โ† Security by Design ยท Lesson 4 of 4

Module Three

๐Ÿ“– Every lesson in this course is free to read right here, no account needed. Create a free account to track your progress, take the exam, and earn your certificate.
1

Course Outline

Security by Design ยท Course Outline

๐Ÿ—๏ธ Security by Design

Course Outline ยท Beginner Friendly ยท 2026


๐Ÿ“˜ Course Overview

This short course teaches you how to build security into a system from the very beginning. You will learn why it is better to plan for safety first instead of fixing problems later. No technical experience needed.


๐Ÿ“‹ Course Details

Item Details
Level Beginner
Duration 2 weeks ยท 2โ€“3 hours per week
Modules 3 modules + 1 final project
Tools Pen and paper (a computer is optional)
Certificate Yes, after the final project

๐Ÿ“š Module Count

This course contains 3 modules plus a final project.


๐ŸŽฏ What You Will Learn

  • What Security by Design means
  • Why planning for safety first matters
  • The main principles of secure design
  • How to think about threats before building
  • How to design simple, safe systems
  • How to explain Security by Design to others

๐Ÿ“š Course Modules

Module 1 โ€” What is Security by Design?

Learn what Security by Design means and why it matters for every project.

Topics

  • What is Security by Design?
  • Building security in from the start
  • The cost of fixing security later
  • Real-life examples of good and bad design
  • Why everyone can use Security by Design

Learning Outcome

Explain Security by Design and why it matters in simple words.


Module 2 โ€” Principles of Secure Design

Learn the main rules that make a system safe from the very beginning.

Topics

  • Keep it simple
  • Least privilege (give only what is needed)
  • Defence in depth (many layers)
  • Fail safely
  • Do not trust input
  • Keep it open (no secrets in the design)

Learning Outcome

Name and explain at least four principles of secure design.


Module 3 โ€” Thinking About Threats and Building Safely

Learn how to think about threats early and build systems that stay safe.

Topics

  • What is a threat model?
  • Asking "what could go wrong?"
  • Planning for mistakes and attacks
  • Testing your design before building
  • Keeping systems safe after they are built

Learning Outcome

Create a simple threat model for a small project.


๐Ÿ† Final Project โ€” Design a Safe System

Choose a simple system (for example, a school portal, a small shop, or a family budget app). Write a short plan that explains:

  1. What the system does
  2. Who will use it
  3. What could go wrong
  4. How you will protect it from the start
  5. Which design principles you will use

Present your plan to a friend, teacher, or family member. This becomes your portfolio piece.


๐Ÿ’ก Why Take This Course?

  • It is short and easy to follow.
  • No technical experience needed.
  • You will think more clearly about safety.
  • It prepares you for more advanced cybersecurity courses.

โœ… By the End of This Course

  • You will know what Security by Design means.
  • You will know the main principles of secure design.
  • You will know how to think about threats.
  • You will know how to plan a safe system.
  • You will have a written plan for a safe system.

โžก๏ธ What Comes Next?

After this course, you can continue to Introduction to Secure Coding, where you will learn how to write code that follows Security by Design principles.


Security by Design ยท Course Outline

Beginner Friendly ยท 2026

2

Module One

Module 1 ยท What is Security by Design?

โฌ… Back to Course Outline

๐Ÿ—๏ธ Module 1 โ€” What is Security by Design?

Security by Design ยท Beginner Level ยท 2026


1. Module Introduction

Welcome to the first module of Security by Design. This is the start of a very important journey. By the end of this module, you will understand what Security by Design means and why it matters for every project.

Have you ever built a house with cardboard? You start with a plan. You decide where the walls will go. You decide where the door will be. You decide how strong the roof should be. You do all of this before you build anything.

Security by Design means planning for safety from the very beginning. It means thinking about what could go wrong before you build, and building in a way that stops problems from happening.

Imagine building a house without planning for a lock. You finish the house and then realise there is no place for a lock on the door. Now you must break the door to add one. That is what happens when we do not think about security first.

In this module, you will learn what Security by Design means. You will learn why planning for safety first is much better than fixing things later. You will also see examples from real life, school, home, and Nigeria.

This module is written for complete beginners. You do not need to know any coding. Every new word is explained in very simple language. So relax, read slowly, and let us begin.

YOUR LEARNING JOURNEY IN MODULE 1
=================================

[ Start ]
    |
    V
What is Security by Design?
    |
    V
Building Security In from the Start
    |
    V
The Cost of Fixing Security Later
    |
    V
Real-Life Examples
    |
    V
Why Everyone Can Use It
    |
    V
[ You understand Security by Design! ]

Summary of the Introduction

This module introduces Security by Design. You will learn what it means, why it matters, and how it saves time, money, and stress. Everything is explained in simple language with plenty of examples.


2. Learning Objectives

By the end of this module, you will be able to:

  1. Explain what Security by Design means in your own words.
  2. Describe why building security in from the start is important.
  3. Explain the cost of fixing security later.
  4. Give real-life examples of good and bad design.
  5. Describe why everyone can use Security by Design.
  6. Identify simple places where security should be planned.
  7. Explain what happens when security is forgotten.
  8. Describe how Security by Design saves money and time.
  9. Give examples from school, home, and Nigeria.
  10. Feel confident and curious to continue to Module 2.

Summary of Learning Objectives

You will learn what Security by Design is, why it matters, and how it saves time, money, and stress.


3. Warm-up Story โ€” Chidi Builds a Clubhouse

Chidi is a 12-year-old boy who lives in Lagos. He loves building things. One Saturday, he decided to build a small clubhouse in the backyard.

Chidi was excited. He ran to the backyard with wood, nails, and a hammer. He started building immediately.

He built the walls. He built the roof. He built a small door. It looked wonderful. Chidi was very proud of his clubhouse.

But that night, it rained heavily. The next morning, Chidi ran to the backyard. The clubhouse was ruined. The roof had leaked. The walls had fallen. The wood was wet and broken.

His father came out. "Chidi, what happened?"

"The rain destroyed it, Papa," Chidi said sadly.

"Did you plan the clubhouse before you built it?" his father asked.

"No, Papa. I just started building."

