Threat Modeling for Regular People: 7 Simple Steps to Feel Truly Secure

Last Update: Oct. 6, 2026

Digital minimalism and protecting your digital privacy go hand in hand. So many people are just focused on reducing their screen time when it comes to digital minimalism, that they forget that without digital privacy you are basically just leaving the door unlocked to your digital life. I want to help you protect your digital privacy using a concept called threat modeling.

OK, so I know this sounds like nerd jargon, but hear me out. Threat modeling is a concept that information security professionals use every day and it can just as easily apply to an enterprise network as your personal life. It’s just a matter of scale.

Let me start by telling you what it’s not. It’s not a gigantic list of tips and tricks for things that you can adjust in your life to make it more secure. I’ve been through those lists a million times over. Here are the common threads that I always found with them:

  • They offer advice that doesn’t apply to my life.
  • They offer configuration changes that if you don’t know exactly what you are doing can ruin the devices you are doing them on. I’ve seen multitudes of articles that have made recommendations that unless you are an advanced user will cause you to need to reset your phone from factory settings.
  • They remove actual useful functionality in the name of privacy when the benefits of keeping those settings often outweigh the negatives.

A lack of tools and configuration settings is definitely not the problem. The lack of knowing where to start is. So that brings us back to threat modeling. Threat modeling is quick, easy, and it can help you identify the things most likely to happen in your life while ignoring those things that are probably not worth your time.

For my part, I want to walk you through threat modeling in plain language. I make no assumptions that you know what any of these technical terms actually mean or know about the acronyms. I hate acronyms because there are so many of them in the IT world that they overlap and you end up with same acronym meaning different things.

If I do use an acronym, I promise I will explain what it is or at the very least link you out to a place that explains the concept. My goal is that you will have a short, personal list of of what to actually do rather than being left with this vague sense of dread about all the things you aren’t doing.

What Is Threat Modeling?

Four simple icons representing the core questions behind threat modeling

Threat modeling is very simple. It’s basically four simple questions that you are going to ask yourself:

  1. What do I want to protect?
  2. Who or what might try to get it, break it, or expose it?
  3. How likely is it to happen?
  4. What am I willing to do about it?

That’s all there is to it. This is about as simple as it gets and they are all questions you can answer without needing to be an expert in information security. As I said, my goal was to walk you through threat modeling in plain language. These four questions help you to break security into a short list of very specific, very manageable decisions.

So now that you know what it is, you’re probably asking ‘why should I care?’ I know that was the first question that my neighbor asked me when I was explaining it to him. His thoughts were ‘Security is security, so I want to be as secure as possible. Why should I bother with this?’

I can totally see that point of view. I disagree with it, but I understand it. The easiest way to understand why this is important is to imagine two different people:

We have Robert, he is a 43 year old office worker with a 14 year old daughter and he’s worried about her photos ending up somewhere they shouldn’t. Then we have Emily who is a 28 year old school teacher with an abusive ex-boyfriend who is stalking her.

Now if you give Robert the advice to turn off location sharing on his phone, that isn’t going to do anything to help alleviate the risk of his daughter’s photos ending up somewhere where they shouldn’t. If you give that same advice to Emily, it’s going to make it potentially far more difficult for her ex to stalk her.

This is why I don’t like providing just generic one size fits all advice for information security. As you can see from these two people I just outlined above, you need specific and actionable steps to secure your privacy. Threat modeling accounts for this.

The Seven Steps of Threat Modeling

Now I know I said it’s basically four questions, but in reality it’s seven steps. I know, nothing is as easy as it sounds right? Don’t worry, none of the steps are particularly difficult.

Step 1: Identify what you are actually protecting

Icons representing the personal assets people protect in a security plan

Before you can secure anything, you have to know what you are actually protecting. This is just going to be a simple list of what matters to you. It’s important to not overthink this. I recommend just grabbing a blank piece of paper or opening your word processor on your computer and starting to write down your actual assets.

