When you need it
Your team is about to build, or has just built, something that handles sensitive data or payments. Security comes up in pull requests one finding at a time, and nobody has looked at the design as a whole to ask what could go wrong.
What sets the quote
- One system or major feature per workshop, in two half-day sessions with up to 8 participants.
- A standard workshop takes one week and fits a system with up to 5 trust boundaries and 10 integrations.
- Complex systems, with more trust boundaries or integrations or with regulated data such as health or payment data, take up to two weeks.
What changes
- Your team shares one picture of how data moves through the system and where trust changes.
- The threats that matter most are known and ranked before they become incidents or penetration test findings.
- Mitigations sit in your backlog as ordinary work items with owners, not in a report nobody opens.
- The model is kept next to the code, so it can be updated when the design changes.
What you get
- Data-flow diagram with trust boundaries, agreed with your team
- STRIDE threat list with a risk rating for each threat
- Prioritised mitigations written as backlog items in Jira, Azure Boards or GitHub Issues
- The model in OWASP Threat Dragon, or as diagrams as code in your repository
- A two-page summary of the top risks for management
- A short guide to updating the model when the design changes
Run it at design time, before the code is written, or a few weeks before a penetration test so the test targets the riskiest paths. The mitigations can go straight into your own backlog or become a build package.
Not included
- Penetration testing (we can refer you to a certified partner)
- Implementing the mitigations (quoted separately)
- Code review or automated code scanning
What we need from you
- Existing architecture diagrams, API descriptions and data classification, if you have them.
- A 60-minute preparation call with the tech lead or architect of the system.
- Up to 8 participants for both sessions, typically engineers who know the system, the product owner and whoever owns security.
- Permission to create items in your backlog tool, or someone who can import them.
How it works
Free 30-minute call, then a written fixed quote.
Read your documents and draft the data-flow diagram with your tech lead.
First session: confirm the diagram and trust boundaries, then work through STRIDE threats for each element and data flow.
Second session: rate the threats and agree mitigations and owners.
Write up the model and backlog items, and walk your team through them.
At a glance
- Duration
- 1–2 weeks
- Price
- Fixed quote after a free 30-minute call
- Delivered by
- Our lead architect
Related services
Zero Trust assessment
In 1–2 weeks, a review of identity for people, devices and workloads, cloud guardrails and CI/CD, with every control checked as declared, refused and in effect, ending in a maturity rating per area and a roadmap.
OS hardening baseline
Linux and Windows Server hardened to CIS Benchmarks Level 1 in two to six weeks, built as code with golden images, enforced settings, drift checks and compliance evidence for every host.
Vulnerability management setup
Scanning for hosts, containers, Kubernetes, serverless functions and code dependencies, with triage rules, fix deadlines by severity, ticket integration and a weekly report, set up in two to five weeks.