SDL) work of the early 2000s, where it was formalised as a mandatory design-phase activity. The STRIDE framework (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege), developed by Loren Kohnfelder and Praerit Garg at Microsoft in 1999, became the canonical taxonomy for categorising threats against system components. Concurrent with STRIDE, attack trees (proposed by Bruce Schneier) provided a hierarchical decomposition of how goals could be achieved by adversaries. These foundational frameworks remain widely used alongside newer approaches such as PASTA, VAST, and LINDDUN.
- A threat modelling exercise typically follows four questions: What are we building? What can go wrong? What are we going to do about it? Did we do a good enough job? Practitioners begin by creating a data flow diagram (DFD) or architecture diagram that identifies trust boundaries, data stores, processes, and external entities. Each component and data flow is then analysed using a threat enumeration method to identify attack scenarios. Threats are rated using scoring systems such as DREAD or CVSS to prioritise them. Mitigations—architectural changes, security controls, monitoring—are mapped to each threat, and residual risks are documented for acceptance or escalation.
- Threat modelling is applied across system types: web applications, APIs, cloud infrastructure, embedded systems, AI/ML pipelines, and supply chains. For AI systems, specialised extensions address adversarial attacks, data poisoning, model extraction, and prompt injection—categories absent from traditional frameworks. In regulated industries (finance, healthcare, defence), threat modelling is often mandated by compliance frameworks including ISO 27001, NIST SP 800-30, and the EU AI Act’s risk classification requirements.
- Between 2024 and 2025, the field has adapted rapidly to AI-specific threats. Frameworks such as MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) extend ATT&CK-style threat catalogues to ML attack chains. Automated threat modelling tools—including AI-assisted diagram analysis that generates STRIDE annotations automatically—have lowered the barrier to adoption for smaller teams. Regulatory pressure from the EU Cyber Resilience Act and US Executive Order on AI safety is driving broader mandatory adoption. The challenge of threat modelling agentic AI systems, which have non-deterministic behaviour and complex tool interactions, remains an active research and standards concern.