His father smiled gently. "That is the problem. You did not plan for the rain. If you had planned first, you would have used stronger wood. You would have made a better roof. You would have placed the clubhouse on higher ground."

Chidi understood. "So I should have thought about the rain before I built it."

"Exactly," his father said. "That is what Security by Design means. Think about the problems before you build. Then build so the problems cannot happen."

The next week, Chidi rebuilt the clubhouse. This time, he planned first. He used stronger wood. He built a better roof. He placed it on higher ground. That clubhouse lasted for many years.

CHIDI'S CLUBHOUSE
=================

First try:
  [ Build fast ] -> [ No plan ] -> [ Rain destroyed it ]

Second try:
  [ Plan first ] -> [ Strong materials ] -> [ Safe from rain ]

Summary of the Warm-up Story

Chidi's first clubhouse was destroyed because he did not plan for the rain. His second clubhouse survived because he planned first. This story introduces the whole module.


4. Main Lessons

In this section, you will go through 12 short lessons. Each lesson teaches one big idea. Each lesson ends with a mini summary. Read slowly. Think about the examples. Ask questions. That is how you learn.

Lesson 1 โ€” What is Security by Design?

Definition

Security by Design means planning for safety from the very beginning of any project. It means thinking about what could go wrong before you build.

Why it is important

If you plan for safety first, you save time, money, and stress. If you fix security later, it is harder and costs more.

Simple explanation

Think of building a house. Before you lay the first brick, you decide where the doors, windows, and locks will go. Security by Design is the same for computers, apps, and systems.

Real-life example

A bank plans how to protect money before it opens. It does not wait for a robbery to think about security.

School example

A school plans how to protect student records before creating a portal. It does not wait for a hack.

Home example

Your family plans how to protect the Wi-Fi with a password before strangers connect.

Nigerian example

Nigerian banks plan how to protect customer money before they open online banking.

Illustration

SECURITY BY DESIGN
==================

[ Plan first ]
        |
        V
[ Think about problems ]
        |
        V
[ Build with safety ]
        |
        V
[ System is safe from the start ]

Mini summary

Security by Design means planning for safety from the very beginning. It saves time, money, and stress.


Lesson 2 โ€” Building Security In from the Start

Definition

Building security in from the start means adding safety as you build, not after. It is part of the plan, like a door on a house.

Why it is important

When security is part of the plan, it fits naturally. When it is added later, it may not fit at all.

Simple explanation

Think of baking a cake. You add sugar while mixing. You do not bake the cake first and then try to add sugar. Security works the same way.

Real-life example

A hospital plans how to protect patient records before the system is built.

School example

A school plans passwords and permissions before launching a portal.

Home example

Your family decides on a strong Wi-Fi password before setting up the router.

Nigerian example

Nigerian fintechs plan how to protect money before launching their apps.

Illustration

BUILDING SECURITY IN
====================

[ Plan ] -> [ Build with security ] -> [ Safe system ]

Not:
[ Build ] -> [ Then add security ] -> [ Problems ]

Mini summary

Building security in from the start means making safety part of the plan, not an afterthought.


Lesson 3 โ€” The Cost of Fixing Security Later

Definition

Fixing security later means adding protection after the system is already built. It costs more money, takes more time, and can still leave problems.

Why it is important

Fixing later is like repairing a wall after it collapses. It is much easier to build it strong from the beginning.

Simple explanation

Think of painting a house. It is easy to paint while building. It is very hard to paint after furniture and carpets are in place. Security works the same way.

Why It Costs More

  • You must take apart things you already built.
  • You may need to retrain people.
  • You may lose customers because of a breach.
  • You may have to pay fines or lose money.

Real-life example

A company builds a website without security. Hackers break in. The company spends millions to fix it and loses customers.

School example

A school builds a portal without strong passwords. Students change scores. The school must rebuild the system.

Home example

Your family sets up Wi-Fi without a password. Strangers use the internet. You must change everything.

Nigerian example

Nigerian banks that add security after a breach spend much more than those that plan first.

Illustration

COST OF FIXING LATER
====================

[ Build without security ]
        |
        V
[ Problem happens ]
        |
        V
[ Expensive fix ]
        |
        V
[ Lost time, money, and trust ]

Mini summary

Fixing security later costs more money, takes more time, and can still leave problems.


Lesson 4 โ€” Thinking About What Could Go Wrong

Definition

Thinking about what could go wrong means imagining problems before they happen. It is part of Security by Design.

Why it is important

If you think about problems first, you can plan for them. If you ignore them, they will surprise you.

Simple explanation

Think of going on a trip. You pack an umbrella in case it rains. You pack snacks in case you get hungry. Thinking about problems is the same.

Common Questions to Ask

  • What if someone steals this?
  • What if someone breaks this?
  • What if someone shares this?
  • What if this fails?
  • What if the wrong person sees this?

Real-life example

A bank asks, "What if someone steals a customer's card?" and plans protections before they happen.

School example

A school asks, "What if a student shares their password?" and plans how to reset it.

Home example

Your family asks, "What if someone breaks into the Wi-Fi?" and uses a strong password.

Nigerian example

Nigerian banks ask, "What if a fraudster pretends to be a customer?" and use 2FA.

Illustration

THINK ABOUT WHAT COULD GO WRONG
===============================

[ What if someone steals it? ]
[ What if someone breaks it? ]
[ What if the wrong person sees it? ]
        |
        V
[ Plan for each problem ]
        |
        V
[ System stays safe ]

Mini summary

Thinking about what could go wrong helps you plan for safety before problems happen.


Lesson 5 โ€” Good and Bad Design

Definition

Good design includes safety from the start. Bad design ignores safety until it is too late.

Why it is important

Knowing the difference helps you build better systems and spot problems early.

Simple explanation

Think of two cars. One has airbags and seat belts. The other has none. Both cars can drive, but only one protects you in an accident.

Comparison Table

Good Design Bad Design
Safety planned from start Safety added later
Problems thought through Problems ignored
Costs less to maintain Costs more to fix
Users trust it Users worry about it

Real-life example

A bank app with 2FA is good design. A bank app without any security is bad design.

School example

A school portal with strong passwords is good design. One without is bad.

