# Threat modeling: end with testable decisions

https://thiago.limaesilvatecnologia.com.br/en/artigos/threat-model-decisions/

Published: 2026-09-12

Useful diagrams connect threats to actions and owners.

Content produced with AI assistance for Thiago Silva’s website. Independent editorial analysis; it does not represent clients or employers.

Reading-path month: August 2026

Collection published on September 12, 2026. Months organize the reading path; they are not earlier publication dates.

A short architecture article. The technical reference supports the topic; hypothetical scenarios and assessment proposals are editorial analysis, not accounts of personal implementations.

## The architecture decision

Modeling sessions can generate good discussion but little product change. Convert risks into decisions engineering can implement and verify.

## Practical application

Editorial proposal: select a bounded journey and map data, participants and boundaries. For a hypothetical export, prioritize a few clear-impact abuse scenarios rather than every imaginable risk.

## How to verify

Record failure condition, control, owner and acceptance evidence per decision. Revisit when flows change. Maintain decision history explaining why controls exist and when their assumptions no longer hold.

## Sources

- [OWASP — Threat Modeling Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html). Accessed: 2026-09-12.

[Profile: Thiago Silva | Cyber Architect](https://thiago.limaesilvatecnologia.com.br/en/perfil/)
