A VAST rollout produced a model per system but expert review capacity did not grow - what now?
answer
- Coverage is not assurance
- Production scaled, judgment did not
- Sample by exposure and asset
- Raise the floor of every self-authored model
- Say what modelled does not mean
basics
~20 sSay plainly that a model per system proves production capacity, not security. Stop trying to review every model, sample by exposure and asset value, review recurring threat classes rather than documents, and be explicit with the mandate owner about what modelled does and does not mean.
solid answer
~60 sVAST scales model *production* by delegating it to delivery teams, and nothing about that scales expert *judgment*. When an agency is mandated to hold a current model for every system in its inventory, the predictable end state is a complete inventory of documents that exist to be counted. The principal's job is to refuse the implied equation between coverage and assurance. Practically: triage rather than queue — sample models by exposure and by the asset behind them, and read the crown-jewel ones properly. Raise the floor of what a self-authored model must state — entry points, data held, who can reach it — so that even an unread model still carries the facts triage needs. Judge the programme by what changed in delivery — threats with named owners and closed mitigations — rather than by how many models exist. And say out loud to whoever owns the mandate that full coverage at this depth is a floor, so the next investment argument is about depth, not about more models.
go deeper
Take away one idea: having a threat model for a system is not the same as having examined its threats. Someone has to read the model and act on it before anything is safer.
Be able to explain why review does not scale with production. Teams can author many models in parallel, but judging whether a model found the right threats still needs experienced people, and that number did not change.
Show a workable triage: rank by exposure and by the asset at stake, sample the middle unpredictably, and drive the reviewed threats to owned, closed mitigations rather than filing another comment.
Own the honesty problem. You are expected to tell the mandate owner what modelled does and does not mean, defend breadth as a floor rather than a result, and win funding for a small deep tier instead of promising to review everything.
## The situation A federal agency is required to hold a current threat model for every system in its inventory. A VAST-style rollout delivers exactly that: delivery teams author process-flow application models at scale, the inventory fills in, and the mandate is technically satisfied. Meanwhile the security function has the same number of people it had before. This is the standard second act of any successful scale-first modeling programme, and it is a genuinely open judgment call, which is why it is asked at principal level. ## The mistake to name first The programme has demonstrated **production capacity**, and production capacity is not assurance. A model whose threats no one examined tells you the team drew a diagram. It does not tell you the threats are enumerated, that the important ones were found, or that any of them will be fixed. If you allow the mandate's language — *modelled* — to be read as *assessed*, you have built an artefact that makes the organisation feel covered while changing nothing, and you personally will be the one who signed off on that impression. ## Four moves that actually help **1. Triage instead of queueing.** Trying to review everything at a uniform depth guarantees uniform shallowness and a growing backlog. Rank by two axes the models themselves give you: exposure (does anything unauthenticated reach it) and the asset behind it (money, citizen personal data, credentials, audit truth). Read the top slice properly, sample the middle randomly so nobody can predict which models get looked at, and consciously accept the tail. **2. Raise the floor of the models themselves.** If judgment is the scarce resource, spend some of it once on what a self-authored model is required to state rather than repeatedly on reading finished ones. A required minimum — every entry point, what data the system holds, who can reach it without authenticating, which shared services it depends on — costs the authoring team little and makes an *unread* model useful, because triage can be done from its facts. Weak models usually fail by omitting structure, not by mis-analysing it. **3. Judge the programme by delivery outcomes, not document counts.** The signal that a model was more than paperwork is that something downstream changed: threats carry named owners, mitigations appear and close in the team's own backlog, a design was altered before it shipped. If nothing downstream ever changes, the models are compliance artefacts regardless of how many exist. **4. Be explicit with the mandate owner about the depth ceiling.** Say what a self-authored model is: a structured statement by the builders of what the system is and what they believe can go wrong with it. That is a real and useful floor, especially across an estate nobody previously had a map of. It is not an assessment. Making that distinction in writing is what converts "we are at 100 percent" into a serious argument for funding depth where it matters — and it protects you when an incident lands on a system with a green model. ## The counter-argument, which you should engage rather than dismiss Someone will argue that unreviewed models are worthless and the programme should be cut back to twenty deep assessments. Take it seriously and then answer it. Breadth has two independent values that depth cannot supply: the teams that authored the models thought about their own threats, which sometimes changes a design without any security involvement at all; and the portfolio becomes queryable, which is how you found out which systems deserve depth in the first place. Cutting to twenty deep models restores the old problem — the other systems become unknown again, and unknown is where the surprises are. The right answer is almost never all-breadth or all-depth; it is breadth as a floor with a deliberately funded, deliberately small deep tier. ## What weak answers look like Promising to hire enough reviewers to read everything, which is the same arithmetic failure that motivated scale-first modeling in the first place. Declaring victory on coverage. Or the opposite: rubbishing the whole programme without acknowledging that a mapped estate is worth something. An interviewer at this level is listening for whether you can hold both facts at once — that the coverage is real, and that it is not what the word implies — and whether you will say the second part to the person who owns the mandate.
- How would you sample which models get expert review when you cannot read them all?Two axes the models already supply: exposure — is there an unauthenticated path in from outside — and the asset behind the system, whether that is money, citizen personal data, credentials or audit truth. Read the top slice properly, sample the middle randomly so no team can predict being unread, and knowingly accept the tail. Random sampling matters as much as ranking, because predictable review invites minimum-effort models.
- Someone argues the programme should be cut to twenty deep assessments instead. What is your response?Engage it. Depth finds more per system, but twenty deep models return the rest of the estate to unknown, and the unknown systems are where the surprises live. Breadth also made the teams think about their own threats and made the portfolio queryable, which is how you identified the twenty. Argue for breadth as a floor with a small, explicitly funded deep tier rather than for either extreme.
- What single indicator convinces you the models are more than compliance artefacts?Whether anything downstream changed. Threats carrying named owners and mitigations that appear and close in the delivery team's own backlog — or better, a design altered before it shipped — mean the model did work. Model counts, completion dates and inventory percentages say only that documents were produced on schedule.
Every building in the city now has a fire plan on file. That is worth having, and it is not the same as anyone having walked the stairwells.
saying these in an interview costs you the question
- Equates full model coverage with assurance
- Plans to hire enough reviewers to read everything
- Reports model count as the programme outcome
- Dismisses the whole portfolio as worthless paper
- Reviews every model at the same uniform depth