Bringing it together¶
Link personas, attack paths, and impacts.
Goal¶
Move from isolated exercises to a living threat model your organisation can update and revisit.
Exercise instructions¶
Combine your adversary personas with mapped attack paths.
Add the operational impacts for each path.
Prioritise: which risks are unacceptable, which can be tolerated?
Decide on next steps: mitigations, monitoring, or simply awareness.
Result¶
A threat model that reflects real risks, grounded in team discussion, and ready to guide future decisions.