In this context, actual assets are things that it would genuinely hurt to lose, expose, or have someone else control. For most people, it’s going to be some combination of the following:

  • Financial accounts and access (Bank accounts, credit cards, retirement accounts)
  • Personal photos and family memories.
  • Your identity (Social security number, ID documents)
  • Your location and daily routine
  • Communication with family, friends, or coworkers
  • Work accounts and sensitive material tied to your job
  • Physical devices (laptop, phone, home servers)

One thing you’ll notice about this list is that it’s very specific. There is nothing abstract on here because abstract is incredibly difficult to defend. “My privacy” is very vague and really can’t be defended. On the flip side, ‘my location when I travel to and from work’ is something that is very specific and you can build a plan around it. If you want to be successful at threat modeling, you need to start with concrete nouns and not feelings.

Step 2: Identify who or what you’re protecting it from

Diagram showing different threat sources at varying distances from a home

It’s great to know what you are protecting, but who or what you are protecting it from is just as important. Not all risks come from the same source and generic defense do little to actually protect you. You need to identify specifics about who you are worried about in order to protect against them. Most people don’t have to worry about ‘hackers’.

So who should you be thinking of when you are identifying the who and what? Here are some common ones:

  • Opportunistic criminals. For this think of those spam emails that you get every day. The ones where they are clearly phishing, looking to steal your data. Or the spam calls you get where people are trying to convince you to give them your personal data. These get run against millions of accounts and people every day. You aren’t a specific target, just an easy one because you appear on some list somewhere.
  • People you know. Sadly this is more common than it should be. This could be an ex, an estranged family member, or even a nosy roommate who has physical access to your devices and possibly knows your passwords.
  • Data brokers and advertisers. These people aren’t trying to hack you, they are trying to build a profile on you and everything you click, buy, and search. Amazon, Facebook (Meta), and Google are notorious for this.
  • Your own mistakes. We are guilty of this. This could be things like losing a phone, reusing a password, or clicking a fake email. After data brokers and advertisers, this is going to be the biggest threat that most people are likely to face.

Let’s go back to my neighbor who spent the better part of an hour the other night picking my brain about information security and protecting himself online, which became of particular concern to him after reading some article that came across his Facebook feed a few days earlier. He was looking at some kind of a security key that advertisers decided that he needed after he started searching online for securing his privacy online.

I didn’t look too closely at whatever that device that he was looking at was because it was expensive and probably overkill for whatever he was trying to do. Instead I asked ‘Are you reusing the same passwords across multiple accounts and are you using a password manager?’ The answers were ‘Yes’ to the first question and ‘No’ to the second.

So I bring this up because that device he was looking at didn’t mention password security at all. He was about to spend quite a bit of money on something that wasn’t going to address his actual issue, which is that he’s been reusing the same password for over a decade and it’s not stored securely. I guarantee that password is in some kind of data breach and this device would do absolutely nothing about that.

Step 3: Assess How Likely Each Threat Is

For each item on your list, you want to honestly assess the question: How likely is this to happen to me specifically?

Note the question isn’t: Could this happen to me? Well yes, of course it could happen to you. I could get eaten by a shark but I stay away from boats and I try to stay out of the ocean, so the the probability isn’t that great. So it’s better to question whether or not it’s probable in your actual life.

Someone who runs a business is going to have a very different likelihood profile than a retired teacher in the country. A person going through a very contentious divorce is going to face a set of threats that looks very different from someone in a stable, low-conflict household.

It’s important to be honest here because if you overestimate your risk, then you waste time and energy on defenses you don’t need and will eventually abandon. If you underestimate  then you leave actual gaps.

Make sure you keep this simple! Listen, I love spreadsheets. It’s what I’m known for. So listen to me when I say, you don’t need a spreadsheet with probably percentages for this. In fact, I’d recommend going with a simple scale of ‘High, Medium, Low’. As long as it’s grounded in the reality of your actual circumstances rather than whatever headline came across your news feed last week, you’ll be fine.

Step 4: Weigh the Impact If It Happens

Grid illustrating how likelihood and impact are weighed against each other

Just assessing the likelihood isn’t going to give you a full picture. In the enterprise world, the next step is called ‘Impact analysis’. Sounds scary and complex right? It’s not.

You just multiply the likelihood by impact, which I know without further context sounds confusing, but hear me out. The basic idea is the that something rare but catastrophic may deserve more attention than something that is common but minor.

