Principal Threat Model | Executive Digital Protection | VerSprite

Defenders · Managed Cyberthreat Intelligence

Principal
ThreatModel

PASTA, applied to a person

You threat-model your applications. Your adversaries have moved on to the people who run them. A Principal Threat Model applies the same seven stages VerSprite co-authored for software — Process for Attack Simulation and Threat Analysis — to a consenting executive: their digital footprint, their household, their trust circle, and the specific adversaries with a reason to reach them.

Exposure Rose

Illustrative profile

Twelve threat classes, scored at intake and re-scored against the treatment roadmap.

Exposure Rose A twelve-axis radar chart of an illustrative principal’s exposure across twelve threat classes, shown at intake and after the treatment roadmap is delivered. Every value is also listed in the table below the chart. DOX PHYS STALK EXTORT ATO SIM SYNTH BEC COERCE TRAVEL HOUSE INTEL
Measured exposure Modelled residual
Personal account takeover
Intake 93  →  Residual 18

Select any axis to read that threat class.

Illustrative sample data, not a client profile. In a live engagement each axis is scored from evidenced findings and re-scored at remediation close-out.

Why now

The attack surface went home

Enterprise controls stop at the corporate perimeter. Your executives do not. The gap between what a company can defend and where its leaders actually live is where a growing share of high-consequence attacks now begin.

The perimeter got personal

Personal email, a home router, a family member’s public profile, and a mobile carrier account sit outside every control your security programme owns — and each one leads back to the principal.

Aggregation is the weapon

No single record is sensitive. A broker listing, a property filing, a race result, and a geotagged photo combine into a home address and a predictable routine. Adversaries assemble; defenders rarely check what assembles.

Monitoring is not modelling

Alerting on mentions tells you something happened. It does not tell you which adversary matters, which path they would take, or which of fifty findings to fix first. That requires a model.

The methodology

Seven stages, re-scoped to a person

PASTA was built to model attacks against systems. The stages hold when the asset is a human being — the decomposition changes, the discipline does not. Each stage below carries its original name.

01

Protection objectives

Define what must not happen — to the principal, the household, and the business. Written authorisation, scope, and family inclusion are settled before anything else begins.

Definition of business objectives

02

Footprint scope

Enumerate the real surface: personal accounts and domains, devices, the home network, residences, vehicles, travel patterns, and household staff.

Definition of technical scope

03

Trust circle decomposition

Map who legitimately holds the principal’s data and access — assistant, family office, counsel, physicians, building management, vendors — and how it flows between them.

Application decomposition and analysis

04

Adversary analysis

Establish who is actually motivated to reach this principal, evidenced from surface, deep, and dark web collection alongside breach corpora. Grievance, ideological, financial, fixated, and state interest are assessed separately.

Threat analysis

05

Exposure analysis

Locate what is genuinely reachable: broker records, property filings, credential reuse, carrier weaknesses, geotagged imagery, and routine predictability.

Weakness and vulnerability analysis

06

Attack path simulation

Build an attack tree for each credible threat, then have our offensive practice walk it. Paths are demonstrated end to end, not asserted in a table.

Attack modelling and simulation

07

Risk treatment

Sequence countermeasures by risk reduced per dollar. Deliver a roadmap with a named owner for every item and a written residual risk position.

Risk analysis and management

Then re-model

An adversary picture has a shelf life. Managed engagements re-run stages four through seven quarterly, so the model tracks a moving threat rather than freezing a moment.

Continuous cycle

Threat library

Twelve classes we model against

Every principal is scored against the same library, so exposure is comparable across an executive team and over time. Which classes are credible — and in what order — is what stage four decides.

Doxxing & coordinated harassment

Aggregated public record released to mobilise a crowd against the principal.

Residential approach

Home identified and then physically visited, watched, or served.

Fixated person & stalking

Sustained individual attention escalating toward contact.

Extortion & sextortion

Leverage discovered or manufactured, then monetised under deadline.

Personal account takeover

Reused or breached credentials into personal email, cloud, or finance.

SIM swap & carrier fraud

The mobile number ported away to defeat SMS second factors.

