Skip to content Skip to sidebar Skip to footer

Threat Modeling for Regular People

By Dana Reyes

“Threat modeling” sounds like something for spies or security researchers, but the underlying idea is simple: you can’t protect everything from everyone, so figure out what actually matters to protect, from whom, and how much hassle you’re realistically willing to accept — then spend your effort there instead of everywhere at once.

The Five-Question Framework

The Electronic Frontier Foundation’s Surveillance Self-Defense guide frames this as five questions worth answering before you buy a single privacy tool:

  1. What do I want to protect? (your “assets” — could be your location history, your messages, your finances, your identity, or your physical safety.)
  2. Who do I want to protect it from? (your “adversaries” — an ex-partner, a data broker, your employer, an identity thief, or a government, and these have wildly different capabilities.)
  3. How likely is it that I’ll need to protect it?
  4. How bad are the consequences if I fail?
  5. How much trouble am I willing to go through to prevent those consequences?

The EFF’s own framing is worth keeping in mind here: a 70% solution you’ll actually stick with beats a 100% solution you abandon after two weeks.

Worked Examples by Persona

Persona Primary Adversary Top Asset Practical First Step
Everyday privacy-conscious user Data brokers, ad-tech trackers Browsing habits, location history Browser tracker blocking + a reputable no-logs VPN on public Wi-Fi
Person leaving an abusive relationship A specific individual with account or device access Real-time location, message content Full account-access audit (see our stalkerware-detection guide) before any other step
Small business owner Competitors, credential-stuffing attackers Client data, financial accounts Hardware security keys on email and banking logins
Frequent traveler Public Wi-Fi snoopers, device search at borders Device contents, account sessions Full-disk encryption + logging out of sensitive accounts before crossing a border

Where People Get This Wrong

The most common mistake is adversary mismatch: buying tools built for nation-state-level threats (obscure operating systems, Tor for every task, burner everything) when the actual adversary is a data broker or an ex, or the opposite — assuming “I have nothing to hide” when the real adversary is a specific person with a specific reason to target you. Match the tool to the adversary, not to whichever tool is currently getting the most attention in privacy circles.

The second mistake is treating any single tool, including a VPN, as a complete plan. A VPN addresses one part of one threat model — it hides your traffic from your ISP and from snoopers on the same network — and does nothing for device-level compromise, phishing, or a weak reused password. It’s one line item in a plan, not the plan itself.

A Simple Way to Write Your Own Plan

Take fifteen minutes with a notes app and answer the five EFF questions honestly for your own situation. Then list the two or three tools or habits that actually address what you wrote down — not everything you’ve read about, just what maps to your actual assets and adversaries. Revisit it when your circumstances change (new job, new relationship status, new travel pattern), since threat models aren’t static.

Why a VPN Site Is Telling You to Think Beyond VPNs

It’s tempting for any privacy-focused site to pitch its core product as the answer to every concern, but that’s exactly the “single tool as complete plan” mistake described above. A reader whose actual adversary is an abusive ex needs account-access auditing and device checks first, not a VPN recommendation; a reader whose adversary is ad-tech tracking gets real value from a VPN plus tracker blocking; a reader crossing borders with sensitive work data needs full-disk encryption more than anything else. Recommending the same tool to all three would be bad advice dressed up as helpful advice.

FAQ

Do I need to do this formally, with documents and diagrams? No — for almost everyone this is a five-minute mental exercise, not a corporate risk-assessment document. The value is in asking the questions, not in the paperwork.

Is a VPN part of most people’s threat model? Usually yes, at least a small part — protecting traffic on public Wi-Fi and from ISP data collection is a common, low-effort, high-value line item for most personas above.

How often should I redo this? Whenever a major life circumstance changes — a new job with sensitive data, the end of a relationship, or a big travel pattern change are the usual triggers.

Verdict

Threat modeling isn’t a product you buy, it’s ten minutes of honest thinking that tells you which products are actually worth buying. Do the five-question exercise before you buy the next tool on your list, whether that’s a VPN, a password manager, or a hardware key — it’s the cheapest security investment you’ll make all year.