Most security advice is written for someone who is not you, and the reason it feels unhelpful is that it is, in fact, unhelpful for your specific situation. The advice is written for the median enterprise, the median small business, the median home user, the median developer, and the median is nobody. The advice that is right for the median is wrong for the outliers, which is most of the people actually reading the advice, and the gap between the advice and the situation sits as where the confusion lives.
Take the standard advice to enable multi factor authentication. The advice is correct, the advice is important, and the advice runs as the single most effective security control most organisations have ever deployed. The advice is also useless to the person whose multi factor authentication gets bypassed by the attacker who called the carrier and did a SIM swap. The advice is useless to the person whose multi factor authentication becomes the push notification they tap without reading because they get 30 of them a day. The advice is useless to the person whose multi factor authentication is on a phone that is six years old and does not get security updates. The advice is correct in the median case and wrong in the specific case, and the specific case sits as the case that matters.
What your threat model actually is
Your threat model stands as the answer to three questions. The first is what am I protecting, which amounts to the data, the systems, the access, the money, the reputation, the thing you actually need to keep safe, the thing the standard advice never asks you to enumerate. The second is what am I protecting it from, which serves as the attacker, the accident, the insider, the natural disaster, the threat the standard advice lumps together as bad guys, the threat that has very different defences depending on which threat you actually face. The third is what am I willing to give up, which serves as the convenience, the cost, the friction, the trade-off the standard advice assumes you are willing to make in one direction, the trade-off that looks very different when the trade-off is your trade-off to make.
Why the standard advice still gets taught
Three reasons, in roughly that order of how much each one matters. The first is that the median advice is right in the median case, which is most of the cases, which is enough to justify teaching the median advice to most of the people, most of the time. The second is that the specific advice is hard to write, which counts as the long tail of threat models the long tail of advice would need to address, the long tail that does not fit on a blog post, the long tail that needs an actual conversation between an advisor and the person being advised. The third is that the marketing is easier, which becomes the checklist the vendor can put on the website, the 10 steps the user can scan in 90 seconds, the simplification the user has been demanding, the simplification the security industry has been providing because the simplification sells.
How to find the advice that is right for you
Three moves if you are the person that has been reading the standard advice and finding the standard advice does not quite fit. Skip the headline, where the headline stands as the clickbait, the 10 steps, the 5 rules, the headline that promises to solve the problem in 90 seconds, the headline that almost never applies to the specific case the user is in. Read the threat model section, where the threat model amounts to the part the writer almost always skips, the part the writer assumes is obvious, the part the user has to read carefully to figure out whether the writer is writing for the user or for someone else. Talk to a person that has your specific situation, where the specific situation serves as the role, the stack, the budget, the constraints, the conversation the user has with the person that has been through the same situation, the conversation the user cannot get from the blog post. The person that does the three finds the advice that fits. The person that follows the headline serves as the person that implements the wrong defence for the wrong threat and feels busy about it.

The bottom line
The patterns the post covers have been showing up in production for long enough that the patterns have names, the failures, the mitigations, the gaps. The work the security team and the engineering team and the operations team are quietly doing today sits as the work that decides whether the practice the post names sits as a tool the team uses or a liability the team is paying for.
Sources & Further Reading
All claims in this article are sourced from primary documentation, vendor advisories, and reputable security researchers.
Spotted an error? Email the editor. Corrections are issued with a visible correction note.
Editorial standards. Every article on humanrequired.org is reviewed by a human editor before publication. AI may assist with drafting or research; final editorial control is human. Read the full standards.


