The perimeter got personal
Personal email, a home router, a family member’s public profile, and a mobile carrier account sit outside every control your security programme owns — and each one leads back to the principal.
Defenders · Managed Cyberthreat Intelligence
PASTA, applied to a person
You threat-model your applications. Your adversaries have moved on to the people who run them. A Principal Threat Model applies the same seven stages VerSprite co-authored for software — Process for Attack Simulation and Threat Analysis — to a consenting executive: their digital footprint, their household, their trust circle, and the specific adversaries with a reason to reach them.
Exposure Rose
Illustrative profileTwelve threat classes, scored at intake and re-scored against the treatment roadmap.
Select any axis to read that threat class.
Why now
Enterprise controls stop at the corporate perimeter. Your executives do not. The gap between what a company can defend and where its leaders actually live is where a growing share of high-consequence attacks now begin.
Personal email, a home router, a family member’s public profile, and a mobile carrier account sit outside every control your security programme owns — and each one leads back to the principal.
No single record is sensitive. A broker listing, a property filing, a race result, and a geotagged photo combine into a home address and a predictable routine. Adversaries assemble; defenders rarely check what assembles.
Alerting on mentions tells you something happened. It does not tell you which adversary matters, which path they would take, or which of fifty findings to fix first. That requires a model.
The methodology
PASTA was built to model attacks against systems. The stages hold when the asset is a human being — the decomposition changes, the discipline does not. Each stage below carries its original name.
Define what must not happen — to the principal, the household, and the business. Written authorisation, scope, and family inclusion are settled before anything else begins.
Definition of business objectives
Enumerate the real surface: personal accounts and domains, devices, the home network, residences, vehicles, travel patterns, and household staff.
Definition of technical scope
Map who legitimately holds the principal’s data and access — assistant, family office, counsel, physicians, building management, vendors — and how it flows between them.
Application decomposition and analysis
Establish who is actually motivated to reach this principal, evidenced from surface, deep, and dark web collection alongside breach corpora. Grievance, ideological, financial, fixated, and state interest are assessed separately.
Threat analysis
Locate what is genuinely reachable: broker records, property filings, credential reuse, carrier weaknesses, geotagged imagery, and routine predictability.
Weakness and vulnerability analysis
Build an attack tree for each credible threat, then have our offensive practice walk it. Paths are demonstrated end to end, not asserted in a table.
Attack modelling and simulation
Sequence countermeasures by risk reduced per dollar. Deliver a roadmap with a named owner for every item and a written residual risk position.
Risk analysis and management
An adversary picture has a shelf life. Managed engagements re-run stages four through seven quarterly, so the model tracks a moving threat rather than freezing a moment.
Continuous cycle
Threat library
Every principal is scored against the same library, so exposure is comparable across an executive team and over time. Which classes are credible — and in what order — is what stage four decides.
Aggregated public record released to mobilise a crowd against the principal.
Home identified and then physically visited, watched, or served.
Sustained individual attention escalating toward contact.
Leverage discovered or manufactured, then monetised under deadline.
Reused or breached credentials into personal email, cloud, or finance.
The mobile number ported away to defeat SMS second factors.
Cloned voice or video used to authorise a payment or unlock access.
The principal’s identity worn to instruct their own staff.
Pressure applied to staff or family as the route to the principal. Modelled so it can be hardened.
Itinerary predictability weighed against destination risk.
Relatives’ oversharing as the path of least resistance.
Litigation, competitive, or activist research operations targeting the principal.
Collection boundaries
A threat model of a person is only defensible if its collection is. These constraints are contractual rather than aspirational, and we put them in front of your counsel before anything is signed — reviewed against GLBA, FCRA, and applicable state anti-doxxing and stalking statutes.
Deliverables
Engagement tiers
One principal, one model. The full seven-stage engagement delivering the threat model, treatment roadmap, and executive briefing.
3–4 weeksBaseline plus continuous exposure monitoring, broker suppression, takedown support, and a quarterly re-model as the threat picture moves.
Annual, quarterly cycleBoard and executive team together. Each principal’s findings stay confidential to them; the CISO receives aggregate exposure reporting only.
Scoped per headcountWhy VerSprite
PASTA was co-created by our founder, Tony UcedaVélez, and is used globally for risk-centric threat modelling. Extending it to a human principal is done here by the people who defined the stages — and validated by the same offensive practice that runs our red teams.
Also in Defenders
FAQ
Removal services delete records. A Principal Threat Model starts by establishing which adversaries are actually motivated to reach a specific individual, then works out which exposures matter to those adversaries. Removal becomes one countermeasure among many, sequenced by risk reduced rather than applied indiscriminately.
Yes. Written authorisation from the principal precedes any collection, without exception. We do not accept engagements to profile an individual who has not authorised it — including engagements commissioned by their employer.
Only if the principal directs it in writing. Findings belong to the principal. In cohort engagements across a board or executive team, each principal’s individual findings stay confidential to them, and the CISO receives aggregate exposure reporting.
Political affiliation and voting records, religious belief, health and medical data, sexual orientation, immigration status, and other protected-class attributes are out of scope by policy. None of it reduces risk to the principal, and all of it creates legal exposure for everyone involved.
A baseline model for a single principal runs three to four weeks from signed authorisation to executive briefing. Managed engagements continue on a quarterly re-model cycle.
The same seven stages, re-scoped. Because VerSprite co-created PASTA, the mapping from an application’s attack surface to a person’s footprint, household, and trust circle is done by the people who defined the stages in the first place.
Most programmes begin with a single executive — usually the one whose exposure is already keeping someone awake. Bring a consenting principal and we will scope stages one through three on the first call.