Threat models before tools

Most security programs stall on tooling. Start with the decision an attacker wants, then pick the smallest control that makes that decision expensive.