We use cookies to personalize content and to analyze our traffic. Please decide if you are willing to accept cookies from our website.

Threat-Modelling User-to-User Harm in Applications

A technically secure application can still be unsafe for the people using it. CIOs responsible for applications with meaningful user interaction should require a User-Harm Threat Model before launch and whenever interaction functionality materially changes.

Mon., 20. July 2026  |  12 min read

Overview

A technically secure application can still be unsafe for the people using it. Messaging, content sharing, reviews, livestreaming, groups and other legitimate features can be repurposed for harassment, grooming, impersonation, coercion, scams and other user-to-user harms.

CIOs responsible for applications with meaningful user interaction should require a User-Harm Threat Model before launch and whenever interaction functionality materially changes. The objective is not to moderate everything or eliminate all risk. It is to identify foreseeable misuse, apply proportionate controls, assign accountability for what remains, and make an explicit release decision.

What Is Happening

Application security has traditionally concentrated on protecting systems, accounts and data from attackers. That remains essential, but it does not cover situations where a legitimate account uses legitimate application functionality against another legitimate user.

Regulators are increasingly approaching this problem through design and risk assessment rather than relying solely on post-incident moderation. Australia's eSafety …

Tactive Research Group Subscription

To access the complete article, you must be a member. Become a member to get exclusive access to the latest insights, survey invitations, and tailored marketing communications. Stay ahead with us.

Become a Client!

Similar Articles

Designing Safer Applications: Protecting People from People

Designing Safer Applications: Protecting People from People

Software and security engineers usually focus heavily on ensuring their software and web applications are safe from cyber criminals. While this is of utmost importance, it is also crucial to ensure the users of your applications are adequately protected from the potential harms of other users. This article provides an overview of how to design user safety into solutions to protect them from other users with malicious intent.
SEC's New Cybersecurity Disclosure Rule: A Game Changer Now in Effect

SEC's New Cybersecurity Disclosure Rule: A Game Changer Now in Effect

The new SEC Cybersecurity Disclosure Rules have taken effect and seek to mandate public companies, including foreign private issuers, to provide more detailed and uniform disclosures about cybersecurity. C-level IT executives need to understand these updated regulations and adjust their compliance plans accordingly to meet the new standards.