By Kira Mikkonen
A personal threat model is a structured way to figure out who might want to harm you, what they could do, and which of your assets need the most protection. It sits at the intersection of operational security, privacy engineering, and everyday risk management. For people working in journalism, activism, human rights, or local government, a threat model is not a one-time checklist. It is a living document that changes when your work, relationships, or technology change. This guide walks through a practical method for building and updating your own model, with a focus on open security for democratic societies.
Why a Personal Threat Model Matters
Most security advice fails because it tries to protect everyone from everything. That approach leads to burnout, expensive tools, and a false sense of safety. A threat model flips the question. Instead of asking “What is the best security tool?”, you ask “What am I protecting, from whom, and for how long?”
For example, a municipal clerk who handles election records faces different threats than a freelance reporter covering corruption. The clerk may need to protect the integrity of documents and the privacy of voters. The reporter may need to protect a source’s identity and the confidentiality of unpublished material. Both need security, but their models lead to different priorities.
Threat modeling is also a core practice in the open security community. It encourages transparency about assumptions, shared methods, and continuous review. That openness matters in democratic societies, where security should not depend on secrecy or gatekeeping.
Start With Assets, Not Adversaries
Many people begin by listing enemies. That can feel urgent, but it often leads to vague fear. A more useful starting point is to list what you need to protect. Assets can be physical, digital, or social.
Common Asset Categories
- Devices: laptop, phone, external drives, router, smart home devices.
- Accounts: email, cloud storage, social media, banking, government portals.
- Data: contacts, messages, photos, documents, location history, metadata.
- Relationships: sources, colleagues, family members, community groups.
- Reputation: public trust, professional standing, legal record.
- Physical safety: home address, travel patterns, daily routines.
Write these down in a private notebook or an encrypted file. Do not store the list in a shared cloud account unless you have already decided that account is part of your trusted base. The act of listing assets often reveals dependencies you had not considered. For example, a journalist may realize that a source’s safety depends on the journalist’s own phone hygiene.
Identify Who Could Threaten Each Asset
Once you have an asset list, ask who would want to access, disrupt, or destroy each item. Be specific. “Hackers” is too broad. “A former partner with access to my shared photo library” is actionable. “A state agency that monitors protest organizers” is actionable if you have reason to believe you are in that category.
Threat Actor Types
- Opportunistic criminals: phishing, malware, theft of unattended devices.
- Targeted criminals: extortion, doxing, account takeover for financial gain.
- Abusive individuals: stalking, harassment, intimate partner surveillance.
- Corporate data brokers: location tracking, ad profiling, sale of personal data.
- State agencies: lawful interception, metadata analysis, border device searches.
- Insider threats: colleagues, contractors, family members with shared access.
For each asset, note which threat actors are realistic. A local council member may face harassment from a political opponent but is unlikely to be targeted by a foreign intelligence service. A human rights lawyer working on cross-border cases may face both. The goal is not to imagine every possible attack. The goal is to rank plausible ones by likelihood and impact.
Assess Likelihood and Impact
A simple two-axis grid works well. For each threat-asset pair, rate likelihood from low to high and impact from low to high. Focus first on items that are both likely and high impact. Those are your priority risks.
For example, a journalist who uses a personal Gmail account for source communication may rate “account takeover by phishing” as medium likelihood and high impact. A city employee who posts work schedules on a public social media profile may rate “physical harassment at the office” as low likelihood but high impact. Both deserve attention, but the journalist’s risk may require immediate changes to email habits, while the city employee’s risk may require a conversation with a supervisor about privacy settings.
Be honest about uncertainty. If you do not know how likely a threat is, say so. You can still take low-cost steps to reduce impact while you gather more information. Security decisions under uncertainty are normal. The key is to document your reasoning so you can revisit it later.
Map Your Current Defenses
Before adding new tools, list what you already do. Many people have more defenses than they realize, but they are unevenly applied.
Common Existing Defenses
- Two-factor authentication on some accounts.
- Full-disk encryption on a laptop or phone.
- A password manager for some logins.
- Signal or another end-to-end encrypted messenger for certain conversations.
- Physical locks, screen privacy filters, or a safe for documents.
- Separate work and personal devices.
For each priority risk, note which existing defense applies. Then look for gaps. A common gap is inconsistent use. For example, a person may have two-factor authentication on email but not on the cloud storage account that holds backups of that email. Another gap is shared access. A family member may know a device passcode, or a former colleague may still have access to a shared drive.
This step often reveals that the problem is not a lack of tools. It is a lack of routine. Fixing the routine is usually cheaper and more effective than buying a new app.
Choose Controls That Match Your Real Life
Security controls should fit your daily habits, not the other way around. If a control is too difficult, you will stop using it. That creates a worse situation than having no control at all, because you may believe you are protected when you are not.
