Threat Modelling · Durham
Threat Modelling in Durham
Threat modelling for Durham organisations, where the exercise is cheapest before anything is built and almost nobody does it then. The output is a set of design decisions rather than a diagram — and once the system exists, those decisions have already been made implicitly and changing them costs considerably more.
Why this comes up
The problem
The architecture is settled and the security review is now proposing changes nobody can afford.
What you get
What we deliver
- The exercise run at design stage where possible, since that is where it pays
- Data flows mapped so trust boundaries are visible rather than assumed
- Threats identified against those boundaries using a structured approach
- Each threat resolved into a decision — mitigate, accept, transfer or avoid
- Accepted risks recorded with an owner and a reason
- The model kept current, because the system will change after it is written
Want this scoped for your business in Durham?
Thirty minutes, no charge, no sales script. You leave with a written summary of what threat modelling would actually involve — whether or not you use us.
Working in Durham
North East
Durham's economy is dominated by its university and cathedral, so the commercial base is small and much of the local demand comes from spinouts and suppliers attached to the institutions rather than from independent industry.
Research spinout software and visitor systems, usually on institutional procurement timelines rather than commercial ones.
Sectors we work with in Durham
- Higher Education
- Tourism & Heritage
- Public Sector
- Retail
- Research
What we work with
Technologies and platforms
- STRIDE
- Data flow diagrams
- OWASP
- Threat modelling tools
Who we work with
Industries we serve
- Financial services
- Healthcare
- SaaS businesses
- Public sector
- Critical infrastructure
Why us
Why Durham businesses choose Asionis
- Projects typically launched within 4–8 weeks
- No long-term contracts required
- All team members UK-based
- Dedicated account manager and development team
- Transparent reporting with monthly performance metrics
- Scalable from startup to enterprise
How we work
- Step 1
Free consultation
A 30-minute call to understand the problem. You keep the written summary either way.
- Step 2
Proposal
Scope, timeline and a fixed price, in writing, before anything starts.
- Step 3
Build
Short cycles with regular check-ins, so you see progress rather than hear about it.
- Step 4
Launch and support
We handle the go-live and stay available afterwards.
Other services in Durham
Looking for the full picture? See our Threat Modelling services, everything we do in Durham or browse everything we do.
Threat Modelling in Durham — common questions
- Why does timing matter so much?
- Because design decisions harden. Choosing where a trust boundary sits costs nothing on a whiteboard and a great deal once services depend on it, so modelling after the build frequently produces findings the team cannot act on within any reasonable budget.
- Is the diagram the deliverable?
- No — the decisions are. A data flow diagram is a means of finding threats, and the output that matters is the list of what you decided to do about each one, including the ones you deliberately accepted and why.
- Do accepted risks need documenting?
- Particularly those. Accepting a risk is a legitimate decision, and recording who accepted it and on what basis is what distinguishes a considered position from an oversight — and it is the record you will want if the risk later materialises.
- How often should it be revisited?
- When the architecture changes materially. A model describing a system that has since gained integrations, changed its data flows or moved to a different platform is describing something else, so revisiting it at meaningful change points keeps it useful.
- Do you work with businesses across County Durham?
- Yes. We are based in Leicester, United Kingdom and work with clients throughout North East, including Durham and the surrounding County Durham area. Most collaboration happens remotely, and we travel for kick-offs and key milestones.
- What kind of Durham businesses do you usually work with?
- Research spinout software and visitor systems, usually on institutional procurement timelines rather than commercial ones. Beyond that we work across Higher Education, Tourism & Heritage, Public Sector, Retail and Research.
- Do you cover the areas around Durham?
- Yes — we work throughout North East, including Newcastle, Sunderland, York. Durham is an urban area of roughly 70,000+, and we take on work across the wider County Durham region rather than the city boundary alone.
Talk to us about Threat Modelling in Durham
A 30-minute call with someone who would actually work on it. No sales script, no obligation.
- Projects typically launched within 4–8 weeks
- No long-term contracts required
- All team members UK-based
- Dedicated account manager and development team
- Transparent reporting with monthly performance metrics
- Scalable from startup to enterprise
