Speakers
Description
In today’s rapidly evolving cyber threat landscape, organisations can no longer rely solely on reactive security measures. Anticipating potential threats is essential, and threat modelling provides a structured way to do this. In this session, we will show how our team integrates threat modelling into the Cyber Threat Intelligence (CTI) reports produced as part of the GEANT GN5-2 project, delivering actionable insights for education and research institutions across Europe.
Threat modelling involves identifying and analysing potential threats, understanding how adversaries may exploit vulnerabilities, and prioritising risks. Rather than remaining a theoretical exercise, our approach uses threat models to produce intelligence that directly supports operational and strategic decision-making.
The presentation will introduce commonly used threat modelling frameworks and tools, including STRIDE, PASTA, and MITRE ATT&CK. These frameworks provide structure and consistency, helping analysts prioritise mitigation strategies and ensure intelligence is relevant and actionable.
We will also cover the threat modelling lifecycle, from threat identification and analysis to validation and ongoing refinement. Testing and revisiting models is critical to maintaining accuracy and alignment with real-world risks, ensuring CTI outputs remain practical and usable by decision-makers.
A central focus of the session will be our practical use of MITRE ATT&CK. ATT&CK offers a detailed view of adversary tactics and techniques, enabling us to map threats to the environments we support. Using examples from GN5-2 CTI reports, we will demonstrate how ATT&CK helps identify likely adversary behaviours, contextualise threats for education and research organisations, and inform mitigation strategies.
We will then discuss how we plan to extend our reporting using MITRE D3FEND and MITRE ATT&CK Flow. D3FEND provides a structured catalogue of defensive techniques, enabling analysts to link observed adversary behaviour directly to relevant countermeasures and strengthen defensive planning. Building on this, ATT&CK Flow allows analysts to visualise attack paths by showing how adversary actions, assets, tools, and conditions connect. We will show how Flow supports hypothesis-driven analysis and helps reason about adversary behaviour even when concrete indicators are limited. Together, these approaches strengthen the connection between threat analysis and practical defensive guidance.
Beyond our own use cases, the session will address how organisations can adopt and adapt these methods themselves. We will explore how ATT&CK, D3FEND, and Flow can serve as building blocks for bespoke threat models tailored to national contexts, sector-specific risks, or constituent communities.
Practical steps for enabling this capability will be outlined, including establishing repeatable modelling processes, aligning models with organisational priorities, and integrating threat modelling into existing CTI and risk management workflows. This approach supports sustainable, continuously improving threat modelling rather than one-off exercises.
By the end of the session, participants will be able to:
- Apply MITRE ATT&CK to CTI reporting for education and research organisations.
- Use D3FEND and ATT&CK Flow to create richer threat context and structured defensive guidance.
- Build attack flows to visualise adversary behaviour and test hypotheses in the absence of concrete indicators.
- Validate and refine threat models to ensure intelligence remains accurate and actionable.
- Design and maintain bespoke threat models tailored to their countries, sectors, or constituent communities.
- Embed threat modelling into their own intelligence activities.
This session is aimed at security practitioners, threat analysts, and decision-makers seeking to move beyond reactive security approaches. By demonstrating how threat modelling can be embedded into intelligence reporting — and scaled for organisational use — we aim to equip participants with practical methods to prioritise threats, understand adversary behaviour, and support informed security decisions across the European education and research sector.