Security advice often begins at the wrong end. It starts with a product—VPN, encrypted drive, hardware key, identity monitor—and works backward to a fear. Threat modeling reverses the order. What are you protecting? From which plausible failure or adversary? What would the consequence be? Which control changes that path?

You do not need to imagine an intelligence agency to benefit. For most people, lost phones, reused passwords, phishing, account recovery failures, exposed personal data and unpatched software matter more than exotic attacks. A useful model reflects your life rather than the internet's loudest nightmare.

The operating ruleProtect the most consequential, plausible paths first. A modest control you can maintain is better than an elaborate system you abandon or cannot recover.

What threat modeling means here

The Electronic Frontier Foundation calls this security planning: deciding what you want to protect and from whom. NIST's formal risk-assessment guidance is written for organizations, but its underlying structure is useful at home—identify threats, vulnerabilities, likelihood and impact, then decide what to do about the risk.

This guide adapts that logic for ordinary personal systems. It is not a substitute for professional help in cases involving stalking, domestic abuse, journalism under repression, active legal threats, regulated data or targeted harassment. Those situations change the adversary, consequence and safe sequence of action.

A person at a home desk inventorying a laptop, phone, external drive, keys and paper records
Begin with the real things and accounts in your life. Security planning is an inventory and recovery exercise before it is a shopping exercise.

The forty-five-minute worksheet

Use one sheet of paper. Set a timer. You are producing a first defensible model, not a complete catalog of every conceivable danger.

1. Name the assets

List what would cause genuine harm if lost, exposed, altered or made unavailable. Common examples include primary email, phone number, password vault, financial accounts, tax documents, family photos, work files, medical information, home address, identity documents and the ability to contact family.

Separate the data from the service holding it. “Family photos” are an asset; the phone, cloud library and backup drive are locations. “Primary email” is both information and a control plane because it can reset many other accounts.

2. Name the failure, not just the villain

Write how each important asset could be harmed. A phone can be stolen, smashed or locked after too many failed attempts. An account can be phished, taken over through a reused password, lost when a number changes or made inaccessible when the only authenticator is on the missing phone.

Many failures have no attacker. Hardware dies. A subscription lapses. A partner does not know where the recovery codes are. Threat modeling that considers only malicious people misses ordinary fragility.

3. Identify likely actors and access paths

“Hackers” is too vague. Distinguish opportunistic credential thieves, a scammer who can call your carrier, an acquaintance with physical access, a data broker, a curious child, an employer or service provider, and a determined person who knows you. Then identify the path: email attachment, password reset, unlocked device, shared cloud folder, public record or discarded paper.

Do not assign equal probability to each. EFF emphasizes that risk is personal and subjective. A public figure, survivor, activist and person managing a quiet household have different credible threats even when they use the same phone.

4. Rate likelihood and consequence separately

Use simple labels—low, medium, high—and add one sentence of evidence. “Phishing against primary email: medium likelihood because attempts arrive weekly; high consequence because it resets financial and social accounts.” Avoid multiplying invented numbers into fake precision.

High consequence and low likelihood may still deserve a cheap safeguard. A printed recovery code in a secure place costs little. High likelihood and low consequence may deserve tolerance rather than a complicated tool.

5. Record the controls already working

Inventory before buying: unique passwords, multifactor authentication, automatic updates, device encryption, screen locks, cloud backup, offline backup, account alerts, recovery contacts and household instructions. Confirm each control rather than assuming it exists.

The Cybersecurity and Infrastructure Security Agency's Secure Our World program emphasizes four broadly useful actions: recognize phishing, use strong passwords and a password manager, turn on multifactor authentication and update software. They are not a complete threat model, but they cover common attack paths.

6. Choose the smallest next defense

For each high-priority path, choose one control that reduces likelihood, consequence or recovery time. Use app-based or phishing-resistant multifactor authentication on primary email. Remove an old recovery number. Encrypt the laptop. Give a trusted adult sealed recovery instructions. Move irreplaceable photos into a second independent backup.

A purchase is justified only if it closes the named path better than configuration, deletion, a process or a backup. A hardware key can be excellent for a high-value account; it can also create lockout if you buy one key, lose it and never configure recovery.

7. Prove recovery

A backup you have never restored is a hope. A recovery email you cannot access is decoration. Test one safe recovery path: restore a noncritical file, sign in using a backup authenticator, confirm recovery codes exist or walk another adult through the location of emergency instructions.

Do not trigger account-recovery processes casually on systems that might lock you out. Use provider documentation and test only where the procedure is understood.

8. Set a review trigger

Review after moving, changing phone numbers, starting a sensitive job, separating from a partner, receiving a targeted threat, adding a child account or adopting a new password system. Otherwise, six months is a reasonable reminder. Continuous anxiety is not maintenance.

A worked ordinary-person model

Asset: primary email. Plausible paths: phishing, reused password, stolen unlocked phone and failed recovery. Consequence: high, because the inbox can reset other accounts. Existing controls: unique password and phone-based authentication. Gaps: recovery codes exist only on the phone; old phone number remains attached.

Smallest next steps: remove the old number, save codes in a secure offline location, add a second authenticator or backup key and confirm the account's recovery information. Notice what did not enter the plan: a new VPN, antivirus subscription or anonymous email service. Those tools do not solve this named failure path.

Threat modeling for a household

A family model includes coordination. Who can reach school, insurance and medical information if one parent's phone is unavailable? Which accounts are individual, shared or recoverable by another adult? Are children's photos public by default? Can a child approve purchases or reveal a lock-screen code?

Create a one-page continuity note with emergency contacts, key providers, the existence—not the secret contents—of the password manager, and instructions for accessing critical records. Store it appropriately. Avoid building a shared spreadsheet full of passwords as a shortcut.

Controls that often arrive before the problem

  • A VPN: useful for specific network or location needs, but it does not fix weak passwords, phishing or compromised endpoints.
  • Identity monitoring: may provide alerts or recovery services, but cannot prevent all misuse and may require sharing more personal data.
  • Encrypted cloud storage: changes who can read stored content, but recovery and sharing can become harder.
  • Hardware security keys: strong authentication for compatible accounts, but require spares, enrollment and a recovery plan.
  • Privacy browsers and DNS: useful layers for particular tracking or resolver concerns, not a blanket defense against account takeover.

Use the site's guides to examine a control only after the model names its job: password managers, security keys, encrypted storage and private DNS.

When ordinary advice is not enough

If the threat includes an abusive partner or stalker, changing settings can alert the person and increase danger. Use a safer device and contact a specialist organization before making visible changes. Journalists, activists and people handling regulated information should use security guidance designed for their jurisdiction, organization and adversary. If an account or device appears actively compromised, preserve evidence and seek qualified incident-response or legal help rather than improvising.

Authoritative sources

This guide provides general educational information, not individualized security, legal or safety advice.


END OF FIELD GUIDE 030

Keep the question. Test the model.

Choose the narrowest claim the evidence can carry, then leave room for revision.