The task
Produce a short threat model of a real system you personally use and are responsible for. Not a company system, not a hypothetical — something yours: your phone, your laptop, your email account, or a small business you help run.
This is the week's assessed work. It should take two to three hours of real thought, and it should be written for a reader who is not you.
What to hand in
A document of roughly 800–1,200 words, in six sections.
1. What the system is
Describe it plainly, in a paragraph. What is it, who uses it, and what would be genuinely lost if it went wrong? Write for someone who has never seen it.
2. What is actually valuable
List the three to five things worth protecting. Be specific: not "my data", but "seven years of family photographs, none of them backed up anywhere else" or "the WhatsApp account my customers use to place orders".
For each, note whether the value is confidentiality, integrity, availability, or a mix — and rank the three properties for the system as a whole, with one sentence justifying the ranking.
3. Who would attack it, and why
Two or three realistic attackers, using the categories from this week — opportunistic criminal, targeted criminal, insider, hacktivist, state actor.
Be honest about realism. A state actor is almost certainly not coming for your phone. Explain what each one would want and how hard they would work to get it.
4. How they would get in
For each attacker, describe the route you think they would actually take. Use the attack chain: how would they learn about you, get their first foothold, and reach the valuable thing?
You do not need technical depth you do not have yet. "Guess or reuse my password because I use the same one in three places" is an excellent answer, and a more honest one than something copied from an article.
5. Would you notice?
This is the most important section, and the one that will be marked hardest.
For each attack route, answer three things:
- What evidence would exist that it happened?
- Where would that evidence live?
- How long would it realistically take you to notice — honestly?
If the answer is "I would not notice, ever", write that. It is the correct answer for most personal systems and recognising it is the point of the exercise.
6. The three things you will actually do
Not a wishlist. Three specific changes you will genuinely make this week, each with a sentence on which risk it addresses and what it costs you in convenience.
Then — and this is part of the mark — do at least one of them before you submit, and say which one you did.
How this is marked
| Weight | What is being assessed |
|---|---|
| 30% | Honesty and realism — a model claiming state actors want your Instagram scores badly; one admitting you would never notice a breach scores well |
| 25% | Section 5. Detection is the theme of this course and this is where you show you understood it |
| 20% | Specificity. "Improve security" is worth nothing; "turn on two-factor for the email that can reset every other password" is worth a lot |
| 15% | Correct, sensible use of the CIA triad and the attacker categories |
| 10% | Clear writing for a non-expert reader |
Notes
- Do not attack anything to research this. Not even your own account, this week. This is a thinking exercise, and the lab is where hands-on work belongs.
- Writing about security is most of the job. Reports are how findings become decisions, and a finding nobody acts on may as well not exist. Your writing is assessed all term.
- Keep this document. In Week 12 you will revisit it and mark up everything you now know that you did not know today.
Submit
Push it to your course repository as week-01-threat-model.md, or hand in the file however your instructor has asked. Submit the link on this lesson.