Adversarial exposure · Knowledge distribution
Threat-model the design, and keep doing it after the training
Structured threat modelling taught to a team and then tracked produced mitigations that measurably blocked real attacks — 541 unique intrusion attempts, five privileged account hijackings prevented, three public-facing vulnerabilities addressed over 120 days — with 20 of 25 participants still using it unprompted a month later.
Do this firstWrite down decisions, with the reasoning and the alternatives
Sit down with a design and ask what an opponent would do to it, using a structure so the answer does not depend on who is in the room.
Two things in the measurement matter more than the headline. Adoption was tracked at thirty and 120 days rather than assumed from a completed session — that is the number most training programmes never collect. And of 147 distinct mitigation strategies the participants generated, 64% were new and unimplemented, which says the exercise surfaced work that existing processes had not.
One honest caveat the study states about itself: it evaluated one framework, so it cannot tell you whether a different structure would have done better or whether the structure mattered at all against simply setting aside the time.
The decoy
A one-off workshop. The measurable question is not whether people can do it once with a facilitator in the room; it is whether any of them still do it thirty days later without being asked.
Evidence
- The Battle for New York: A Case Study of Applied Digital Threat Modeling at the Enterprise Level — II partly self-reported20 of 25 participants were still incorporating the method into daily duties 30 days after training without prompting. Over 120 days, participant-designed mitigations blocked 541 unique intrusion attempts, prevented the hijacking of five privileged accounts, and addressed three public-facing server vulnerabilities. Participants generated 147 distinct mitigation strategies, 64% of them new and unimplemented.
Last reviewed 2026-08-19.