NEW: English for Tech Bundle → Save 40%
Your progress

Loading your progress…

Home
Planning & Processnoun · /θret ˈmɒd.əl/

threat model

In simple English

A threat model is a cornerstone security practice in tech companies where teams systematically think through how an application could be compromised. Rather than building a system and then hoping it is secure, teams create a threat model early in the design phase to identify vulnerabilities proactively. This process typically involves mapping data flows, identifying entry points, and considering various attacker personas and their motivations. For example, a banking app team might create a threat model that considers how hackers could intercept login credentials, how insider threats might steal customer data, or how a man-in-the-middle attack could compromise transactions. The threat model becomes a living document referenced during design reviews, code reviews, and security audits. In many enterprises, threat modeling is mandatory before any system goes to production. Teams use frameworks like STRIDE or attack trees to structure their analysis, making it more thorough and systematic.

Understand how to identify and document potential security threats in software systems through structured analysis.

At a glanceCEFR C1
Commonness4/5
Versatility4/5
FormalityCasualFormalFormal
Spoken ↔ WrittenSpokenWrittenBoth
Directness ↔ DiplomaticDirectDiplomaticDirect
RegionUS and UK
New app · Free lessons

Speak up in meetings. Feel confident.

Standup vocabulary, native examples, and quick practice — 100+ free lessons

Start learning freeNo card needed · Google or email

Say it like this

Let us build a threat model for this feature.
We need to threat model this before we ship it.
The threat model shows several critical vulnerabilities.
Have you reviewed the threat model yet?

Real examples

in a standup

"I spent yesterday threat modeling our new user authentication service to identify potential attack vectors."

in a code review

"According to our threat model, this endpoint needs additional rate limiting to prevent brute force attacks."

in a team meeting

"The threat model revealed that we should encrypt sensitive data in transit, not just at rest."

in a security discussion

"Our threat model assumes an attacker has limited network access but full user-level permissions."

Don't say this

Handle with care. Often confused with risk assessment or penetration testing; a threat model is specifically a structured framework for identifying and analyzing potential security threats, not the actual testing itself.

We need to threat model this code right now before shipping.
We need to threat model this feature during the design phase before we begin coding.Threat modeling is most effective early in development, not at the last minute before release.
The threat model passed our security audit.
The results of our threat model informed our security improvements that passed the audit.A threat model does not pass or fail; it is an analysis document. The vulnerabilities it identifies are what teams address.
Our threat model found a hacker attacking the system.
Our threat model identified a potential attack vector that could be exploited.A threat model predicts possible attacks; it does not detect actual attacks in real time.
Threat modeling is only for security engineers.
Threat modeling should involve developers, architects, and security engineers together.Effective threat modeling requires diverse perspectives across teams to identify all potential weaknesses.

Other forms

noun

threat model

"Our threat model identifies SQL injection as a critical risk."

verb

threat model

"We will threat model the payment processing service next week."

noun

threat modeling

"Threat modeling early in development saves significant time and money later."

adjective

threat modeling

"The threat modeling session revealed several architectural flaws."

Often used with

threat modelused with build, create, develop, conduct, review, update
attack vectorcommonly discussed within a threat model analysis
data flowcentral element when creating a threat model diagram
STRIDE frameworka popular structured methodology used in threat modeling
vulnerabilitywhat a threat model identifies and documents
threat actorthe attacker persona considered in threat modeling

Similar words

security analysisbroader term; threat modeling is a specific, structured approach to security analysis
risk assessmentrelated but different; risk assessment evaluates business impact, while threat modeling identifies technical attack paths
attack treea diagram technique used within threat modeling to visualize attack paths
security design reviewoften incorporates threat modeling but may also address other security considerations

Opposites

assume security is built inskip security planningreactive security response

Practice

Try it

4 quick exercises

Pick the most natural phrasing

1. You are planning a new payment feature. What would you say in a meeting?

Complete the sentence

2. During the design phase, our team will _______ the entire API surface to identify potential security weaknesses.

Spot the mistake

3. Which sentence uses threat model incorrectly?

Rewrite naturally

4. Rewrite this in natural tech English using threat model: 'Before we build this feature, we need to look at all the ways bad people could attack it.'

Questions

Quick poll

Have you said "threat model" in a standup this week?

Want more structured practice like this? Our English for Programmers course covers real workplace English in depth.

Your badges