7 min read

How to Threat-Model a System You Have Never Seen Before

Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. Here is the version that does

Threat Modelling Purple Teaming

Most threat-modelling advice assumes you have weeks, a working relationship with the engineering team, and a system that is stable. None of those apply when you are walking into a new environment on a Tuesday afternoon. The environment is in production. The engineering team is busy. The documentation does not exist. The threat model is needed by Friday.

Here is the version that does.

The first hour

The first hour is not the threat model. The first hour is the orientation. The first hour is the work of understanding what the environment is, what the environment does, and who the environment matters to.

The first hour is the work of asking the obvious questions. The first hour is the work of asking what the system does. The first hour is the work of asking who uses the system. The first hour is the work of asking what the system is connected to. The first hour is the work of asking what the system has access to. The first hour is the work of asking what would happen if the system were unavailable. The first hour is the work of asking what would happen if the system were compromised.

The first hour is the work of the conversation. The first hour is the work of the conversation with the engineering team, the operations team, the security team, the business owner. The first hour is the work of the conversation that gives the threat model the context that the threat model needs.

The first hour is the work that the threat-modelling advice skips. The first hour is the work that the threat-modelling advice assumes the threat-modeller has done. The first hour is the work that the threat-modeller has to do.

The first day

The first day is the data-flow diagram. The first day is the work of mapping the system. The first day is the work of mapping the components. The first day is the work of mapping the trust boundaries. The first day is the work of mapping the data flows.

The first day is the work of building the diagram that the threat model is built on. The first day is the work of building the diagram that the engineering team can review, the operations team can review, the security team can review, the business owner can review. The first day is the work of building the diagram that the threat model is shared on.

The first day is the work that is the most likely to be skipped. The first day is the work that is the most likely to be replaced by a generic threat model that the threat-modeller has used before. The first day is the work that is the most important to do properly.

The first day is the work that the threat model is built on. The first day is the work that the threat model depends on. The first day is the work that is the difference between a threat model that is useful and a threat model that is not.

The first week

The first week is the threat model. The first week is the work of identifying the threats. The first week is the work of identifying the threats to the components that the first day mapped. The first week is the work of identifying the threats to the data flows that the first day mapped. The first week is the work of identifying the threats to the trust boundaries that the first day mapped.

The first week is the work of using a methodology. The first week is the work of using STRIDE. The first week is the work of using PASTA. The first week is the work of using the methodology that the threat-modelling team is most comfortable with. The first week is the work of using the methodology that the engineering team is most comfortable with.

The first week is the work of producing the document. The first week is the work of producing the document that the threats are listed in. The first week is the work of producing the document that the threats are prioritised in. The first week is the work of producing the document that the threats are tracked in.

The first week is the work that is the most likely to be skipped. The first week is the work that is the most likely to be replaced by a one-page threat summary that the threat-modeller has written in an afternoon. The first week is the work that is the most important to do properly.

The first month

The first month is the validation. The first month is the work of validating the threat model. The first month is the work of validating the threat model against the actual environment. The first month is the work of validating the threat model against the actual threats that the environment is facing. The first month is the work of validating the threat model against the actual detections that the environment is firing.

The first month is the work that the threat model is updated. The first month is the work that the threat model is updated with the threats that were missed in the first week. The first month is the work that the threat model is updated with the detections that were not in the first week. The first month is the work that the threat model is updated with the controls that were not in the first week.

The first month is the work that is the most likely to be skipped. The first month is the work that is the most likely to be replaced by a one-time threat model that the threat-modeller has produced and then moved on. The first month is the work that is the most important to do properly.

The first quarter

The first quarter is the integration. The first quarter is the work of integrating the threat model into the engineering process. The first quarter is the work of integrating the threat model into the operations process. The first quarter is the work of integrating the threat model into the security process. The first quarter is the work of integrating the threat model into the decision-making.

The first quarter is the work of making the threat model a living document. The first quarter is the work of making the threat model a document that is updated when the system changes. The first quarter is the work of making the threat model a document that is consulted when the architecture changes. The first quarter is the work of making the threat model a document that is consulted when the controls are reviewed.

The first quarter is the work that the threat model becomes useful. The first quarter is the work that the threat model becomes a tool that the engineering team uses, the operations team uses, the security team uses. The first quarter is the work that the threat model becomes a tool that the leadership uses.

The honest answer

The honest answer is that the threat model is a work, not a document. The honest answer is that the threat model is the work that the threat-modelling team does over the first hour, the first day, the first week, the first month, the first quarter. The honest answer is that the threat model is the work that produces the document, not the work that is the document.

The honest answer is that the work is the most important part of the threat-modelling practice. The honest answer is that the work is the most under-resourced part of the threat-modelling practice. The honest answer is that the work is the most under-appreciated part of the threat-modelling practice.

The honest answer is that the threat-modelling practice is worth the money when the threat-modelling practice is the work. The honest answer is that the threat-modelling practice is not worth the money when the threat-modelling practice is the document.

If you are doing threat modelling, do the work. If you are doing threat modelling, do the work that is the first hour, the first day, the first week, the first month, the first quarter. If you are doing threat modelling, do the work that is the threat model.