
Security isn’t a product you buy. It’s a practice you live. For those of us who care about open societies, that practice starts with a clear-eyed look at what we’re protecting, from whom, and why. A personal threat model isn’t a paranoid checklist. It’s a structured way to make smart decisions about your time, your resources, and your peace of mind. Without one, you’re either securing nothing or trying to secure everything—and both roads lead to trouble. This guide walks you through building a threat model that fits your life, your work, and the democratic values you want to defend.
What Is a Personal Threat Model?
A personal threat model is a framework that helps you figure out what you need to protect, who might want to compromise it, and how they could pull it off. It’s the foundation of operational security (OPSEC) for individuals, not just intelligence agencies. The core pieces are simple: assets, adversaries, capabilities, and consequences. When you map these out, you trade a vague sense of anxiety for a clear set of priorities. You stop worrying about every possible hack and start focusing on the risks that actually touch your life.
For people working in open societies—journalists, activists, lawyers, or engaged citizens—the threat landscape is its own beast. You’re not hiding from a totalitarian state, but you might be targeted by harassment campaigns, doxxing, corporate surveillance, or legal intimidation. Your threat model has to reflect the reality that you operate in a space where transparency and privacy need to coexist. The goal isn’t to become invisible; it’s to control the flow of information so you can keep doing your work safely.
Step 1: Define What You’re Protecting
Start with your assets. These aren’t just devices or accounts; they’re the things that, if lost or exposed, would cause you real harm. Common assets for people in open societies include:
- Personal safety: Your physical location, routines, and the safety of your family.
- Confidential communications: The content of messages with sources, clients, or loved ones.
- Professional integrity: Your reputation, your ability to publish without interference, or your standing in a community.
- Digital accounts: Email, social media, cloud storage, and financial logins.
- Devices: Laptops, phones, and external drives that hold sensitive data.
Get specific. “My privacy” is too broad. Instead, think: “The anonymity of a whistleblower who contacted me” or “The draft of a report on local government corruption.” Write these assets down. The act of listing them forces you to confront what you actually value and what you’re willing to defend.

Step 2: Identify Your Adversaries
An adversary is anyone who might want to compromise your assets. In an open society, adversaries are often not monolithic state actors but a mix of motivated groups and individuals. Be honest about who might target you and why. Common adversaries include:
- Harassers and trolls: Individuals or loose networks aiming to intimidate, silence, or discredit you.
- Corporations: Data brokers, surveillance-advertising companies, or competitors seeking to profile or undermine you.
- Overreaching law enforcement: Agencies that may use legal tools like subpoenas or National Security Letters to access your data without proper oversight.
- Cybercriminals: Opportunistic attackers looking for financial gain through ransomware, phishing, or identity theft.
- Insiders: A disgruntled colleague, a vindictive ex-partner, or someone with access to your physical space.
For each adversary, consider their motivation and resources. A troll has high motivation but low resources. A state-level actor has vast resources but may only target you if your work directly threatens their interests. This step prevents you from over-engineering defenses against a threat you don’t face, which is a common and exhausting mistake.
Step 3: Map the Attack Vectors
An attack vector is the path an adversary takes to compromise your asset. This is where you think like an opponent. For each asset and adversary pair, ask: How would they get to this? The most common vectors for individuals include:
- Phishing: Deceptive emails or messages designed to steal credentials or install malware.
- Physical theft or loss: A stolen laptop or a misplaced USB drive.
- Network interception: Unencrypted traffic on public Wi-Fi or a compromised home router.
- Legal coercion: Subpoenas, warrants, or national security letters served to your service providers.
- Social engineering: Manipulating customer support to gain access to your accounts.
- Doxxing: Aggregating public and semi-public information to expose your private life.
For example, if your asset is a confidential source’s identity and your adversary is a corporation filing a lawsuit, the vector might be a subpoena to your email provider. If your adversary is a troll, the vector might be doxxing through your social media history. Mapping vectors reveals where you need to focus your defenses.
Step 4: Assess the Impact and Likelihood
Not all threats are equal. A ransomware attack that locks your personal photos has a different impact than a leak that exposes a source to physical danger. Rate each threat on two scales: impact (how bad would it be?) and likelihood (how probable is it?). Use a simple high/medium/low matrix.
For a journalist, a high-impact, low-likelihood threat might be a state-level hacking attempt. A medium-impact, high-likelihood threat might be a phishing email. This exercise forces you to allocate your limited time and energy to the threats that matter most. You can’t defend against everything, so defend against what would hurt the most and what’s most likely to happen.

Step 5: Choose Practical Countermeasures
Countermeasures are the actions and tools you use to block or mitigate attack vectors. They should be proportional to the threat. For a high-impact, low-likelihood threat, you might accept some risk and focus on detection. For a high-likelihood threat, you need strong, easy-to-use defenses. Here are countermeasures mapped to common vectors:
Against Phishing and Account Takeover
- Use a password manager to generate and store unique, strong passwords for every service.
- Enable two-factor authentication (2FA) everywhere, preferably using a hardware security key like a YubiKey or a TOTP app, not SMS.
- Learn to recognize phishing attempts: check sender addresses, hover over links, and never open unexpected attachments.
