By Dana Reyes
“Threat modeling” sounds like something for spies or security researchers, but the underlying idea is simple: you can’t protect everything from everyone, so figure out what actually matters to protect, from whom, and how much hassle you’re realistically willing to accept — then spend your effort there instead of everywhere at once.
The Five-Question Framework
The Electronic Frontier Foundation’s Surveillance Self-Defense guide frames this as five questions worth answering before you buy a single privacy tool:
- What do I want to protect? (your “assets” — could be your location history, your messages, your finances, your identity, or your physical safety.)
- Who do I want to protect it from? (your “adversaries” — an ex-partner, a data broker, your employer, an identity thief, or a government, and these have wildly different capabilities.)
- How likely is it that I’ll need to protect it?
- How bad are the consequences if I fail?
- How much trouble am I willing to go through to prevent those consequences?
The EFF’s own framing is worth keeping in mind here: a 70% solution you’ll actually stick with beats a 100% solution you abandon after two weeks.
Worked Examples by Persona
| Persona | Primary Adversary | Top Asset | Practical First Step |
|---|---|---|---|
| Everyday privacy-conscious user | Data brokers, ad-tech trackers | Browsing habits, location history | Browser tracker blocking + a reputable no-logs VPN on public Wi-Fi |
| Person leaving an abusive relationship | A specific individual with account or device access | Real-time location, message content | Full account-access audit (see our stalkerware-detection guide) before any other step |
| Small business owner | Competitors, credential-stuffing attackers | Client data, financial accounts | Hardware security keys on email and banking logins |
| Frequent traveler | Public Wi-Fi snoopers, device search at borders | Device contents, account sessions | Full-disk encryption + logging out of sensitive accounts before crossing a border |
Where People Get This Wrong
The most common mistake is adversary mismatch: buying tools built for nation-state-level threats (obscure operating systems, Tor for every task, burner everything) when the actual adversary is a data broker or an ex, or the opposite — assuming “I have nothing to hide” when the real adversary is a specific person with a specific reason to target you. Match the tool to the adversary, not to whichever tool is currently getting the most attention in privacy circles.
The second mistake is treating any single tool, including a VPN, as a complete plan. A VPN addresses one part of one threat model — it hides your traffic from your ISP and from snoopers on the same network — and does nothing for device-level compromise, phishing, or a weak reused password. It’s one line item in a plan, not the plan itself.
A Simple Way to Write Your Own Plan
Take fifteen minutes with a notes app and answer the five EFF questions honestly for your own situation. Then list the two or three tools or habits that actually address what you wrote down — not everything you’ve read about, just what maps to your actual assets and adversaries. Revisit it when your circumstances change (new job, new relationship status, new travel pattern), since threat models aren’t static.
Why a VPN Site Is Telling You to Think Beyond VPNs
It’s tempting for any privacy-focused site to pitch its core product as the answer to every concern, but that’s exactly the “single tool as complete plan” mistake described above. A reader whose actual adversary is an abusive ex needs account-access auditing and device checks first, not a VPN recommendation; a reader whose adversary is ad-tech tracking gets real value from a VPN plus tracker blocking; a reader crossing borders with sensitive work data needs full-disk encryption more than anything else. Recommending the same tool to all three would be bad advice dressed up as helpful advice.
FAQ
Do I need to do this formally, with documents and diagrams? No — for almost everyone this is a five-minute mental exercise, not a corporate risk-assessment document. The value is in asking the questions, not in the paperwork.
Is a VPN part of most people’s threat model? Usually yes, at least a small part — protecting traffic on public Wi-Fi and from ISP data collection is a common, low-effort, high-value line item for most personas above.
How often should I redo this? Whenever a major life circumstance changes — a new job with sensitive data, the end of a relationship, or a big travel pattern change are the usual triggers.
Verdict
Threat modeling isn’t a product you buy, it’s ten minutes of honest thinking that tells you which products are actually worth buying. Do the five-question exercise before you buy the next tool on your list, whether that’s a VPN, a password manager, or a hardware key — it’s the cheapest security investment you’ll make all year.
