DREAD
Version 1.0.0 · Updated 2026-07-30
CORE DEFINITION
A threat assessment model developed by Microsoft for quantifying security risks, consisting of five dimensions: - D (Damage): the extent of damage - how much loss is caused if the attack succeeds; - R (Reproducibility): how easily the attack can be repeated; - E (Exploitability): how much skill/resources are needed to launch the attack; - A (Affected users): how many users are affected; - D (Discoverability): how easily the vulnerability can be discovered. Scoring method: each dimension is scored from 1 to 10, and the higher the total score, the greater the risk.
SCAFFOLDING EFFECT
Reduce cognitive load
- Threat model: developed by Microsoft to quantify security risk across five dimensions. - Dimensions: Damage, Reproducibility, Exploitability, Affected users and Discoverability, each scoring how severe or how easy the attack is. - Scoring: rate every dimension from 1 to 10, and the higher the total, the greater the risk.
Anchor fast decisions
A threat assessment model developed by Microsoft that quantifies security risks using five dimensions: Damage, Reproducibility, Exploitability, Affected users, and Discoverability. Each dimension is scored from 1 to 10, and the higher the total score, the greater the risk. The mechanism is to transform vague 'dangerous or not' into comparable scores.
MINIMUM ACTION
In progress 0/4Practice this model in one real situation:
account_treeGenealogyexpand_more
menu_bookReferencesexpand_more
Source support: Explicit
- en.wikipedia.orghttps://en.wikipedia.org/wiki/Dreadverified
PRIVATE NOTES · Only visible to you
SAVED Q&A
ENTRY Q&A · Private saving available
Ask with a clear boundary
thinkingmodels answers from published entry context only.
Your question is sent to thinkingmodels. The answer uses public entry context only.
RELATED MODELS