Synthetic impersonation

Cloned voice or video used to authorise a payment or unlock access.

Executive impersonation & BEC

The principal’s identity worn to instruct their own staff.

Trust-circle coercion

Pressure applied to staff or family as the route to the principal. Modelled so it can be hardened.

Travel & K&R exposure

Itinerary predictability weighed against destination risk.

Household & family exposure

Relatives’ oversharing as the path of least resistance.

Adversarial intelligence collection

Litigation, competitive, or activist research operations targeting the principal.

Collection boundaries

What we will not do

  • Written authorisation from the principal precedes any collection. No exceptions and no pre-work.
  • We decline engagements to profile an individual who has not authorised it, including those commissioned by an employer.
  • Family members consent separately. For minors we perform exposure removal only, never profiling.
  • Exposed credentials are reported to the principal. They are never used to authenticate.
  • No collection against third parties who have not consented to be in scope.
  • Out of scope by policy: political affiliation and voting records, religious belief, health data, sexual orientation, immigration status, and every other protected-class attribute.
  • Findings belong to the principal. They reach an employer only on the principal’s written instruction.
  • Encrypted handling, named custodians, and a contractual destruction schedule.

A threat model of a person is only defensible if its collection is. These constraints are contractual rather than aspirational, and we put them in front of your counsel before anything is signed — reviewed against GLBA, FCRA, and applicable state anti-doxxing and stalking statutes.

Deliverables

What you receive

  • Principal Threat Model report
  • Annotated attack tree for each credible threat
  • Exposure inventory with source attribution
  • Prioritised risk treatment roadmap, with named owners
  • Household and travel hardening playbook
  • Executive briefing for the principal and designated staff
  • Written residual risk position
  • Re-test attestation at remediation close-out

Engagement tiers

How it is scoped

Baseline

One principal, one model. The full seven-stage engagement delivering the threat model, treatment roadmap, and executive briefing.

3–4 weeks
Managed

Baseline plus continuous exposure monitoring, broker suppression, takedown support, and a quarterly re-model as the threat picture moves.

Annual, quarterly cycle
Cohort

Board and executive team together. Each principal’s findings stay confidential to them; the CISO receives aggregate exposure reporting only.

Scoped per headcount

Why VerSprite

We wrote the methodology

PASTA was co-created by our founder, Tony UcedaVélez, and is used globally for risk-centric threat modelling. Extending it to a human principal is done here by the people who defined the stages — and validated by the same offensive practice that runs our red teams.

90%
Client retention rate
200+
Best-in-industry specialists
16+
Years of experience
2,000+
Risk assessments completed

FAQ

Common questions

How is this different from a data broker removal service?

Removal services delete records. A Principal Threat Model starts by establishing which adversaries are actually motivated to reach a specific individual, then works out which exposures matter to those adversaries. Removal becomes one countermeasure among many, sequenced by risk reduced rather than applied indiscriminately.

Do you need the executive’s permission?

Yes. Written authorisation from the principal precedes any collection, without exception. We do not accept engagements to profile an individual who has not authorised it — including engagements commissioned by their employer.

Does the employer see the findings?

Only if the principal directs it in writing. Findings belong to the principal. In cohort engagements across a board or executive team, each principal’s individual findings stay confidential to them, and the CISO receives aggregate exposure reporting.

What data do you refuse to collect?

Political affiliation and voting records, religious belief, health and medical data, sexual orientation, immigration status, and other protected-class attributes are out of scope by policy. None of it reduces risk to the principal, and all of it creates legal exposure for everyone involved.

How long does an engagement take?

A baseline model for a single principal runs three to four weeks from signed authorisation to executive briefing. Managed engagements continue on a quarterly re-model cycle.

Is this the same PASTA methodology used for applications?

The same seven stages, re-scoped. Because VerSprite co-created PASTA, the mapping from an application’s attack surface to a person’s footprint, household, and trust circle is done by the people who defined the stages in the first place.

Start with one principal

Most programmes begin with a single executive — usually the one whose exposure is already keeping someone awake. Bring a consenting principal and we will scope stages one through three on the first call.