How do you split a threat statement that bundles four separate threats in a refund flow?
answer
- the unit of work, not the sentence
- different owner, different decision
- count the verbs and the assets
- a chain with no standalone loss stays whole
- watch "or" in the actor slot
basics
~10 sSplit wherever two clauses could get different answers — a different owner, a different mitigation, or a different accept-versus-fix decision. Each resulting sentence keeps its own actor, entry point, action, asset and impact.
solid answer
~50 sThe test is not grammatical, it is operational: if two parts of the sentence could end up with a different owner, a different mitigation, or a different decision, they are two threats. A charity refund statement reading "a fundraising coordinator refunds donations to a card they control, edits the reason afterwards, suppresses the donor's confirmation email, and exports the donor list" bundles four: theft of funds, destruction of the ledger's audit truth, removal of the donor's out-of-band signal, and bulk export of donor identities. Each has a different asset and a different answer — dual authorisation on refunds to new instruments, append-only reason notes, alerting on notification suppression, export limits. Bundled, one owner cannot close it and any rating applies ambiguously. The exception is a chain whose steps only cause loss in sequence: that is one threat whose action happens to have several steps.
go deeper
Recognise the tell: an "and" or an "or" joining two different actions or two different actors usually means the sentence is carrying more than one threat.
Be able to perform the split on a bundled sentence and show that each result still names an actor, an entry point, an action, an asset and an impact on its own.
Show the operational reasoning — different owner, different mitigation, different accept-or-fix decision — and demonstrate the restraint not to split a chain whose steps cause no loss individually.
Own the consequence at portfolio scale: bundled statements make a backlog uncountable and let partial fixes read as closures, so granularity is a reporting-integrity issue, not a style preference.
## Why one threat per statement A threat statement is the unit of work in a threat model. It gets an owner, a decision, and eventually a closure. All three break when a sentence carries more than one threat. - **Ownership.** Two clauses often belong to two teams. Bundled, the statement lands on whoever is nearest and the other half is silently orphaned. - **Decision.** Some threats are fixed, some are accepted deliberately, some are pushed to a later release. A compound sentence forces one verdict on several different claims. - **Closure.** "Done" has to mean a specific loss can no longer occur. If the sentence contains four losses, nobody can honestly tick it. - **Mitigation.** Distinct threats usually have distinct answers, and bundling hides that the cheap answer only addresses one clause. ## The worked example A charity donation platform's refund flow. The reviewer is handed: > *A fundraising coordinator could refund donations to a card they control, edit the refund reason afterwards, suppress the donor's confirmation email, and export the donor list — leading to fraud and reputational damage.* The actor is fine and well-bounded: an insider with legitimate refund authority. The rest is four threats and a mood. **Split:** 1. *A fundraising coordinator, through the refund screen, issues refunds for settled donations to a payment instrument they control, moving charity funds to themselves.* Asset: money. 2. *A fundraising coordinator rewrites the refund reason in the case notes after the fact, so the ledger no longer records why funds left.* Asset: audit truth — and note this one exists to defeat the detection of the first. 3. *A fundraising coordinator disables donor confirmation emails in notification settings, removing the donor's out-of-band signal that money moved on their account.* Asset: the detection path itself; impact is that theft runs undetected for a full reporting cycle. 4. *A fundraising coordinator exports the full donor list from the reporting screen, taking donor identity and giving history off-platform.* Asset: personal privacy of donors. Four statements, four answers: dual authorisation for refunds to an instrument not used for the original donation; append-only reason notes with the original preserved; making notification suppression itself an alerted, logged event; volume limits and logging on donor exports. The charity may well fix 1 and 4 this quarter, accept 3 with a compensating monthly reconciliation, and hand 2 to the finance-systems team. None of that is expressible while the four live in one sentence. ## When *not* to split A chain whose steps produce no loss individually is **one** threat. If the coordinator must first create a dummy donor record, then a donation, then refund it — and no step alone moves money — the statement is one threat whose action has three steps. Splitting there produces fragments nobody can own, because "creates a dummy donor record" is not by itself something you would spend a sprint on. The question to ask is always: *would this clause, standing alone, get its own owner and its own decision?* If not, it is detail inside the action, not a separate threat. Similarly, do not split a single loss described twice. "Funds are stolen and the charity loses money" is one impact stated redundantly, not two threats. ## The "or" that hides a split Watch the actor slot specifically. *An insider **or** an external attacker who has phished a coordinator account could issue refunds to a controlled card* looks like one statement and is two. The two actors sit in different positions, have different prerequisites, and are answered differently — dual authorisation helps against both, but phishing-resistant authentication only addresses the second and does nothing about the first. An "or" between actors, or between entry points, is almost always an unsplit statement. ## Review heuristic When reviewing someone else's model, count the **verbs** and the **assets** in each sentence. More than one asset is a near-certain split. More than one verb is a prompt to ask whether each verb, alone, causes a loss. Then check that each resulting sentence still carries all five slots on its own — a split that leaves fragments sharing an implied subject is worse than the bundle, because each fragment now reads as complete when it is not.
- Is a multi-step attack chain one threat or several?One, if no step alone causes a loss. A statement whose action is "creates a dummy donor, raises a donation against it, then refunds it to their own card" is a single threat with a three-step action; splitting it produces fragments nobody would fund or own. Split the moment a step yields its own distinct loss against its own asset.
- The statement says "an insider or a phished account could do this." Do you split it?Yes. The two actors sit in different positions with different prerequisites, and the answers diverge — dual authorisation helps against both, but phishing-resistant authentication does nothing about the genuine insider. An "or" in the actor or entry-point slot is nearly always two statements that were never separated.
- What do you do with two clauses that share an action but hit different assets?Split them. Same action, two assets means two losses, and the losses may be owned and decided differently — one may be accepted while the other is fixed. Repeat the shared actor, entry point and action verbatim in both sentences; the duplication costs nothing and each statement must stand alone.
A bug tracker ticket that says "login is broken, and also the export is slow, and the emails look wrong" gets closed when someone fixes one third of it. Threat statements fail the same way for the same reason.
saying these in an interview costs you the question
- Joins threats with "and" so no single owner can close it
- Leaves "insider or outsider" sitting in the actor slot
- Splits an attack chain into fragments with no standalone loss
- Treats splitting as cosmetic tidying rather than making it ownable
- Leaves split fragments sharing an implied subject and no asset