Course overview
The best time to find a security weakness is before an attacker does. Threat modeling and risk assessment provide a disciplined way to do that: mapping how a system could be attacked, judging how likely and damaging each threat is, and directing defense to where it matters most. This course gives security professionals the frameworks and methods to do this rigorously.
Participants move from the concepts of threats, vulnerabilities, and risk through established threat-modeling frameworks such as STRIDE and MITRE ATT&CK, then into recognized risk-assessment standards including the NIST Cybersecurity Framework, ISO/IEC 27005, and the FAIR model for quantitative analysis. The course closes on quantifying, reporting, and embedding risk assessment into security strategy.
Why this matters
Security spending is wasted when it is not aimed at real risk. Threat modeling exposes how systems actually fail, and structured risk assessment translates that into priorities and, increasingly, into financial terms that executives act on. Professionals who can model threats and quantify risk make security decisions defensible, work that pairs with the Building a Cybersecurity Strategy for Enterprises course.
What you will be able to do afterwards
By the end of the course, participants will be able to:
- Explain the role of threat modeling in cybersecurity.
- Apply frameworks such as STRIDE, attack trees, and MITRE ATT&CK.
- Use standards including the NIST CSF, ISO/IEC 27005, and FAIR.
- Quantify cyber risk and translate it into business impact.
- Embed threat modeling and risk assessment into strategy.
Course outline
Unit 1: Introduction to threat modeling and risk assessment
The unit sets out the core concepts.
- The role of threat modeling in cybersecurity.
- Key concepts of risks, vulnerabilities, and threats.
- Case studies of failures and successes.
- An overview of frameworks and approaches.
Unit 2: Frameworks for threat modeling
Participants examine structured modeling methods.
- The STRIDE and DREAD models.
- Attack-tree methodology.
- MITRE ATT&CK for mapping adversary tactics.
- A worked threat-modeling example.
Unit 3: Cyber risk assessment standards
The unit covers recognized risk frameworks.
- The NIST Cybersecurity Framework.
- ISO/IEC 27005 risk management.
- The FAIR model for quantitative risk analysis.
- A guided risk-assessment walkthrough.
Unit 4: Quantifying and reporting cyber risks
Participants study turning risk into decisions.
- Translating risk into financial impact.
- Probability, impact, and prioritization.
- Building heat maps and dashboards.
- Reporting risk to executives and boards.
Unit 5: Integrating threat modeling into strategy
The closing unit embeds the practice.
- Embedding risk assessment into enterprise security.
- Continuous monitoring and reassessment.
- Future challenges in threat modeling.
- Building a proactive defense roadmap.
How the course is delivered
The course combines structured teaching with worked examples, documented cases, and guided walkthroughs of threat-modeling and risk-assessment frameworks. Participants reason through modeling and quantification on realistic systems, so the methods transfer to their own work. The course is educational and does not provide a live lab or a security certification.
Who should attend
The course suits security architects and analysts, risk and compliance professionals, developers concerned with secure design, and technical managers responsible for security risk. A basic grounding in security concepts is helpful.
About EuroQuest International Training
EuroQuest International Training is an international training provider founded in 2015, with a catalog of more than 1,000 courses delivered to over 15,000 participants. Headquartered in Bratislava, EuroQuest runs courses across a network of European and regional training hubs and focuses on practical, current, and professionally relevant content.
Frequently asked questions
Which frameworks does the course cover?
It covers widely used threat-modeling frameworks such as STRIDE, attack trees, and MITRE ATT&CK, and risk-assessment standards including the NIST Cybersecurity Framework, ISO/IEC 27005, and the FAIR model, as educational subject matter.
Does it cover quantitative risk analysis?
Yes. A full unit addresses quantifying cyber risk, including the FAIR model and translating risk into financial impact, since executives increasingly expect risk expressed in business terms.
Does the course include a live lab?
No. It builds understanding through worked examples and guided walkthroughs rather than a live lab. It is educational and prepares you to apply threat-modeling and risk methods, not a certification.
Related courses
- Advanced Network Security and Threat Prevention
- Cybersecurity Analytics and Threat Intelligence
- Cyber Risk Quantification and Investment Strategies
- Cybersecurity Governance and Risk Compliance
Register for this course
To reserve a place or request an in-house session for your team, contact EuroQuest International Training and our team will help you confirm dates and details.
All Course Dates & Locations
29 dates · 17 cities · Oct 2026 – Jul 2027