"Threat modelling" sounds like something for a security team with a whiteboard and a budget to match. It is not. At its heart it is a simple habit: thinking like someone who wants to cause you trouble, before they get the chance. What do you have that is worth taking or breaking, what could go wrong, and what will you do about it first. Any owner can do a useful first pass in an afternoon.
We use the same thinking every time we design cyber security for a client. Good security is not a shopping list of tools. It starts with understanding one specific business, then putting the effort where the real risk sits. Here is the plain-English version you can run yourself.
The goal is not perfect security. It is knowing your biggest risks and dealing with them in a sensible order, before something forces the issue.
1. Map what matters
Start with a short, honest list of what your business actually depends on. That usually means your data (customer records, contracts, financials), the systems that run the day (Microsoft 365, your line-of-business software, your website), the way money moves (invoices, bank details, payroll), and who has access to all of it. Do not skip email. Your Microsoft 365 mailboxes are often the keys to everything else, which is why business email compromise is such a common and costly attack.
2. Ask what could go wrong, and who would want it
For each item on your list, ask two questions: what could go wrong, and who would benefit. You do not need a threat-intelligence feed for this. The realistic scenarios for most small businesses are well known:
- Ransomware locks up your files and someone demands payment to release them.
- Business email compromise, where an attacker slips into a mailbox and redirects an invoice or payment.
- A laptop or phone is lost or stolen with company data still on it.
- A supplier or software vendor you rely on is breached, and the problem reaches you through them.
- An honest mistake: a weak password reused, a dodgy link clicked, a file shared too widely.
Threats are not always someone in a hoodie. Human error causes a large share of incidents, so plain carelessness belongs on the list right next to the criminals.
3. Rank by likelihood and impact
You cannot fix everything at once, and you do not need to. Take each scenario and weigh two things: how likely it is, and how much it would hurt if it happened. A risk that is both likely and painful goes to the top. Something unlikely and minor can wait. This is where threat modelling earns its keep, because it turns a vague sense of unease into a short, ordered list you can actually act on.
4. Put controls against the biggest risks first
Now match your effort to your ranking. The controls that block the most common attacks are well understood and, for the most part, not expensive: multi-factor authentication on every account, keeping systems patched, backups you have actually tested a restore from, and people who can recognise a suspect email. Two Australian baselines give you a ready-made starting point. The ASD Essential Eight sets out eight practical mitigation strategies that stop or limit most attacks. SMB1001 is a tiered standard built specifically for smaller businesses, so you can lift your maturity in stages rather than all at once. Measuring your top risks against one of these means you are working to something recognised, not guessing.
5. Revisit as the business changes
A threat model is a snapshot, not a monument. The moment you add a new system, take on a new supplier, hire more people, or change how you get paid, the picture shifts. Set a regular cadence to look again, and revisit sooner after any big change. It also pays to know your obligations in advance: under the Notifiable Data Breaches scheme, certain breaches must be reported, so it is far better to have thought that through before you are under pressure. For the same reason, it is worth reading ahead on what to do in the first hour of a cyberattack, so a bad day does not become a worse one.
How we build AgileSECURE around real risk
This is exactly how we approach AgileSECURE. Rather than selling a single product and calling it protection, we start with what a business has, what it can least afford to lose, and where the realistic threats sit, then build layered controls against those first. If you would like an outside view of where you stand, our free Cyber Health Check is a straightforward way to get one.
Threat modelling is not about fear. It is about spending your limited time and money where they count, with a clear head, before anything goes wrong. Done once a year, and again whenever the business changes, it quietly keeps your security honest.
Common questions
What is threat modelling in simple terms?
It is the habit of thinking like an attacker about your own business: what is worth protecting, what could go wrong, and what you will fix first. You do the thinking before an incident, not after.
Do I need special tools or a big budget to start?
No. A first pass is just a list of what matters, the realistic things that could go wrong, and a ranking by likelihood and impact. Many of the most effective controls, like multi-factor authentication and tested backups, cost very little.
How does this relate to the ASD Essential Eight and SMB1001?
Threat modelling tells you where your biggest risks are, while the Essential Eight and SMB1001 give you recognised, ready-made controls to put against them. We use both when building AgileSECURE around a client's real risk.