Practical Control Examples
- Email: Move high-sensitivity conversations to a dedicated account with hardware-key two-factor authentication. Use a separate account for newsletters and online shopping.
- Messaging: Set disappearing messages for sensitive group chats. Verify safety numbers for key contacts.
- Devices: Enable automatic updates. Use a standard user account instead of an administrator account for daily work.
- Travel: Use a travel-only phone with minimal data when crossing borders. Log out of sensitive accounts before departure.
- Home network: Change default router passwords. Segment smart home devices from work devices.
- Physical documents: Shred papers with personal data. Store backups in a fireproof safe or a trusted off-site location.
Each control should be tied to a specific risk from your grid. If you cannot name the risk, the control may be security theater. That does not mean it is useless, but it should not be a priority.
Write It Down and Set a Review Date
A threat model that lives only in your head will drift. Write a short version: one page is enough. Include your top five assets, the three most likely threat actors, your priority risks, and the controls you plan to use. Store it securely. Set a calendar reminder to review it every three to six months, or sooner if your work changes.
Review questions to ask:
- Have I started a new project that involves sensitive data?
- Have I changed jobs, moved, or ended a relationship?
- Have any of my accounts been compromised or targeted?
- Have I stopped using a control because it was inconvenient?
- Has the legal or political environment changed in a way that affects my risk?
This review habit is what separates a living threat model from a forgotten document. It also builds a personal security history that can help you spot patterns over time.
Common Mistakes and How to Avoid Them
Even experienced practitioners make mistakes. Here are a few that show up often in workshops and consultations.
Overestimating the Adversary
Assuming every threat actor has unlimited resources leads to paralysis. Most attacks are opportunistic and rely on known weaknesses. Fixing the basics—updates, two-factor authentication, unique passwords—blocks a large share of real-world incidents. You do not need to be invisible. You need to be harder to target than the next person.
Ignoring Metadata
Content encryption protects what you say, but metadata reveals who you talk to, when, and for how long. For some threat models, metadata is the main risk. A journalist’s call log can expose a source even if the call content is encrypted. Consider whether you need to reduce metadata exposure through tools like Tor, VPNs, or simply changing communication patterns.
Treating Security as a Product
Buying a “secure” app does not make you secure. The app’s defaults, your settings, and your behavior all matter. A secure messaging app with cloud backup enabled may store plaintext copies of your messages on a server. Read the settings. Ask what happens if you lose your phone. Test your recovery process before you need it.
Forgetting Physical and Social Context
Digital security is only one layer. A locked laptop does not help if someone can watch you type your password. A private chat does not help if you discuss sensitive topics in a café. Social engineering often targets the people around you, not your devices. Include physical and social risks in your model.
Tools and Resources for Open Security
Several organizations publish free, practical guidance that aligns with open security principles. The Electronic Frontier Foundation’s Surveillance Self-Defense guide covers threat modeling, encryption, and device hardening. The Cybersecurity and Infrastructure Security Agency offers plain-language advice for individuals and small organizations. The Freedom of the Press Foundation maintains training materials for journalists and their sources. These resources are useful starting points, but they are not substitutes for your own written model.
What Comes Next
After you complete a first draft of your threat model, the natural next step is to test it. Pick one priority risk and run a small drill. For example, if you worry about losing access to your primary email account, try the account recovery process from a different device. If you worry about border searches, practice logging out of sensitive accounts and removing files before a trip. These drills reveal gaps that no checklist can catch.
This article is part of a series on personal operational security for people who work in democratic institutions, journalism, and civil society. Future pieces will cover device hardening for travel, secure communication with sources, and how to help a colleague who has been doxed. If you have a specific question about your own threat model, send it through the contact page. Reader questions often shape the next article.
Frequently Asked Questions
How often should I update my personal threat model?
Review it every three to six months, and immediately after major life or work changes. A new job, a move, a legal case, a relationship change, or a security incident all warrant a fresh look. The review does not need to be long. Thirty minutes with your one-page document is enough to catch most drift.
What is the difference between a threat model and a risk assessment?
A threat model focuses on who might target you and why. A risk assessment focuses on the likelihood and impact of specific events. In practice, a personal threat model includes a lightweight risk assessment. You identify threat actors, list assets, and then rank risks by likelihood and impact. The two practices overlap, but threat modeling starts with the adversary’s perspective.
Do I need to be a technical expert to build a threat model?
No. The core skill is clear thinking about what you value and who might threaten it. Technical knowledge helps when choosing controls, but you can start with basic steps like unique passwords, two-factor authentication, and device updates. Many open security guides are written for non-experts and include step-by-step instructions.
What if I share devices or accounts with family members?
Shared access is a common and often overlooked risk. Include family members in your model as both assets and potential insider threats. Set clear boundaries for shared devices, use separate user accounts where possible, and discuss what information should not be shared casually. A family member who forwards a message or leaves a device unlocked can unintentionally expose you.