Home example

A Wi-Fi router with a password is good design. One without is bad.

Nigerian example

Nigerian banks with strong security are good design. Those without lose customer money.

Illustration

GOOD vs BAD DESIGN
==================

Good: [ Plan ] -> [ Build with safety ] -> [ Safe system ]

Bad:  [ Build ] -> [ Ignore safety ] -> [ Problem happens ]

Mini summary

Good design includes safety from the start. Bad design ignores safety until it is too late.


Lesson 6 โ€” Why Security by Design Saves Money

Definition

Security by Design saves money because problems are prevented before they happen.

Why it is important

Every problem that does not happen saves money. Security is cheaper than fixing breaches.

Simple explanation

Think of repairing a roof. Fixing a small leak is cheap. Rebuilding a fallen roof is expensive.

How It Saves Money

  • You do not pay for breaches.
  • You do not lose customers.
  • You do not pay fines.
  • You do not rebuild systems.
  • You do not lose trust.

Real-life example

A bank that plans security first saves millions compared to one that pays for a breach.

School example

A school that plans security saves the cost of rebuilding a hacked portal.

Home example

Your family saves money by preventing strangers from using your Wi-Fi.

Nigerian example

Nigerian banks that plan security save money on fraud recovery.

Illustration

SAVING MONEY
============

[ Plan security first ]
        |
        V
[ No breach ]
        |
        V
[ No lost money ]
        |
        V
[ More profit ]

Mini summary

Security by Design saves money by preventing problems before they happen.


Lesson 7 โ€” Why Security by Design Saves Time

Definition

Security by Design saves time because you do not have to rebuild or repair later.

Why it is important

Time is valuable. Fixing a problem takes much longer than planning for it.

Simple explanation

Think of writing a school essay. If you plan first, you finish faster. If you write without a plan, you must rewrite it many times.

How It Saves Time

  • No emergency fixes.
  • No angry customers waiting.
  • No downtime.
  • No rebuilding from scratch.

Real-life example

A company that plans security does not have to stop work to fix a breach.

School example

A school that plans security does not lose time rebuilding a hacked portal.

Home example

Your family saves time by setting up Wi-Fi correctly the first time.

Nigerian example

Nigerian banks with good planning spend less time responding to incidents.

Illustration

SAVING TIME
===========

[ Plan first ]
        |
        V
[ Build once ]
        |
        V
[ No repairs ]
        |
        V
[ Time saved ]

Mini summary

Security by Design saves time because you do not have to rebuild or repair later.


Lesson 8 โ€” Real-Life Examples of Security by Design

Definition

Real-life examples help us see how Security by Design is used in the world around us.

Why it is important

Seeing real examples helps you understand and remember the idea.

Simple explanation

Think of your school. It has a fence, a gate, and a watchman. These were planned before the school was built.

Real-Life Examples

  • Cars โ€” built with seat belts and airbags.
  • Houses โ€” built with locks and strong doors.
  • Banks โ€” built with vaults and cameras.
  • Websites โ€” built with passwords and 2FA.
  • Phones โ€” built with fingerprint locks.

Real-life example

A car factory plans where to place airbags before the car is built.

School example

A school plans a fence and gate before opening.

Home example

Your family plans where to install locks before moving into a new house.

Nigerian example

Nigerian banks plan their vaults and security systems before opening.

Illustration

SECURITY BY DESIGN EVERYWHERE
=============================

Cars:      Seat belts, airbags
Houses:    Locks, strong doors
Banks:     Vaults, cameras
Websites:  Passwords, 2FA
Phones:    Fingerprint locks

All planned before building.

Mini summary

Security by Design is everywhere โ€” in cars, houses, banks, websites, and phones.


Lesson 9 โ€” Why Everyone Can Use Security by Design

Definition

Security by Design is not only for big companies. Anyone can use it โ€” students, parents, teachers, and small businesses.

Why it is important

Everyone builds or plans something. Everyone can plan for safety.

Simple explanation

Think of a student planning a school project. They plan what to do, what could go wrong, and how to fix it.

Everyone Can Plan

  • Students can plan safe passwords for school portals.
  • Parents can plan safe Wi-Fi for the family.
  • Teachers can plan safe online classrooms.
  • Traders can plan safe payments.
  • Businesses can plan safe systems.

Real-life example

A student plans how to keep their school portal password safe.

School example

A teacher plans how students will log in safely.

Home example

Your family plans how to protect your Wi-Fi and devices.

Nigerian example

A small Nigerian trader plans how to keep customer payments safe.

Illustration

EVERYONE CAN PLAN
=================

[ Student ] -> Safe passwords
[ Parent ]  -> Safe Wi-Fi
[ Teacher ] -> Safe classroom
[ Trader ]  -> Safe payments
[ Business ]-> Safe systems

Mini summary

Anyone can use Security by Design. It is for students, parents, teachers, traders, and businesses.


Lesson 10 โ€” Security by Design in Your Daily Life

Definition

Security by Design is part of your daily life. Every safe habit you have was planned.

Why it is important

Understanding daily examples helps you see the idea everywhere.

Simple explanation

Think of your morning routine. You lock your door, carry your keys, and take your phone. These habits were planned.

Daily Examples

  • Locking the front door when leaving.
  • Keeping your phone in your pocket.
  • Using a PIN on your bank card.
  • Checking the door before opening it.
  • Keeping your wallet close in a crowd.

Real-life example

Your family plans where to keep the spare key โ€” not under the mat.

School example

Your school plans where to keep exam papers โ€” in a locked cupboard.

Home example

Your family plans how to keep the Wi-Fi password private.

Nigerian example

A Nigerian family plans how to keep their gate locked at night.

Illustration

DAILY LIFE
==========

[ Lock the door ]
[ Use a PIN ]
[ Check the door ]
[ Keep wallet close ]
[ Keep Wi-Fi password private ]

All were planned for safety.

Mini summary

Security by Design is part of everyday life. Every safe habit was planned.


Lesson 11 โ€” What Happens When Security is Forgotten

Definition

When security is forgotten, problems happen. Hackers, thieves, and accidents cause damage.

Why it is important

Knowing what happens when security is forgotten helps you plan better.

