threat-modeling.sgit.ai / papers / Threat Models as Mandatory Disclosures
Threat Models as Mandatory Disclosures
Security suffers a market-for-lemons problem — vendors know far more about their product's security than buyers do — and the proposed fix is to make threat-model publication a regulatory requirement, the way financial statements and food-ingredient labels are mandated.
What it argues
- The market-for-lemons diagnosis: inferior security offerings thrive and outcompete higher-quality ones because buyers cannot tell the difference from the outside.
- The correction: a published threat model as a reliable signal of security quality — concrete evidence of the threats a company has considered and mitigated, substantiating claims that today are often vague or unverified.
- Historical parallels, a maturity roadmap, stakeholder impacts and practical steps toward the regime the paper argues for.
- The reflexive test this site is built to pass: a site arguing that threat models should be mandatory disclosures is judged by whether it discloses its own — see /disclosure/ and /practice/, which are written to answer each other.
What checks it
This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.