The threat model, on its own.
A structured threat model of a system or architecture without the full scoring exercise. It fits design reviews and architecture decisions, and it feeds a complete assessment later without rework.
Every component in scope is taken through all six, then the credible threats are mapped to MITRE ATT&CK techniques.
What triggers this engagement.
A system is being designed or re-architected, and you want the threats understood before anything is built rather than after.
Where the boundary sits.
A scope that is not written down is a scope that grows. Ours is agreed before work starts and it is printed in the report.
- Decomposition of the system into components and trust boundaries
- STRIDE applied to every component in scope
- Credible threats mapped to MITRE ATT&CK techniques
- Design-level mitigations tied to each modelled threat
- Likelihood and impact scoring, which belongs to a full assessment
- A residual risk position
- Testing of the built system
- Architecture documentation or a whiteboard session with the designers
- Access to the engineers making the design decisions
- The stage the design is at, honestly stated
Shorter than a full assessment, and set by how many components sit inside the boundary.
What you receive.
One document, layered so that a board and an engineering team can both work from it.
Is this the right scope for you?
Tell us the decision you are facing. If a different engagement fits better, we will say so before you commit to this one.