Simple explanation

Think of a house without a lock. Anyone can walk in. Systems without security are the same.

What Can Happen

  • Money is stolen.
  • Personal information is leaked.
  • Systems crash.
  • Customers lose trust.
  • Businesses close.
  • Families lose savings.

Real-life example

A company loses customer data because it forgot to plan security.

School example

A school's exam questions are leaked because no one planned security.

Home example

Your family's Wi-Fi is used by strangers because no password was set.

Nigerian example

Many Nigerian businesses have closed because of cyber attacks they did not plan for.

Illustration

WHEN SECURITY IS FORGOTTEN
==========================

[ No plan ]
        |
        V
[ No security ]
        |
        V
[ Attack or accident ]
        |
        V
[ Money lost, trust lost ]

Mini summary

When security is forgotten, money is lost, trust is broken, and systems fail.


Lesson 12 โ€” Becoming a Security by Design Thinker

Definition

A Security by Design thinker is someone who always asks "what could go wrong?" before building anything.

Why it is important

This habit protects you, your family, and your projects.

Simple explanation

Think of a careful planner. They always check the weather, the route, and the time before leaving. A Security by Design thinker does the same for projects.

How to Become One

  1. Always ask "what could go wrong?"
  2. Plan for problems before they happen.
  3. Keep things simple.
  4. Do not trust everything.
  5. Teach others the same habit.

Real-life example

A student plans their school project with safety in mind.

School example

A student asks, "What if my password is stolen?" and plans for it.

Home example

Your family asks, "What if a stranger uses our Wi-Fi?" and sets a password.

Nigerian example

A Nigerian trader asks, "What if a customer's payment fails?" and plans a backup.

Illustration

BECOMING A THINKER
==================

[ Ask "what could go wrong?" ]
        |
        V
[ Plan for problems ]
        |
        V
[ Build with safety ]
        |
        V
[ Protect yourself and others ]

Mini summary

A Security by Design thinker always asks "what could go wrong?" before building.


5. Key Vocabulary

Word Simple Definition
Security by Design Planning for safety from the very beginning.
Plan Deciding what to do before doing it.
Design The way something is built or arranged.
Good design Building with safety from the start.
Bad design Ignoring safety until it is too late.
Breach When someone breaks into a system.
Trust When people feel safe using your system.
Risk The chance that something will go wrong.
Thinker Someone who asks good questions and plans well.

Summary of Key Vocabulary

These words are the foundation of Security by Design. Use them often so they become easy.


6. Important Concepts

Concept 1 โ€” Plan Safety First

Think about safety before you build. It is much easier than fixing later.

Concept 2 โ€” Prevention Beats Repair

Preventing a problem is cheaper and faster than repairing it.

Concept 3 โ€” Ask "What Could Go Wrong?"

This question helps you plan for problems before they happen.

Concept 4 โ€” Everyone Can Plan

Students, parents, teachers, and businesses can all use Security by Design.

Concept 5 โ€” Forgotten Security is Expensive

When security is forgotten, money, time, and trust are lost.

Summary of Important Concepts

These five concepts are the heart of Module 1. Read them again before moving on.


7. Step-by-step Explanations

Step-by-step: How to Use Security by Design

  1. Understand what you are building.
  2. Ask "what could go wrong?".
  3. Plan for each problem.
  4. Build with safety in mind.
  5. Test your system.
  6. Review and improve.
USING SECURITY BY DESIGN
========================

[ Understand ] -> [ Ask "what could go wrong?" ]
        -> [ Plan ] -> [ Build safely ]
        -> [ Test ] -> [ Review ]

Step-by-step: Questions to Ask Before Building

  1. Who will use this?
  2. What could go wrong?
  3. Who might try to break it?
  4. What information could be stolen?
  5. How will I protect it?
  6. What will I do if it fails?
QUESTIONS TO ASK
================

[ Who will use it? ]
[ What could go wrong? ]
[ Who might attack it? ]
[ What could be stolen? ]
[ How to protect it? ]
[ What if it fails? ]

Step-by-step: How to Spot Good Design

  1. Was safety planned from the start?
  2. Are there many layers of protection?
  3. Is the system simple?
  4. Does it protect user information?
  5. Can it recover from problems?
SPOTTING GOOD DESIGN
====================

[ Safety planned? ] -> Yes
[ Many layers? ]    -> Yes
[ Simple? ]         -> Yes
[ Protects users? ] -> Yes
[ Recovers? ]       -> Yes

Summary of Step-by-step Explanations

Using Security by Design, asking questions, and spotting good design all follow simple steps. Follow them, and your projects stay safe.


8. Real-life Examples

Example 1 โ€” A Bank

A bank plans where the vault will be before building. It plans where cameras go. It plans how money is protected.

Example 2 โ€” A Hospital

A hospital plans where patient records are stored and who can see them.

Example 3 โ€” A School

A school plans student passwords and permissions before opening a portal.

Example 4 โ€” An Online Shop

An online shop plans how payments are protected before selling anything.

Example 5 โ€” A Government Office

A government office plans how national data is protected from the start.

Summary of Real-life Examples

Security by Design is used in banks, hospitals, schools, shops, and government offices.


9. Nigerian Examples

Example 1 โ€” Nigerian Banks

Banks plan secure vaults, cameras, and 2FA before opening.

Example 2 โ€” Nigerian Fintechs

Fintechs like Paystack plan how payments are protected from the start.

Example 3 โ€” Nigerian Schools

Universities plan how to protect student records before building portals.

Example 4 โ€” Nigerian Government

Agencies like NITDA plan how to protect national systems.

Example 5 โ€” Nigerian Families

Families plan Wi-Fi passwords and PINs before setting up devices.

Summary of Nigerian Examples

Nigeria has many examples of Security by Design in banks, fintechs, schools, government, and families.


10. Fun Examples Children Can Relate To

Example 1 โ€” Building a Sandcastle

A good sandcastle is built on firm ground, with strong walls, and away from the water. That is planning for safety.

Example 2 โ€” Baking a Cake

You plan the recipe, the ingredients, and the temperature before baking.

Example 3 โ€” Playing Football

The coach plans the formation before the match. That is planning for success.

Example 4 โ€” Building with LEGO

You plan the building before putting the bricks together.

