Weekly project: threat-model something you own

Project

~150 min

The task

Produce a short threat model of a real system you personally use and are responsible for. Not a company system, not a hypothetical — something yours: your phone, your laptop, your email account, or a small business you help run.

This is the week's assessed work. It should take two to three hours of real thought, and it should be written for a reader who is not you.

What to hand in

A document of roughly 800–1,200 words, in six sections.

1. What the system is

Describe it plainly, in a paragraph. What is it, who uses it, and what would be genuinely lost if it went wrong? Write for someone who has never seen it.

2. What is actually valuable

List the three to five things worth protecting. Be specific: not "my data", but "seven years of family photographs, none of them backed up anywhere else" or "the WhatsApp account my customers use to place orders".

For each, note whether the value is confidentiality, integrity, availability, or a mix — and rank the three properties for the system as a whole, with one sentence justifying the ranking.

3. Who would attack it, and why

Two or three realistic attackers, using the categories from this week — opportunistic criminal, targeted criminal, insider, hacktivist, state actor.

Be honest about realism. A state actor is almost certainly not coming for your phone. Explain what each one would want and how hard they would work to get it.

4. How they would get in

For each attacker, describe the route you think they would actually take. Use the attack chain: how would they learn about you, get their first foothold, and reach the valuable thing?

You do not need technical depth you do not have yet. "Guess or reuse my password because I use the same one in three places" is an excellent answer, and a more honest one than something copied from an article.

5. Would you notice?

This is the most important section, and the one that will be marked hardest.

For each attack route, answer three things:

  • What evidence would exist that it happened?
  • Where would that evidence live?
  • How long would it realistically take you to notice — honestly?

If the answer is "I would not notice, ever", write that. It is the correct answer for most personal systems and recognising it is the point of the exercise.

6. The three things you will actually do

Not a wishlist. Three specific changes you will genuinely make this week, each with a sentence on which risk it addresses and what it costs you in convenience.

Then — and this is part of the mark — do at least one of them before you submit, and say which one you did.

How this is marked

WeightWhat is being assessed
30%Honesty and realism — a model claiming state actors want your Instagram scores badly; one admitting you would never notice a breach scores well
25%Section 5. Detection is the theme of this course and this is where you show you understood it
20%Specificity. "Improve security" is worth nothing; "turn on two-factor for the email that can reset every other password" is worth a lot
15%Correct, sensible use of the CIA triad and the attacker categories
10%Clear writing for a non-expert reader

Notes

  • Do not attack anything to research this. Not even your own account, this week. This is a thinking exercise, and the lab is where hands-on work belongs.
  • Writing about security is most of the job. Reports are how findings become decisions, and a finding nobody acts on may as well not exist. Your writing is assessed all term.
  • Keep this document. In Week 12 you will revisit it and mark up everything you now know that you did not know today.

Submit

Push it to your course repository as week-01-threat-model.md, or hand in the file however your instructor has asked. Submit the link on this lesson.

Sign in to submit your work.