OPSEC & Threat Modeling
Incident response for ordinary people
A calm first-response plan for a stolen device, compromised account, suspicious login or exposed personal information.
Slow down first
An incident creates pressure. Attackers use urgency to keep you from preserving evidence, checking a message, or asking another person for help. Write down what happened, when you noticed it, which device or account was involved, and what you have already changed.
Contain the immediate path
Use a known-clean device to change the most important account password, revoke active sessions, remove unknown recovery methods, and enable stronger authentication. If a device is stolen, use the platform’s lock or erase controls and contact the carrier when the phone number is involved.
Do not delete every message or wipe the affected device before deciding whether evidence is needed. If money, abuse, stalking or an active workplace compromise is involved, contact the relevant bank, platform, employer, or local support service through a verified channel.
Recover and learn
Restore only from backups you trust. Check for new forwarding rules, browser extensions, OAuth apps, administrator accounts and unfamiliar devices. Then update the threat model: what was exposed, what made the event possible, and which control would reduce the chance or impact next time?
Topics
Sources
- Computer Security Incident Handling Guide Accessed
- Account security guidance Accessed
Related guides
-
Guide Intermediate
Account recovery is part of account security (Guide)
How recovery email, phone numbers, codes, trusted devices and support processes can become the weakest path into an account.
-
Guide Intermediate
Secure backups that survive device loss (Guide)
A practical backup plan for recovering important data without turning every copy into an unprotected leak.
-
Guide Introductory
Define Your Threat Model (Guide)
Work out who you are protecting something from before you install anything, using a written, revisable model.