Let’s see how this plays out in the real world. We are going to ask the question of: If this actually happened, how bad would it be?

Let’s say that you’ve got an account on Tumblr that you haven’t logged into for 8 months. You realize someone hacked it because it used a password that had been in a data breach and you’ve lost access to it. So the likelihood of this is pretty common, but your impact is going to be pretty low. Let’s face it, you haven’t used the account in 8 months. It’s probably not a huge deal.

OK, now lets say that you’ve suddenly lost access to your primary email account that is tied to your bank account and basically everything account that you own so that when password resets happen, they go through that account.

If you’ve got common security procedures like multi-factor authentication setup and you’ve got a unique password stored in a password manager, this should be very rare, but if it does happen it’s going to be a five-alarm fire in your world.

Both of these things are account compromise, but they don’t require the same amount of your attention or effort.

Step 5: Match Your Defenses to the Actual Risk

Alright, now for the fun part! We get to start picking tools and habits. Now the reason why we waited for Step 5 on this one is because if you go straight to picking tools you end up buying or collecting tools and software you don’t need.

Remember, a VPN is useless if what you really need is a password manager. Also, if you’re thinking ‘Wow, this guy brings up password managers a lot!’ You aren’t imagining things. A good password manager has saved me a lot of headaches in life and would have saved me a ton of headache for people I’ve worked with. I’m a big advocate.

Also, if you have no idea what a VPN is, it’s basically a tool that puts your internet traffic inside an armored car so nobody can see what is inside or where it came from.

For most people, the following list is going to address the highest-likelihood, highest-impact threats:

  • A password manager with unique passwords for every account (There he goes again with the password managers!)
  • Multi-factor authentication on email, banking, and anything tied to account recovery. Now notice I call it multi-factor authentication or MFA. You’ll also commonly see two-factor authentication. Just note that all two-factor authentication is multi-factor authentication but not all multi-factor authentication is two-factor authentication. The difference is that two-factor authentication requires exactly two methods of authentication while MFA requires two or more. (Cue ‘The More You Know’ Rainbow)
  • Regular software and application updates. Most breaches exploit known, unpatched vulnerabilities, so keeping your software and apps up to date goes a long ways towards protecting yourself.
  • Reviewing application permissions. Things like location access on your phone can be especially risky.
  • A basic understanding of phishing red flags. Human error is the number one entry point for real-world attacks.

As you are going through this list, one thing that should stand out to you is that all of this is very easy to implement. None of this requires exotic hardware or a degree in information security. It’s all stuff that is readily available to you on your existing devices and most of your existing services.

When doing threat modeling, the goal isn’t to make you paranoid. The goal is to make sure that the effort you put in actually does something to fix the real risks in your life rather than just addressing risks that don’t apply to you but you are aware of because of some Instagram reel.

If you want a deeper walkthrough of specific protective steps once you know your priorities, a free step-by-step guide from the Electronic Frontier Foundation covers most common scenarios in detail, and government guidance on protecting yourself online is a solid, non-commercial second opinion.

Step 6: Write it Down

OK, now those who know me are going to accuse me of writing this step in because I love documentation. That’s not why I included that step though. Think about the effort that you put into this. Just by thinking about threat modeling, you are already significantly ahead of most people on the Internet. Look at you go!

With that said, a threat model that only lives in your head is a threat model that gets forgotten the moment life gets too busy. This is where my love of spreadsheets comes out. Put it a spreadsheet, (Excel, Numbers, Google Docs) with the following columns:

  • Asset
  • Threat
  • Likelihood
  • Impact
  • Actions Taken (List one or two actions you plan to or have taken in this column)

This is about as simple as spreadsheets get and proof that it doesn’t need to be fancy to be effective.

Writing it down does two things. First, it forces all that vague anxiety in your head to become a concrete and finite list. This is really important because if you are like me, I tend to forget things very rapidly. Hence why I love documentation. Fun fact, young kids will turn your brain to mush as you get asked for the 7th time that day ‘Daddy, why are houses attached to the ground?’

