← Privacy Guides

Start here

Threat modeling: start here

Decide what you are protecting, from whom, and how much effort it deserves, before you install anything.

  • Low threat
  • Time 30 minutes
  • Difficulty Easy
  • Last verified

What this protects, and what it doesn't

Protects

  • Against wasted effort: hardening the wrong thing while the real exposure stays open.
  • Against tool-first thinking: you pick guides because they answer a threat you wrote down, not because they are popular.
  • Against panic and overload: a written plan tells you which threat level you actually need.

Does not protect

  • It protects nothing on its own. It is a plan, not a control: you still have to carry out the steps it points to.
  • It does not make you anonymous or untraceable. No guide here does; your threat model decides what is good enough.
  • It goes stale. A new job, a public profile, a breakup or a lawsuit changes your adversaries, so review it.

Prerequisites

  • Pen and paper, or a local note that is not synced to a cloud you do not control.
  • Thirty quiet minutes and some honesty about your situation.

Step by step

  1. List what you want to protect

    Write down your assets: the things you value. For most people they are information: messages, contacts, photos, location history, client files, passwords, the fact that you talk to a particular person. Add devices and accounts that hold them (phone, laptop, email, cloud storage).

    Be specific. "My privacy" is not an asset. "The list of sources in my notes app" is.

  2. Name who you protect it from

    An adversary is a person or organisation that poses a threat to your assets. Typical ones: opportunistic criminals and phishing gangs, data brokers and advertisers, an abusive partner or family member with physical access to your phone, a former employer, a competitor, a stalker, a hostile state.

    For each one, note what they can realistically do: guess or buy passwords, take your unlocked phone, send legal requests to your provider, run targeted malware.

  3. Estimate how bad failure would be

    For each asset and adversary pair, write what happens if you lose: embarrassment, money, a lost client, a lost job, legal trouble, physical danger to you or someone else. This is what separates a Low-level problem from a High-level one.

  4. Estimate how likely it is

    A capable adversary who has no interest in you is a low likelihood. A moderately skilled ex-partner who knows your PIN is a high one. Rank each pair: likely, possible, unlikely. Spend your effort on likely and severe first.

  5. Decide how much trouble you will accept

    Every protection costs time, money or convenience. Write down what you will actually keep doing: a password manager and passkeys are cheap; a separate hardened phone or an amnesic operating system is not. A plan you abandon after a week protects less than a modest one you keep.

  6. List your allies

    Who can help, and who shares your risk? Colleagues, your IT or security team, a lawyer, a press-freedom or digital-rights organisation, family members who use the same accounts. Your security is often only as strong as the people you message, so the plan may include getting them on the same tools.

  7. Pick your threat level and your next three guides

    Match your worst likely scenario to a level:

    • Low: everyday threats (phishing, account takeover, data brokers, lost or stolen devices).
    • Medium: you are a likely target because of what you do or who you talk to.
    • High: a well-resourced adversary is actively interested in you.

    Then pick the three guides in Privacy Guides that close your biggest gaps, and do those first.

  8. Write it down and set a review date

    Keep the plan where your adversaries cannot read it. Put a review date in your calendar (every six months, and after any big change in your life or work), and ask the last of the four threat-modeling questions: did we do a good enough job?

Common mistakes

  • Starting with tools (“which VPN?”) instead of threats. Many people who buy a VPN first are more exposed through a reused password.
  • Planning only for the most dramatic adversary and ignoring the likely one, such as someone who can pick up your unlocked phone.
  • Treating the plan as permanent. Your exposure changes when your life does.
  • Keeping the plan in a shared or synced document that the adversary can read.

Going further

If your plan lands on Medium or High, continue with the device and communications guides, and consider a professional threat-modeling session with your security team. Security professionals can use the same four questions for systems and engagements: What are we working on? What can go wrong? What are we going to do about it? Did we do a good enough job?