Against Physical Theft or Loss
- Encrypt your devices. Use FileVault on macOS, BitLocker on Windows, or LUKS on Linux.
- Set a strong device passphrase, not a simple PIN. Biometrics can be compelled; a passphrase cannot.
- Maintain verified backups. Follow the 3-2-1 rule: three copies of your data, on two different media, with one off-site.
Against Network Interception
- Use a trusted VPN when on public Wi-Fi, but understand its limits: a VPN provider can see your traffic, so choose one with a strong no-logs policy that has been tested in court.
- Ensure websites you visit use HTTPS. The Electronic Frontier Foundation’s (EFF) browser extension, HTTPS Everywhere, can help enforce this.
- For sensitive communications, use end-to-end encrypted messaging like Signal, which protects content even if the network is compromised.
Against Legal Coercion
- Understand your threat landscape. If you’re likely to face subpoenas, choose service providers with a track record of transparency and fighting for user rights, such as those that publish regular transparency reports.
- Use encryption that you control. With end-to-end encryption, the service provider can’t hand over your data because they don’t have access to it.
- Know your rights. Organizations like the Electronic Frontier Foundation (EFF) provide guides on responding to legal requests for data.
Against Doxxing
- Audit your online presence. Search for yourself and see what public records, social media profiles, and data broker sites reveal.
- Use a service like DeleteMe or manually opt out of data broker sites to reduce your digital footprint.
- Separate your professional and personal online identities. Use different email addresses, usernames, and even devices if the threat is high.
Building a Sustainable Security Routine
A threat model isn’t a one-time document; it’s a living practice. Set a recurring calendar reminder to review your assets, adversaries, and countermeasures. Your life changes, and so do the threats. A new project, a public talk, or a change in your personal relationships can shift your risk profile overnight.
Integrate security into your daily habits. For example, make it a rule to lock your screen every time you step away from your desk. Use a password manager so strong, unique passwords become the default, not the exception. Keep your software updated—not just your operating system, but your router firmware, your browser, and every app you use. These small, consistent actions build a resilient baseline that’s far more effective than occasional, heroic security sprints.
Common Pitfalls in Personal Threat Modeling
Many people, when first introduced to threat modeling, fall into one of two traps. The first is security nihilism: the belief that because no system is perfectly secure, no effort is worthwhile. This is false. Most attacks are opportunistic, not targeted. Simple measures like enabling 2FA and using a password manager stop the vast majority of automated and low-effort attacks.
The second trap is security maximalism: trying to protect against every conceivable threat, which leads to burnout and unusable systems. If your security measures are too cumbersome, you’ll abandon them. A threat model helps you find the middle ground—the set of practices that meaningfully reduce your most likely and most damaging risks without making your digital life unlivable.
FAQ
How is a personal threat model different from a corporate risk assessment?
A corporate risk assessment often focuses on financial loss, regulatory penalties, and brand damage across an entire organization. A personal threat model is centered on you as an individual: your physical safety, your personal relationships, your private communications, and your ability to speak and act freely. It’s less formal but more intimate. You’re the sole decision-maker, and the consequences are directly felt. The process is the same—identify assets, adversaries, and vectors—but the scale and the stakes are personal.
Do I need a different threat model for my phone versus my laptop?
Yes, and you should. Your phone is a unique asset because it’s almost always with you, contains a dense concentration of personal data (location history, messages, photos, contacts), and is more susceptible to physical theft or seizure. Your laptop may hold more work-related assets and is often used on different networks. Create a sub-model for each device. For your phone, prioritize anti-theft measures (encryption, remote wipe capability) and limit the sensitive data stored on it. For your laptop, focus on endpoint security, encrypted backups, and network protections.
What if I can’t afford paid security tools?
Many of the most effective countermeasures are free and open-source. Bitwarden offers a strong free tier for password management. Signal is free for encrypted messaging and calls. The Tor Browser, which protects your anonymity online, is free. VeraCrypt provides free disk encryption. The key isn’t money; it’s adopting a security mindset and using well-vetted, transparent tools. Often, free and open-source tools are more trustworthy than paid alternatives because their code can be audited by the community.
How often should I update my threat model?
At a minimum, review your threat model every six months. Also, trigger a review whenever you experience a major life change: starting a new job, moving to a new city, beginning a sensitive project, or after a security incident. Think of it like a fire drill—you practice it so that when there’s an actual fire, you know exactly what to do. A stale threat model is a false comfort.
Your Next Step: From Model to Action
This article has given you the framework. Your next step is to spend thirty minutes with a notebook or a blank document and draft your first threat model. List your top three assets, your most likely adversaries, and the attack vectors that keep you up at night. Then, pick one countermeasure from this guide and implement it today. Maybe it’s enabling 2FA on your email. Maybe it’s installing Signal. The goal is progress, not perfection.
Security in an open society is a collective effort. When you protect your own communications, you protect the people who trust you. When you model good practices, you raise the bar for your community. This isn’t about paranoia; it’s about agency. You have the right to participate in public life without fear. A personal threat model is how you claim that right, practically and deliberately.
This article is part of our ongoing series on operational security for democratic actors. For a deeper dive into specific tools, see our guides on encrypted communication and secure device setup.