Example 5 โ€” Riding a Bicycle

You plan a safe route, wear a helmet, and check the brakes. That is Security by Design.

Summary of Fun Examples

Security by Design is like building a sandcastle, baking a cake, playing football, building with LEGO, and riding a bicycle.


11. Everyday Examples

Situation Security by Design Idea
Locking the door Planning safety before leaving
Setting a Wi-Fi password Planning protection before use
Using a PIN on your card Planning protection for money
Planning a family trip Planning for problems before travelling
Planning a project Planning for safety before building

Summary of Everyday Examples

Even simple daily activities use Security by Design. Now you can see it everywhere.


12. Parent Tips

  1. Ask your child "what could go wrong?" before they start a project.
  2. Plan together. Show how planning saves time and money.
  3. Use examples from home. Locking doors, Wi-Fi passwords, and PINs.
  4. Praise good planning. When your child plans ahead, praise them.
  5. Talk about real-life breaches. Explain how companies lose money.
  6. Be patient. Planning is a habit that takes time.
  7. Encourage curiosity. Ask your child to find examples of good design.
  8. Keep learning. Parents can learn too.

Summary of Parent Tips

Parents can teach Security by Design at home through daily conversations and simple examples.


13. Interesting Facts

  1. Companies that plan security spend 10 times less on breaches.
  2. Cars have been designed with seat belts since the 1950s.
  3. Banks have used vaults and security for centuries.
  4. Modern websites plan 2FA before launching.
  5. Security by Design saves companies millions of dollars.
  6. Small businesses that plan security survive longer.
  7. Nigerian fintechs plan security before launching apps.
  8. Learning Security by Design helps in every career.

Summary of Interesting Facts

Security by Design is powerful and saves money, time, and trust.


14. Did You Know?

  • Did you know that "Security by Design" is a real principle used by companies?
  • Did you know that fixing a bug after launch costs 100 times more than fixing it during design?
  • Did you know that companies that plan security keep customers longer?
  • Did you know that every device you use was planned for safety?
  • Did you know that banks have used planning for security for hundreds of years?
  • Did you know that students can learn Security by Design too?

Summary of Did You Know?

Security by Design is full of surprises. The more you learn, the more useful it becomes.


15. Remember This

  • Security by Design means planning for safety first.
  • Prevention is cheaper than repair.
  • Always ask "what could go wrong?".
  • Good design includes safety from the start.
  • Bad design ignores safety until it is too late.
  • Everyone can use Security by Design.
  • Security by Design saves money.
  • Security by Design saves time.
  • Forgotten security is expensive.
  • Anyone can become a Security by Design thinker.

Summary of Remember This

These ten points are the heart of Module 1. Read them again before moving on.


16. Common Mistakes

  1. Building first, planning later. Plan before you build.
  2. Ignoring "what could go wrong?". This question saves projects.
  3. Thinking security is only for big companies. Everyone can use it.
  4. Thinking it is too expensive. It saves money in the long run.
  5. Forgetting to test. Always test your design.
  6. Adding security at the last minute. It should be part of the plan.
  7. Ignoring small problems. They can become big breaches.
  8. Giving up too soon. Planning takes practice.

Summary of Common Mistakes

Avoiding these mistakes will make you better at Security by Design than many adults.


17. Best Practices

  1. Plan before you build.
  2. Ask "what could go wrong?".
  3. Keep things simple.
  4. Plan many layers of protection.
  5. Test your design before using it.
  6. Review and improve your design.
  7. Teach others the same habit.
  8. Look for examples in daily life.
  9. Start small and grow.
  10. Never stop learning.

Summary of Best Practices

These ten practices will help you build safer systems and safer habits.


18. ASCII Illustrations, Diagrams, Flowcharts, and Timelines

Diagram 1 โ€” Security by Design

SECURITY BY DESIGN
==================

[ Plan first ]
        |
        V
[ Think about problems ]
        |
        V
[ Build with safety ]
        |
        V
[ System is safe from the start ]

Diagram 2 โ€” Building Security In

BUILDING SECURITY IN
====================

[ Plan ] -> [ Build with security ] -> [ Safe system ]

Not:
[ Build ] -> [ Then add security ] -> [ Problems ]

Diagram 3 โ€” Cost of Fixing Later

COST OF FIXING LATER
====================

[ Build without security ]
        |
        V
[ Problem happens ]
        |
        V
[ Expensive fix ]
        |
        V
[ Lost time, money, and trust ]

Diagram 4 โ€” Thinking About Problems

THINK ABOUT WHAT COULD GO WRONG
===============================

[ What if someone steals it? ]
[ What if someone breaks it? ]
[ What if the wrong person sees it? ]
        |
        V
[ Plan for each problem ]
        |
        V
[ System stays safe ]

Diagram 5 โ€” Good vs Bad Design

GOOD vs BAD DESIGN
==================

Good: [ Plan ] -> [ Build with safety ] -> [ Safe system ]

Bad:  [ Build ] -> [ Ignore safety ] -> [ Problem happens ]

Diagram 6 โ€” Becoming a Thinker

BECOMING A THINKER
==================

[ Ask "what could go wrong?" ]
        |
        V
[ Plan for problems ]
        |
        V
[ Build with safety ]
        |
        V
[ Protect yourself and others ]

Summary of Illustrations

These diagrams help you see Security by Design clearly. Draw them yourself to remember them better.


19. Comparison Tables

Table 1 โ€” Good vs Bad Design

Good Design Bad Design
Safety planned from start Safety added later
Problems thought through Problems ignored
Costs less to maintain Costs more to fix
Users trust it Users worry about it

Table 2 โ€” Plan First vs Fix Later

Plan First Fix Later
Cheaper More expensive
Faster Slower
Safer Riskier
Keeps trust Loses trust

Table 3 โ€” Real-Life Examples of Security by Design

Thing Security by Design
Cars Seat belts, airbags
Houses Locks, strong doors
Banks Vaults, cameras, 2FA
Websites Passwords, HTTPS
Phones Fingerprint locks

Summary of Comparison Tables

Comparing ideas side by side helps you remember the differences clearly.


