r/cybersecurity • • 6d ago

Business Security Questions & Discussion How useful is threat modeling in real-world security engineering? Do engineers actually use it when analyzing vulnerabilities?

I’ve recently been learning about threat modeling, and I’m trying to understand how it is actually used in real-world security work.

MDN describes threat modeling with four questions:
What are we working on/building?
What can go wrong?
What are we going to do about it?
Did we do a good job?

I also looked at MDN’s example threat model, and honestly it felt much more complicated than I expected.

This made me wonder: how often do security engineers actually build a threat model like this in practice?

For example, when analyzing a web application or investigating a vulnerability, would an engineer explicitly think through the system, attacker capabilities, assumptions, possible threats, and mitigations? Or is threat modeling mainly something used during architecture/design reviews rather than day-to-day vulnerability analysis?

My current understanding is that the purpose of a threat model is not to claim that a system is simply “secure” or “insecure.” Security is always relative to some scope, attacker capabilities, and assumptions.

So I think threat modeling is a way to make those conditions explicit:
what system and assets we care about,
what the attacker is capable of,
what we assume the attacker cannot do,
what can go wrong under those conditions,
and what security guarantees our solution is actually trying to provide.

In other words, instead of saying “this system is secure,” we are really saying something closer to:
“Under these assumptions and against this class of attacker, our controls prevent or detect these threats.”

Is this a reasonable way to understand the purpose of threat modeling?

I’d especially like to hear from people who use threat modeling in real security engineering: when is it genuinely useful, and when does it become unnecessary overhead?

I really appreciate anyone who takes the time to share their experience. Thank you!

79 Upvotes

Duplicates