Threat modelling a biotech lab-data platform
Identified nine design-level risks in a biotech's lab-data platform before build.
9
Problem, approach, and the outcome
The client is a UK biotech designing a new platform to hold irreplaceable research data and intellectual property. This is the kind of asset that cannot simply be restored from backup if it leaks.
They understood that the most expensive security mistakes get baked into architecture, and wanted those risks surfaced while they were still cheap to change.
A new platform would hold irreplaceable research data and intellectual property, the kind of asset that cannot simply be restored from backup if it leaks. The value at stake made design-level security critical.
The most expensive security mistakes get baked into the architecture, where they are far costlier to fix after build. Timing was everything.
The biotech wanted those risks surfaced while they were still cheap to change: on the whiteboard, not in production. Catching them early was the whole point.
We ran structured threat modelling alongside the architects, mapping abuse cases and trust boundaries across the proposed design. Working with the architects at design time is what makes mitigations cheap.
Using STRIDE and attack trees, we reasoned systematically about how research IP could be exposed or tampered with. A structured method is what ensures the analysis is thorough, not ad hoc.
Each risk was translated into a concrete design change rather than a future patch, so mitigations became part of the build, and prioritising by impact on research integrity kept the team focused on what genuinely mattered. Security became part of the architecture from the start.
- Nine design-level risks found pre-build
- Research-IP trust boundaries mapped
- Risks resolved as design changes, not patches
- Mitigations built into the architecture from the start
More Cybersecurity case studies

Threat modelling a connected vehicle
Mapped and mitigated attack paths for a UNECE R155-regulated connected vehicle.
Read the full case study
Threat modelling a logistics partner API
Hardened a logistics partner API against abuse before third-party onboarding.
Read the full case study
Red-team engagement against a fintech app
Found and helped close three account-takeover paths before a fintech's launch.
Read the full case studyGet a senior architect on the call, first time, every time.
No SDR gauntlet. 30 minutes with an engineer who can scope the problem, name the risks, and give you an honest feasibility call.