20. Summary After Every Lesson

Lesson Main Idea
Lesson 1 Security by Design means planning safety first.
Lesson 2 Build security in from the start.
Lesson 3 Fixing security later costs more.
Lesson 4 Ask "what could go wrong?".
Lesson 5 Good design plans safety; bad design ignores it.
Lesson 6 Security by Design saves money.
Lesson 7 Security by Design saves time.
Lesson 8 Real-life examples show it everywhere.
Lesson 9 Everyone can use it.
Lesson 10 It is part of daily life.
Lesson 11 Forgotten security is expensive.
Lesson 12 Anyone can become a Security by Design thinker.

21. End-of-Module Summary

Congratulations! You have completed Module 1. Let us review what you have learned.

You began by learning that Security by Design means planning for safety from the very beginning.

You discovered how to build security in from the start โ€” making safety part of the plan.

You learned the cost of fixing security later โ€” more money, more time, and more stress.

You explored thinking about what could go wrong before you build.

You learned to recognise good and bad design.

You discovered how Security by Design saves money.

You learned how it saves time.

You explored real-life examples in cars, houses, banks, websites, and phones.

You learned that everyone can use Security by Design โ€” students, parents, teachers, and businesses.

You discovered how it is part of daily life.

You learned what happens when security is forgotten.

Finally, you learned how to become a Security by Design thinker.

MODULE 1 SUMMARY MAP
====================

[ What is Security by Design? ]
        |
        V
[ Plan Safety First ] -> [ Ask "What Could Go Wrong?" ]
        |
        V
[ Cost of Fixing Later ] -> [ Good vs Bad Design ]
        |
        V
[ Real-Life Examples ] -> [ Everyone Can Plan ]
        |
        V
[ Daily Life ] -> [ Forgotten Security is Expensive ]
        |
        V
[ Security by Design Thinker! ]

Well done! You now have a strong foundation. In Module 2, you will learn the main principles of secure design.


22. Frequently Asked Questions (10 Questions)

Question 1: What is Security by Design in the simplest words?

Security by Design means planning for safety from the very beginning of any project.

Question 2: Why is it important?

Because planning for safety first saves time, money, and stress.

Question 3: What happens if security is fixed later?

It costs more money, takes more time, and can still leave problems.

Question 4: What question should I always ask?

"What could go wrong?"

Question 5: Is Security by Design only for big companies?

No. Everyone can use it โ€” students, parents, teachers, and small businesses.

Question 6: Can you give a real-life example?

Cars with seat belts and airbags are good examples of Security by Design.

Question 7: How does it save money?

It prevents problems before they happen, so you do not pay for breaches.

Question 8: How does it save time?

You build once instead of repairing or rebuilding later.

Question 9: What happens when security is forgotten?

Money, time, and trust are lost. Systems fail. Businesses close.

Question 10: What will I learn in Module 2?

You will learn the main principles of secure design, like keeping it simple, least privilege, and defence in depth.


23. Matching Exercises

Exercise 1 โ€” Match the Word to the Meaning

Column A (Word) Column B (Meaning)
1. Security by Design A. When someone breaks into a system
2. Plan B. Planning for safety from the very beginning
3. Breach C. The chance that something will go wrong
4. Risk D. Deciding what to do before doing it
5. Trust E. When people feel safe using your system

Answers: 1-B, 2-D, 3-A, 4-C, 5-E

Exercise 2 โ€” Match the Question to Its Purpose

Column A (Question) Column B (Purpose)
1. "What could go wrong?" A. Know who uses it
2. "Who will use it?" B. Plan for problems
3. "What could be stolen?" C. Plan for recovery
4. "What if it fails?" D. Protect information

Answers: 1-B, 2-A, 3-D, 4-C

Summary of Matching Exercises

Matching helps you connect words to meanings quickly.


24. Scenario-based Exercises

Scenario 1 โ€” The New School Portal

A school is building a new student portal. They want to launch it next week.

Questions:

  1. What questions should the school ask before launching?
  2. What could go wrong if they skip planning?
  3. How can Security by Design help?

Scenario 2 โ€” The Family Wi-Fi

Your family just bought a new Wi-Fi router. It does not have a password yet.

Questions:

  1. What could go wrong without a password?
  2. How can Security by Design help?
  3. What should you plan first?

Scenario 3 โ€” The New Shop

A trader wants to start selling products online. She is ready to launch today.

Questions:

  1. What should she plan before launching?
  2. What could go wrong if she skips planning?
  3. How would Security by Design help her business?

Summary of Scenario-based Exercises

These scenarios help you apply what you have learned to real situations.


25. Group Activity

Activity: Plan a Safe Project

Group size: 3โ€“5 students

Time: 40 minutes

Materials: Paper, pencil

Instructions:

  1. Choose a simple project (like a class website or a family budget app).
  2. Write what the project does and who will use it.
  3. Ask "what could go wrong?".
  4. Write a plan for safety.
  5. Present your plan to the class.

Goal: To practise Security by Design as a team.


26. Individual Activity

Activity: My Safe Design Plan

Time: 20 minutes

Materials: Notebook, pencil

Instructions:

  1. Think of a project you would like to build.
  2. Write what the project does.
  3. Write 3 things that could go wrong.
  4. Write 3 ways to prevent them.
  5. Write one habit you will start today.

Goal: To practise Security by Design on your own idea.


27. Mini Project

Project: Design a Safe System on Paper

Time: 1โ€“2 hours

Materials: Paper, pencil, colour pencils

Instructions:

  1. Choose a system (school portal, family app, small shop website).
  2. Draw what it will look like.
  3. List 5 things that could go wrong.
  4. Write how you will prevent each one.
  5. Present your design to the class.

Goal: To practise designing a safe system from the start.


28. Practical Assignment

Assignment: Find Examples of Security by Design

Time: 1 week

Materials: Notebook, pencil

Instructions:

  1. Look for examples of Security by Design in your daily life.
  2. Find at least 5 examples (locks, PINs, passwords, seat belts).
  3. Write what could have gone wrong without them.
  4. Write a short report on what you learned.
  5. Share it with your class.

Goal: To see Security by Design in the real world.


