Applying Threat Models and Selecting the Right Security Controls

Blog By: Kenneth Juhan

Date: August 12, 2026

Kenny Juhan will explain Threats to the model in the following blog.

Applying Threat Models and Selecting the Right Security Controls

Threat modeling is useful only when it leads to better security decisions.

For SecurityX, candidates should understand how organizations evaluate threats differently depending on whether they are protecting an existing system or designing a new system without established controls.

Starting with the Environment

Before selecting security controls, the organization needs to understand what it is protecting.

That includes:

  • Assets
  • Data
  • Users
  • Applications
  • Network connections
  • APIs
  • Trust boundaries
  • Dependencies

Threat modeling then asks how an attacker could interact with those components.

The goal is not to predict every possible attack. It is to identify realistic threats and design appropriate defenses.

Existing Systems

When an existing system is already operating, security teams first need to understand what controls are currently in place.

They might review:

  • Network architecture
  • Authentication
  • Authorization
  • Encryption
  • Logging
  • Segmentation
  • Existing vulnerabilities
  • Security monitoring

The next step is identifying gaps between existing protection and the organization’s actual risk.

This is important because adding another control is not always the best answer.

If an effective control already addresses the risk, adding a duplicate technology could increase cost and complexity without meaningfully improving security.

Selecting Appropriate Controls

Control selection should be based on the threat and business requirements.

For example, if the threat is unauthorized access, stronger authentication or access controls may be appropriate.

If the threat is lateral movement, segmentation or microsegmentation may provide better protection.

If the concern is unauthorized modification, integrity controls such as hashing or digital signatures may be appropriate.

The key SecurityX lesson is:

Match the control to the risk.

Do not select a technology simply because it is considered “more secure.”

Designing Without an Existing System

Threat modeling can be even more valuable before a system is built.

Security teams can review architecture diagrams, data flows, trust boundaries, APIs, authentication requirements, and storage designs before deployment.

This allows security to be designed into the architecture instead of added after vulnerabilities are discovered.

Correcting an insecure design before deployment is usually easier and less expensive than redesigning a production environment.

This idea also connects to secure by design principles.

Balancing Security and Business Needs

Security controls should reduce risk without unnecessarily preventing the organization from accomplishing its mission.

A control may provide excellent protection but create unacceptable performance problems or prevent required business operations.

SecurityX frequently expects candidates to balance:

Security + Risk + Business requirements + Operational impact

Why This Matters for SecurityX

SecurityX scenario questions often include several controls that could technically improve security.

Your job is to identify which control BEST addresses the specific threat in the environment described.

A useful process is:

Understand assets → Identify threats → Review existing controls → Find gaps → Select control → Validate effectiveness

For a new system:

Model threats → Design controls → Build securely → Test → Validate

Threat modeling is not just about creating diagrams. It gives organizations a structured way to understand risk before spending money or deploying technology.

Learning to connect threats with appropriate controls is one of the most useful skills for SecurityX because it reflects exactly how many scenario-based questions are designed.

Leave a comment