The second thing it does is give you something to revisit. This means that you have something to reference instead of starting the whole mental exercise from scratch every time a scary headline shows up in your feed.

Step 7: Revisit and Adjust as Life Changes

For as simple as it is, threat modeling is not a one time thing. Your risks change when your life changes. A new jobs with access to different material can change your work related risk. Your kids getting old enough to have their own devices can change your family risk. This was a big one for me recently as I got to learn how to lock down a tablet.

Other things that can change the risks in your life are things like moving, starting or ending a relationship, or changing to work from home.

The easiest thing to do is just set a recurring reminder every 6 months to reread your list and ask whether it still reflects your actual life. The reassessment should only take a few minutes but it will keep your defenses aligned with reality rather than frozen in time at whatever the circumstances were the day you first wrote it down.

Threat Modeling: A Real World Example

A family's home network protected as part of a personal security plan

Now that I’ve gone through the seven steps with you and your head hurts, lets pull this out of the abstract. I’m going to provide you with a real world example. Now keep in mind I’m simplifying this a bit for the sake of brevity.

Imagine you are a parent with two young kids. You work a hybrid job and you’ve recently decided it would be fun to self-host your own family photo backups instead of relying entirely on the cloud provider. So, let’s run through the steps!

  1. Assets – Your assets are going to be your family photos, your work laptop with its VPN access, your kid’s school portal login, and your home network.
  2. Threats – Your most likely threats are going to be a phishing email targeting your work credentials, a reused password showing up in a breach, someone on your home network snooping if you forgot to change your Wi-Fi off the default settings, or a device loss.
  3. Likelihood and Impact – The Phishing and reused password risks are both high likelihood and high impact. This is because your email touches a lot of things and if you reused a password that was in a breach, then someone could potentially cause a lot of damage to you, the company you work for, or both. The Wi-Fi snooping is lower likelihood, but it’s an quick fix worth doing. Device loss is medium likelihood (unless you are my nephew), the impact of that is going to depend entirely on whether your devices are encrypted and how frequently your device is backed up.
  4. Defenses – Setting up unique passwords through a password manager will go a long ways to alleviate these threats. Using multi-factor authentic your email and work VPN will reduce the risk from phishing attacks. A renamed Wi-FI network with WPA3 and a strong passphrase will fix the Wi-Fi snooping issue….just make sure you warn your significant other before you do this. As a hard lesson learned, there is hell to pay when the Internet suddenly disappears. Finally, full-disk encryption on your laptop and phone as well as regular backups can make the impact of device loss significantly lower.

Notice that in this real world scenario of threat modeling, you didn’t need to go out and buy a firewall or some security appliance? It only included things that actually address the household’s top risks. That is threat modeling working exactly as intended.

Common Mistakes in Threat Modeling

There are a few patterns that come up again and again when people first attempt threat modeling. Don’t worry if you find that this happens to you, it’s all part of the learning process.

  • Copying someone else’s threat model – The threat models of a suburban parent vs that of a journalist working out in the field in a war zone are going to look very different. Build your list from your own life.
  • Treating every risk as equally urgent – Not everything deserves the same level of response. A breach of an unused Tumblr account is not the same as a breach of your bank account. This is why we weigh the likelihood against impact.
  • Buying tools before identifying threats – Those advertisements are designed to make you think you need those tools. Don’t give in. If you buy tools before you identify the threat, you end up with a drawer of unused security gadgets and generally the same reused password on your email account.
  • Never revisiting the list – Your life changes. Your threat model should change with it.

Bringing It All Together

Threat modeling isn’t about becoming paranoid and anxious. Goodness knows we have enough things in our life to cover those two categories without adding yet another thing onto the pile.

Instead it’s about replacing that vague, exhausting anxiety with a short, honest, and personal list of what actually matters and what you plan to do about it. You can accomplish far more with twenty minutes and a notebook than you will ever achieve spending doom-scrolling security horror stories.

Start today. Write down three things you’d genuinely hate to lose. Think honestly about who or what threatens them, and then pick one small action for each. That is threat modeling in practice and it’s a habit worth keeping. If you want to go more in depth on personal security, I’ve put together an entire article on how to perform a personal security audit.

Leave a Comment