29. Key Takeaways

  1. Security by Design means planning for safety first.
  2. Prevention is cheaper than repair.
  3. Always ask "what could go wrong?".
  4. Good design includes safety from the start.
  5. Bad design ignores safety until it is too late.
  6. Everyone can use Security by Design.
  7. Security by Design saves money.
  8. Security by Design saves time.
  9. Forgotten security is expensive.
  10. Anyone can become a Security by Design thinker.

30. Classroom Discussion Questions

  1. What is Security by Design in your own words?
  2. Why is planning for safety better than fixing problems later?
  3. What questions should you always ask before building?
  4. Can you give an example of good design in your home?
  5. Can you give an example of bad design?
  6. How does Security by Design save money?
  7. How does Security by Design save time?
  8. Why is Security by Design important for everyone?
  9. What habit will you start today?
  10. What did you enjoy most in this module?

31. Preparation for the Next Module

You have finished Module 1. Well done! Here is how to prepare for Module 2, which is all about Principles of Secure Design.

  1. Review your key words. Make sure you can explain Security by Design in your own words.
  2. Notice good design. Look around your home, school, and community for good examples.
  3. Ask "what could go wrong?". Practice this question every day.
  4. Think about the future. What projects would you like to build safely?
  5. Bring your curiosity. Module 2 will teach you the principles of secure design, like keeping it simple, least privilege, and defence in depth.
TRANSITION TO MODULE 2
======================

[ Module 1: What is Security by Design? ]
          |
          V
[ Module 2: Principles of Secure Design ]
          |
          V
[ You will learn: keep it simple, least privilege,
  defence in depth, fail safely, and more ]

See you in Module 2. Keep thinking like a Security by Design thinker!


End of Module 1 โ€” What is Security by Design?

โฌ… Back to Course Outline | Go to Module 2 โžก

Security by Design ยท Beginner Level ยท 2026

3

Module Two

Module 2 ยท Principles of Secure Design

โฌ… Back to Course Outline

๐Ÿงฉ Module 2 โ€” Principles of Secure Design

Security by Design ยท Beginner Level ยท 2026


1. Module Introduction

Welcome to Module 2. In Module 1, you learned what Security by Design means. You learned that it is about planning for safety from the very beginning. You also learned why it saves time, money, and stress.

Now we go one step further. You will learn the main principles of secure design. A principle is like a rule or a guide. When you follow good principles, your design stays safe.

Think of building a bridge. Engineers follow principles like "use strong materials," "build on solid ground," and "test before opening." Security has its own principles too.

In this module, you will learn six big principles. You will learn to keep things simple. You will learn about least privilege, defence in depth, failing safely, not trusting input, and keeping your design open. Each one protects you in a different way.

This module is written for complete beginners. You do not need to know any coding. Every new word is explained in very simple language. Every principle comes with examples from real life, school, home, and Nigeria. So relax, read slowly, and let us begin.

YOUR LEARNING JOURNEY IN MODULE 2
=================================

[ Start ]
    |
    V
Keep It Simple
    |
    V
Least Privilege
    |
    V
Defence in Depth
    |
    V
Fail Safely
    |
    V
Do Not Trust Input
    |
    V
Keep It Open
    |
    V
[ You know the principles of secure design! ]

Summary of the Introduction

This module teaches you the six main principles of secure design. Each principle helps you build safer systems from the start.


2. Learning Objectives

By the end of this module, you will be able to:

  1. Explain what a principle is in your own words.
  2. Describe the principle of keeping it simple.
  3. Explain least privilege and why it matters.
  4. Describe defence in depth and its purpose.
  5. Explain what it means to fail safely.
  6. Describe why we should not trust input.
  7. Explain the principle of keeping it open.
  8. Give real-life examples of each principle.
  9. Spot which principle is missing in a bad design.
  10. Feel confident and curious to continue to Module 3.

Summary of Learning Objectives

You will learn six principles of secure design and how to apply them in daily life.


3. Warm-up Story โ€” Tunde's Locked Boxes

Tunde is a 12-year-old boy who lives in Ibadan. He loves collecting special things โ€” coins, stamps, and small toys. He keeps them in a wooden box in his room.

One day, Tunde's mother gave him three smaller boxes. "You can use these to organise your collection," she said.

Tunde thought about it. He had an idea.

First, he put all his coins in Box A. Then he put his stamps in Box B. Then he put his small toys in Box C. He labelled each box clearly.

Next, he placed all three small boxes inside the big wooden box. He locked the big box with a key.

But that is not all. He also placed a small padlock on each of the three smaller boxes.

His friend Chidi came to visit. "Why so many locks?" Chidi asked.

"Because if someone opens the big box, they still cannot open the small boxes without their own keys," Tunde said.

"But why organise them in small boxes?" Chidi asked.

"Because it is easier to find things. And if one box is broken, the others are still safe."

Chidi was impressed. "You have designed your collection well!"

Tunde smiled. He had used several principles without knowing their names. He had kept things simple. He had used many layers of protection. He had given each box only what it needed. His design was strong.

TUNDE'S BOXES
=============

[ Big Box with Lock ]
     |
     +-- [ Small Box A ] + padlock
     +-- [ Small Box B ] + padlock
     +-- [ Small Box C ] + padlock

Many locks = Defence in Depth
Small boxes = Keep It Simple
Each box has its key = Least Privilege

Summary of the Warm-up Story

Tunde organised his collection with three small boxes inside a big box. He used several locks and separate keys. Without knowing their names, he used the principles of secure design. This story introduces the whole module.


4. Main Lessons

In this section, you will go through 12 short lessons. Each lesson teaches one big idea. Each lesson ends with a mini summary. Read slowly. Think about the examples. Ask questions. That is how you learn.

Lesson 1 โ€” What is a Principle?

Definition

A principle is a rule or guide that helps you make good decisions. It is a simple idea you follow again and again.

Why it is important

Principles help you stay consistent. When you follow good principles, you make fewer mistakes.

Simple explanation

Think of a football coach. They have principles like "always pass the ball" and "keep your shape." A security designer has principles too.

Examples of Principles

  • In cooking: taste before serving.
  • In sports: warm up before playing.
  • In school: study a little every day.
  • In security: plan for safety first.

Real-life example

A carpenter follows the principle "measure twice, cut once."

