qualitylab

Adversarial exposure · Knowledge distribution

Threat-model the design, and keep doing it after the training

tier II/cost to adopt: medium/active

Structured threat modelling taught to a team and then tracked produced mitigations that measurably blocked real attacks — 541 unique intrusion attempts, five privileged account hijackings prevented, three public-facing vulnerabilities addressed over 120 days — with 20 of 25 participants still using it unprompted a month later.

Do this firstWrite down decisions, with the reasoning and the alternatives

Sit down with a design and ask what an opponent would do to it, using a structure so the answer does not depend on who is in the room.

Two things in the measurement matter more than the headline. Adoption was tracked at thirty and 120 days rather than assumed from a completed session — that is the number most training programmes never collect. And of 147 distinct mitigation strategies the participants generated, 64% were new and unimplemented, which says the exercise surfaced work that existing processes had not.

One honest caveat the study states about itself: it evaluated one framework, so it cannot tell you whether a different structure would have done better or whether the structure mattered at all against simply setting aside the time.

The decoy

A one-off workshop. The measurable question is not whether people can do it once with a facilitator in the room; it is whether any of them still do it thirty days later without being asked.

Evidence

Last reviewed 2026-08-19.