Engineering
Minimalist dark 3D sovereign shield monolith with lavender and amber rim lighting on stepped plinth
• • 8 min read

Threat Modeling for Normal People: Protecting Your Documents Without Paranoia

A plain-language method for deciding which documents need protection, from whom, and which habits and tools genuinely reduce your exposure.

Security advice usually fails in one of two directions. It assumes a journalist facing a nation-state, produces a checklist of seventeen steps nobody follows, and breeds apathy. Or it sells universal paranoia—encrypt everything, trust nothing—and burns people out by week two. Both skip the step professionals never skip: deciding what you are protecting and from whom, before choosing any tools.

That decision process is called threat modeling, and despite the name it needs no jargon to run. Four questions, asked in order, turn vague anxiety into a short list of proportionate habits. This article walks through them for ordinary documents—tax returns, journals, kids’ school forms—the things real people actually hold.

Why advice fails without the first step

Generic hardening checklists ignore context, and context is everything. The person worried about a vindictive ex-partner and the person worried about mass data breaches need almost opposite investments—one targeted, one structural—yet both get told to buy a Faraday bag. Threat modeling flips the order: assets first, adversaries second, only then tools. The payoff is proportionality—you stop paying usability taxes on threats that will never visit you, and start paying attention where exposure is actually live.

Four questions, asked in order

1. What are the assets? List the document categories you hold and rank them honestly by harm-if-leaked: financial loss, embarrassment, coercion, legal trouble, or merely annoyance. Most people end up with three tiers—sensitive (identity numbers, medical records, private journals), moderate (contracts, correspondence), and trivial (receipts). Ranking is the whole game; it converts an undifferentiated pile into a policy.

2. Who plausibly wants them? Name realistic adversaries for your life—not movie ones. An opportunist crawling breached databases, a cloud provider with loose retention habits, a curious employee with database access, a phone thief, occasionally a legal demand. Each adversary implies different defenses; some imply none you can control.

3. Which surfaces connect them? Trace each document’s path: where it was created, which services have copies, how it travels (email attachments, uploads, sync folders), where it rests (laptop, phone, backup drive). Adversaries do not attack documents; they attack surfaces. A tax return stored locally but emailed unencrypted has an email problem.

4. Which mitigations break which connections—at what price? For each live connection, ask what would sever it and what that severing costs daily convenience. Client-side processing removes the upload entirely. Encryption at rest neutralizes a stolen disk. Separate email aliases contain credential spills. Keep the mitigations whose price fits the asset’s tier; skip the rest deliberately rather than accidentally.

The everyday adversary catalog

Honest likelihoods, calibrated for ordinary people rather than high-profile targets:

AdversaryRealistic likelihoodWhat limits them
Bulk breach crawlersHigh over timeMinimize uploaded copies, unique passwords
Careless cloud retentionModerate–highLocal-first tools, reading retention policies
Insider curiosityLow per service, nonzero in aggregateEncrypt before upload or don’t upload
Physical theftLocation-dependentDevice encryption, screen locks
Targeted intrusionVery low for mostProfessional guidance if genuinely in scope

The table’s quiet lesson: the adversaries most likely to touch your documents are indifferent ones—scripts harvesting millions of records, retention systems keeping files longer than anyone intended. Defenses against indifferent adversaries tend to be cheap and structural, which is convenient, because they cover most of the real risk.

Three documents, three postures

The four questions produce different answers per document, which is exactly the point.

A tax return with identity numbers. Harm if leaked: years of fraud risk. Plausible adversaries: breach crawlers and careless retention—both mostly reach it through uploads. Surfaces: the software used to prepare it, email to an accountant, cloud backup. Proportionate posture: prepare and assemble locally with client-side tools so no upload happens in the first place (our client-side versus cloud PDF security comparison covers the tool-choice mechanics); send only the specific pages required, encrypted or via a portal the accountant mandates; keep local copies on an encrypted disk. Skip: exotic measures against nation-states.

A personal journal. Harm if leaked: intimate but rarely financial. Plausible adversaries: future breaches of whatever service holds it, plus anyone with physical access to devices. Surfaces: sync services, unlocked devices. Proportionate posture: an encrypted local vault with a strong passphrase—zero-knowledge encryption explained covers why the provider cannot read entries even when a server exists—and tested exports, as described in our offline diary guide. The journal’s protection lives mostly in one good habit, not seven.

A school permission form. Harm if leaked: minimal—a name, a class, a signature. Honest answer: standard handling suffices. Any free tool works; the effort budget belongs elsewhere. Saying this plainly matters, because treating trivial documents like sensitive ones is how security practice collapses under its own weight.

The mitigation ladder

Ordered from cheapest to most involved, each rung states its target and its blind spot:

RungDefeatsDoes not defeat
Unique passwords + a password managerCredential-stuffing crawlersPhishing, malware
Separate emails for sensitive signupsCross-service correlation, spill contagionAny single-service compromise
Client-side/local tools for document editsUpload exposure, retention riskDevice compromise
Encrypted containers/vaults at restStolen drives, snooping providersKeystroke loggers
Full-disk encryption + tested backupsPhysical theft, ransomware total lossOnline account takeover
Specialized guidanceTargeted, high-stakes scenariosNothing—this rung is for real adversaries

Climb only as far as your asset tiers justify. A person whose most sensitive document is a tax return belongs somewhere around rung three or four; someone keeping a decade of intimate journals earns value from every rung above it.

Honest limits

Threat modeling cannot fix three realities. Malware defeats everything at once—it operates as you, inside your defenses—which makes browser hygiene and OS updates unglamorous prerequisites rather than optional extras. Phishing steals credentials directly from humans, bypassing every cipher. And compulsion—legal or physical—can extract whatever a passphrase protects, which is why journalists in genuine danger need professional operational security, not blog posts.

Security is also a habit, not a purchase: models go stale as documents and life circumstances change. Revisit yours yearly or after major changes—a new job, a move, a new device family—and adjust rungs accordingly.

Questions people often ask

Is the cloud ever fine?

Constantly—for the right tiers and the right adversaries. Cloud storage with a strong unique password beats most people’s backup hygiene for moderate-tier documents. The failure mode is uploading sensitive-tier material to services whose retention and breach history you have not weighed. Tier first, then choose.

Password manager secure notes versus a dedicated vault?

Password-manager notes suit credentials and short secrets—they inherit the manager’s strong security model. Long-form private writing deserves a dedicated encrypted vault with export capability, because journaling wants different ergonomics than credential lookup, and consolidating everything behind one master password concentrates blast radius.

Should I just encrypt everything and skip the analysis?

Uniform encryption sounds rigorous but usually decays: unlock friction on trivial documents trains people to bypass their own safeguards. Encrypt the tiers where leaks cause harm; let low tiers stay convenient. Proportionality outlasts purity.

How often should I redo this exercise?

Annually is plenty, plus whenever life shifts materially—new household, new job with confidentiality obligations, a breach headline touching a service you actually use. Fifteen minutes with the four questions is enough to catch drift.

The takeaway

Good document security is not a product purchase; it is fifteen minutes of thinking applied honestly. Rank what you hold, name who plausibly wants it, trace how they could reach it, then pay for defenses exactly where connections are live. Do that and you will spend less effort than the paranoid—and be protected better than the careless.

ADVERTISEMENT
SPREAD THE WORD

Found this guide helpful? Share it with your team & network.

ADVERTISEMENT
Author

Author

Verified

Engineer at Anirone, building Awesome Crate — free browser tools that keep your files on your device — and writing about how they work.