Threat Modeling for Normal People: Protecting Your Documents Without Paranoia
A plain-language method for deciding which documents need protection, from whom, and which habits and tools genuinely reduce your exposure.
Security advice usually fails in one of two directions. It assumes a journalist facing a nation-state, produces a checklist of seventeen steps nobody follows, and breeds apathy. Or it sells universal paranoia—encrypt everything, trust nothing—and burns people out by week two. Both skip the step professionals never skip: deciding what you are protecting and from whom, before choosing any tools.
That decision process is called threat modeling, and despite the name it needs no jargon to run. Four questions, asked in order, turn vague anxiety into a short list of proportionate habits. This article walks through them for ordinary documents—tax returns, journals, kids’ school forms—the things real people actually hold.
Why advice fails without the first step
Generic hardening checklists ignore context, and context is everything. The person worried about a vindictive ex-partner and the person worried about mass data breaches need almost opposite investments—one targeted, one structural—yet both get told to buy a Faraday bag. Threat modeling flips the order: assets first, adversaries second, only then tools. The payoff is proportionality—you stop paying usability taxes on threats that will never visit you, and start paying attention where exposure is actually live.
Four questions, asked in order
1. What are the assets? List the document categories you hold and rank them honestly by harm-if-leaked: financial loss, embarrassment, coercion, legal trouble, or merely annoyance. Most people end up with three tiers—sensitive (identity numbers, medical records, private journals), moderate (contracts, correspondence), and trivial (receipts). Ranking is the whole game; it converts an undifferentiated pile into a policy.
2. Who plausibly wants them? Name realistic adversaries for your life—not movie ones. An opportunist crawling breached databases, a cloud provider with loose retention habits, a curious employee with database access, a phone thief, occasionally a legal demand. Each adversary implies different defenses; some imply none you can control.
3. Which surfaces connect them? Trace each document’s path: where it was created, which services have copies, how it travels (email attachments, uploads, sync folders), where it rests (laptop, phone, backup drive). Adversaries do not attack documents; they attack surfaces. A tax return stored locally but emailed unencrypted has an email problem.
4. Which mitigations break which connections—at what price? For each live connection, ask what would sever it and what that severing costs daily convenience. Client-side processing removes the upload entirely. Encryption at rest neutralizes a stolen disk. Separate email aliases contain credential spills. Keep the mitigations whose price fits the asset’s tier; skip the rest deliberately rather than accidentally.
The everyday adversary catalog
Honest likelihoods, calibrated for ordinary people rather than high-profile targets:
| Adversary | Realistic likelihood | What limits them |
|---|---|---|
| Bulk breach crawlers | High over time | Minimize uploaded copies, unique passwords |
| Careless cloud retention | Moderate–high | Local-first tools, reading retention policies |
| Insider curiosity | Low per service, nonzero in aggregate | Encrypt before upload or don’t upload |
| Physical theft | Location-dependent | Device encryption, screen locks |
| Targeted intrusion | Very low for most | Professional guidance if genuinely in scope |
The table’s quiet lesson: the adversaries most likely to touch your documents are indifferent ones—scripts harvesting millions of records, retention systems keeping files longer than anyone intended. Defenses against indifferent adversaries tend to be cheap and structural, which is convenient, because they cover most of the real risk.
Three documents, three postures
The four questions produce different answers per document, which is exactly the point.
A tax return with identity numbers. Harm if leaked: years of fraud risk. Plausible adversaries: breach crawlers and careless retention—both mostly reach it through uploads. Surfaces: the software used to prepare it, email to an accountant, cloud backup. Proportionate posture: prepare and assemble locally with client-side tools so no upload happens in the first place (our client-side versus cloud PDF security comparison covers the tool-choice mechanics); send only the specific pages required, encrypted or via a portal the accountant mandates; keep local copies on an encrypted disk. Skip: exotic measures against nation-states.
A personal journal. Harm if leaked: intimate but rarely financial. Plausible adversaries: future breaches of whatever service holds it, plus anyone with physical access to devices. Surfaces: sync services, unlocked devices. Proportionate posture: an encrypted local vault with a strong passphrase—zero-knowledge encryption explained covers why the provider cannot read entries even when a server exists—and tested exports, as described in our offline diary guide. The journal’s protection lives mostly in one good habit, not seven.
A school permission form. Harm if leaked: minimal—a name, a class, a signature. Honest answer: standard handling suffices. Any free tool works; the effort budget belongs elsewhere. Saying this plainly matters, because treating trivial documents like sensitive ones is how security practice collapses under its own weight.
The mitigation ladder
Ordered from cheapest to most involved, each rung states its target and its blind spot:
| Rung | Defeats | Does not defeat |
|---|---|---|
| Unique passwords + a password manager | Credential-stuffing crawlers | Phishing, malware |
| Separate emails for sensitive signups | Cross-service correlation, spill contagion | Any single-service compromise |
| Client-side/local tools for document edits | Upload exposure, retention risk | Device compromise |
| Encrypted containers/vaults at rest | Stolen drives, snooping providers | Keystroke loggers |
| Full-disk encryption + tested backups | Physical theft, ransomware total loss | Online account takeover |
| Specialized guidance | Targeted, high-stakes scenarios | Nothing—this rung is for real adversaries |
Climb only as far as your asset tiers justify. A person whose most sensitive document is a tax return belongs somewhere around rung three or four; someone keeping a decade of intimate journals earns value from every rung above it.
Honest limits
Threat modeling cannot fix three realities. Malware defeats everything at once—it operates as you, inside your defenses—which makes browser hygiene and OS updates unglamorous prerequisites rather than optional extras. Phishing steals credentials directly from humans, bypassing every cipher. And compulsion—legal or physical—can extract whatever a passphrase protects, which is why journalists in genuine danger need professional operational security, not blog posts.
Security is also a habit, not a purchase: models go stale as documents and life circumstances change. Revisit yours yearly or after major changes—a new job, a move, a new device family—and adjust rungs accordingly.
Questions people often ask
Is the cloud ever fine?
Constantly—for the right tiers and the right adversaries. Cloud storage with a strong unique password beats most people’s backup hygiene for moderate-tier documents. The failure mode is uploading sensitive-tier material to services whose retention and breach history you have not weighed. Tier first, then choose.
Password manager secure notes versus a dedicated vault?
Password-manager notes suit credentials and short secrets—they inherit the manager’s strong security model. Long-form private writing deserves a dedicated encrypted vault with export capability, because journaling wants different ergonomics than credential lookup, and consolidating everything behind one master password concentrates blast radius.
Should I just encrypt everything and skip the analysis?
Uniform encryption sounds rigorous but usually decays: unlock friction on trivial documents trains people to bypass their own safeguards. Encrypt the tiers where leaks cause harm; let low tiers stay convenient. Proportionality outlasts purity.
How often should I redo this exercise?
Annually is plenty, plus whenever life shifts materially—new household, new job with confidentiality obligations, a breach headline touching a service you actually use. Fifteen minutes with the four questions is enough to catch drift.
The takeaway
Good document security is not a product purchase; it is fifteen minutes of thinking applied honestly. Rank what you hold, name who plausibly wants it, trace how they could reach it, then pay for defenses exactly where connections are live. Do that and you will spend less effort than the paranoid—and be protected better than the careless.
Share this article
Link, preview card, or your favorite app
Instagram has no web share link — save the card, copy the caption, post them together.