Skip to content

Glossary

Threat model

A written statement of what is being protected, from whom, and what has deliberately been left undefended.

In plain terms

Writing down what you are worried about before deciding what to do about it. The useful version is short and says who you think might cause a problem and what you have decided to live with, which is a very different document from a list of everything that could conceivably go wrong.

01

Why it matters

Because without one, security decisions get made against whichever risk was most recently discussed. A model gives a stable reference: this is what we hold, this is who might want it, and these are the things we have consciously accepted. Arguments about controls then become arguments about that shared picture rather than about who is most worried today.

02

How it works

It starts with what you hold rather than with what could go wrong. Threats are unbounded and assets are not, so beginning from the material and the systems keeps the exercise finite. An organisation that cannot list what it holds has found the first output rather than failed at the task.

Then it names who, and specificity is what makes it usable. An opportunist, a competitor, a departing employee and somebody who has already got in behave differently and are stopped by different things. A model that says an attacker without saying which is a model that cannot help choose between two controls.

The exclusions are the valuable part and the part usually left out. A document listing what you defend against reads as thorough and commits to nothing; one that also says what you have decided not to defend against is the one that settles arguments later, because somebody wrote down that the trade was deliberate.

It goes stale in a specific way: quietly and without any signal. Systems arrive, tools are adopted, people change roles, and the model still describes the organisation as it was. Nothing breaks, and the document keeps being cited, which is worse than not having one.

For AI tools the useful question is what the model did not anticipate. Most were written when material sat in known systems reached by known people, and a search deployment reaching across all of them, or an assistant holding text somebody pasted, is a shape the original picture did not include.

Two documents with the same title

Two documents with the same titleThe distinction matters because the left-hand version is what usually gets produced, and for understandable reasons: it is safer to write. A document that lists possibilities and recommends vigilance cannot be contradicted by events, and it passes any review that checks whether a threat model exists. The right-hand version takes positions, and positions can turn out to be wrong in public, which is precisely why it is worth something. When somebody later asks why a particular risk was not addressed, an organisation with the left-hand document has to reconstruct whether anybody thought about it, and one with the right-hand document can point at a line saying the trade was made deliberately and on what grounds. The AI-era test of either document is the same and unusually revealing: read it and ask whether the picture it describes still exists. Most were written when material sat in identifiable systems reached by identifiable people, and a tool that reads across all of them at once does not appear anywhere in that picture, which is not a flaw in the original work so much as evidence that the map is now older than the territory.The thorough oneLists many possible threats.Commits to nothing inparticular.Cited, rarely reread.The useful oneNames what is held and whowants it.States what is deliberatelyaccepted.Short enough to reread on adecision.The left-hand document survivesreview because nothing in it canbe shown to be wrong. Theright-hand one is the onlyversion that helps when twopeople disagree about whether acontrol is worth its friction.
The distinction matters because the left-hand version is what usually gets produced, and for understandable reasons: it is safer to write. A document that lists possibilities and recommends vigilance cannot be contradicted by events, and it passes any review that checks whether a threat model exists. The right-hand version takes positions, and positions can turn out to be wrong in public, which is precisely why it is worth something. When somebody later asks why a particular risk was not addressed, an organisation with the left-hand document has to reconstruct whether anybody thought about it, and one with the right-hand document can point at a line saying the trade was made deliberately and on what grounds. The AI-era test of either document is the same and unusually revealing: read it and ask whether the picture it describes still exists. Most were written when material sat in identifiable systems reached by identifiable people, and a tool that reads across all of them at once does not appear anywhere in that picture, which is not a flaw in the original work so much as evidence that the map is now older than the territory.
03

Seen in the wild

  • Asking what an assistant deployment changes about who can reach material, rather than only whether it is secure.

    ChatGPT
  • Revisiting a model after a search tool made everything reachable from one box.

    Glean
  • Naming an automation platform's stored credentials as an asset in their own right.

    Make
04

Common misconceptions

People assume

It is a list of threats.

In fact

The list is the least useful part, because threats are unbounded and everybody's list looks similar. What makes it worth having is the decisions attached: what is worth protecting, from whom specifically, and what has been consciously accepted.

People assume

It is a specialist exercise.

In fact

The hardest questions are about what the organisation holds and who would want it, and the people who know that are rarely the security team. A short model written by people who understand the business beats a thorough one written by people who understand the methods.

05

Questions

How long should one be?
Short enough that somebody rereads it when a decision comes up, which in practice means a page or two. A long document is written once and cited without being read, and a model nobody rereads has stopped doing the only job it had.
When is it worth revisiting?
When something changes what can reach what, rather than on a calendar. A new tool that spans systems previously separate is exactly that kind of change, and it is the sort that arrives without anybody thinking of it as a security event.
What do AI tools usually change about it?
They tend to collapse boundaries the original model assumed. A deployment that reads across systems removes the separation between them, and material pasted into an assistant leaves the systems the model was written about, so both the map and the perimeter it described have moved.
06

Key takeaways

  • Start from what you hold, because threats are unbounded and assets are not.
  • Naming who specifically is what lets it choose between controls.
  • The exclusions settle later arguments; the inclusions rarely do.
  • It goes stale silently, and keeps being cited while it does.
08

Tools that use this

  • ChatGPT

    What a deployment changes about who can reach material.

  • Glean

    Revisiting a model after search made everything reachable at once.

  • Make

    Stored credentials as an asset worth naming in their own right.

Last checked August 2026

All glossary terms