---
title: "Threat modelling | Dedicated Security Team | Azendo"
description: "Threat modelling with STRIDE and data-flow diagrams: design flaws found early, and the dedicated Azendo specialists who work with it. Fully managed."
url: "https://azendo.co/skills/threat-modelling/"
---

1. [Home](https://azendo.co/)
2. [Skills](https://azendo.co/skills/)
3. Threat modelling

# Threat modelling specialists for your dedicated team.

Threat modelling is a structured way to find security flaws in a design before code is written. A team draws the system as a data-flow diagram, marks the trust boundaries, and asks what can go wrong at each one, often using STRIDE: spoofing, tampering, repudiation, information disclosure, denial of service and elevation of privilege.

## Where threat modelling fits in a long-term product team.

Design flaws are the security problems that cost most to fix late, because the fix is a redesign. A service that trusts a header set by the client, or a queue any internal system can write to, is working exactly as built. Threat modelling finds these while they are still a line on a whiteboard, and the output is a short list of threats, each with a mitigation and an owner.

Scale and ceremony are where it goes wrong. A model of the whole platform, produced once in a long workshop, is out of date by the next quarter and rarely opened again. Smaller models, one per feature or per change to a trust boundary, kept next to the design document and revisited when the design changes, are the ones that keep finding problems. Free tools such as OWASP Threat Dragon and the Microsoft Threat Modeling Tool help with the diagrams, and the Elevation of Privilege card game, created by Adam Shostack at Microsoft, turns STRIDE into a short exercise a whole team can join.

## What your dedicated team does with threat modelling.

A threat model is only as good as the knowledge of the people drawing it. Someone who has worked on the product for a year knows which integrations were added in a hurry and which assumptions were never written down, and those gaps are where threats tend to sit.

Keeping models current as features ship is steady work for a security engineer who stays with one product, and it belongs at the core of a [dedicated cybersecurity team](https://azendo.co/services/dedicated-cybersecurity-team/).

## Common threat modelling use cases.

* Design review before a new feature Threats found while the fix is still a change to a diagram.
* Trust boundaries made explicit Every place data crosses from one level of trust to another drawn and named, so controls go where they matter.
* Scope for a penetration test The model points authorised testing at the paths an attacker would try first.

## Adding threat modelling skills to your team.

Threat modelling is scheduled into the same committed monthly capacity as the rest of the security work, so it happens at design time for each significant change.

Threat modelling specialists join your team remotely as dedicated, full-time team members, selected, employed and managed by us in Chiang Mai and Bangkok. Companies that [hire offshore developers](https://azendo.co/hire-a-dedicated-development-team-in-thailand/) through Azendo add the skill at the next monthly cycle.

## Roles that use threat modelling

* [Cloud Security Engineer Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/cloud-security-engineer/)
* [Security Engineer Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/security-engineer/)

## Disciplines it belongs to

* [Cybersecurity](https://azendo.co/services/dedicated-cybersecurity-team/)

Capacity is agreed across your whole team, with one monthly fee, not per skill.

## Related in security

* [Trivy, a skill in our teams](https://azendo.co/skills/trivy/)
* [HashiCorp Vault, a skill in our teams](https://azendo.co/skills/hashicorp-vault/)
* [OWASP Top 10, a skill in our teams](https://azendo.co/skills/owasp-top-10/)
* [Burp Suite, a skill in our teams](https://azendo.co/skills/burp-suite/)
* [OWASP ZAP, a skill in our teams](https://azendo.co/skills/owasp-zap/)
* [Semgrep, a skill in our teams](https://azendo.co/skills/semgrep/)
* [Snyk, a skill in our teams](https://azendo.co/skills/snyk/)

## Tell us what your roadmap needs threat modelling for.

A service delivery manager will reply with the specialists we'd suggest, the monthly capacity and what the first month looks like.

[Browse all skills](https://azendo.co/skills/)
