Glossary term

threat model

A structured analysis of how a system could be attacked, who might attack it, and what the impact would be. Teams use threat modeling to prioritize security investments before an incident rather than after. The output is usually a list of threat scenarios ranked by likelihood and impact.

conceptSecurity & ComplianceIntermediate

When you'd see it: Security architecture reviews, product launches, vendor assessments, penetration-test kickoffs.

Why it matters: Threat modeling shifts security from reactive to proactive. It tells you where to invest limited security budget before something goes wrong, rather than scrambling after a breach.

Common mistakes: Treating it as a one-time exercise done at launch rather than an ongoing practice updated when the system changes.

Study this in BizTech Primer →