School example

A student follows the principle "read the question twice before answering."

Home example

Your family follows the principle "lock the door before going out."

Nigerian example

A trader follows the principle "count your money twice before closing."

Illustration

PRINCIPLES ARE GUIDES
=====================

[ Principle ] -> [ Good decision ]
[ Principle ] -> [ Good decision ]
[ Principle ] -> [ Good decision ]
        |
        V
[ Consistent, safe results ]

Mini summary

A principle is a rule or guide that helps you make good decisions. Principles keep you consistent.


Lesson 2 โ€” Keep It Simple

Definition

Keep It Simple means designing things in the easiest way possible. It means avoiding unnecessary parts.

Why it is important

Simple systems are easier to understand and easier to protect. Complicated systems have more places for problems.

Simple explanation

Think of a bicycle. It has two wheels, a chain, and brakes. A car has thousands of parts. A bicycle is easier to fix. Simple designs are safer.

How to Keep It Simple

  • Do only what is needed.
  • Remove extra features.
  • Use clear names and steps.
  • Do not add things "just in case."

Real-life example

A bank login page asks for your username and password. It does not ask for 20 other details. It is simple.

School example

A school portal asks for your exam number and password. Simple.

Home example

Your Wi-Fi password is one strong phrase. It does not have a hundred rules.

Nigerian example

A POS machine asks for the amount and PIN. It does not ask for unnecessary details.

Illustration

KEEP IT SIMPLE
==============

Simple:   [ User ] -> [ Password ] -> [ Login ]

Complex:  [ User ] -> [ Password ] -> [ OTP ]
       -> [ Secret Question ] -> [ Birthday ]
       -> [ Colour ] -> [ Pet Name ] -> [ Login ]

Simple is easier to protect.

Mini summary

Keep It Simple means designing things in the easiest way possible. Simple systems are easier to protect.


Lesson 3 โ€” Least Privilege

Definition

Least Privilege means giving each person only the access they need to do their job. Nothing more.

Why it is important

If someone has more access than they need, a mistake or hack can cause more damage.

Simple explanation

Think of a school. The head teacher has keys to every room. A student only has access to their classroom. Students do not need keys to the staff room.

How to Use Least Privilege

  • Give each person only what they need.
  • Do not give admin access to everyone.
  • Remove access when it is no longer needed.
  • Check access regularly.

Real-life example

A bank teller can help customers. They cannot access the bank's main vault. That is least privilege.

School example

A student can check their own results. They cannot change anyone's scores.

Home example

Your younger brother can watch TV. He cannot change the family bank account.

Nigerian example

A POS operator can collect payments. They cannot access the business owner's full bank account.

Illustration

LEAST PRIVILEGE
===============

[ Head Teacher ] -> All rooms
[ Teacher ]      -> Classroom + Staff Room
[ Student ]      -> Classroom only
[ Visitor ]      -> Front gate only

Each has only what they need.

Mini summary

Least Privilege means giving each person only the access they need. Nothing more.


Lesson 4 โ€” Defence in Depth

Definition

Defence in Depth means using many layers of protection. If one layer fails, the others still protect you.

Why it is important

No single protection is perfect. Many layers make you much safer.

Simple explanation

Think of a castle. It has a moat, walls, gates, and guards. If someone crosses the moat, they still face the walls. Defence in Depth is the same idea.

Layers of Protection

  • Strong passwords
  • Two-Factor Authentication (2FA)
  • Antivirus software
  • Firewalls
  • Regular backups

Real-life example

A bank has security guards, cameras, alarms, and vaults. Many layers.

School example

A school has a gate, a fence, and a watchman. Many layers.

Home example

Your house has a gate, a door lock, and a window lock. Many layers.

Nigerian example

A Nigerian bank has guards, cameras, alarms, and vault doors. Many layers of protection.

Illustration

DEFENCE IN DEPTH
================

[ Password ]
        |
        V
[ 2FA ]
        |
        V
[ Antivirus ]
        |
        V
[ Firewall ]
        |
        V
[ Backup ]

Many layers. Attackers must pass them all.

Mini summary

Defence in Depth means using many layers of protection. If one fails, the others still protect you.


Lesson 5 โ€” Fail Safely

Definition

Fail Safely means that when something goes wrong, the system should protect users instead of exposing them.

Why it is important

Systems will fail sometimes. The way they fail matters. Failing safely prevents damage.

Simple explanation

Think of a door that locks automatically when the power goes off. That is failing safely.

How to Fail Safely

  • Lock things down when a problem happens.
  • Do not reveal secret information in error messages.
  • Keep a backup ready.
  • Log what went wrong.
  • Alert the right people.

Real-life example

When a bank ATM loses network, it stops giving money. That is failing safely.

School example

If the school portal fails, students cannot change scores. That is failing safely.

Home example

If the Wi-Fi goes down, your devices do not share your passwords. That is failing safely.

Nigerian example

If a Nigerian bank's mobile app fails, it locks your account until you log in again. That is failing safely.

Illustration

FAIL SAFELY
===========

[ Something goes wrong ]
        |
        V
[ System locks down ]
        |
        V
[ No data is exposed ]
        |
        V
[ Users are protected ]

Mini summary

Fail Safely means that when something goes wrong, the system protects users instead of exposing them.


Lesson 6 โ€” Do Not Trust Input

Definition

Do Not Trust Input means always checking what users type or send. Never assume it is safe.

Why it is important

Attackers use input to break into systems. If you check everything, you stay safe.

Simple explanation

Think of a teacher marking exams. They check every answer. They do not assume every answer is correct.

What to Check

  • Names and emails
  • Passwords
  • Numbers (are they really numbers?)
  • File uploads
  • Links

Real-life example

A website asks for your phone number. It checks that you typed numbers, not letters.

School example

A school portal checks that your exam number has the correct format.

Home example

Your family checks a text message before clicking any link.

Nigerian example

A Nigerian bank checks every transaction for suspicious details before allowing it.

Illustration

DO NOT TRUST INPUT
==================

[ User input ] -> [ Check it ] -> [ If good, accept ]
                             -> [ If bad, reject ]

Never trust input directly.

Mini summary

Do Not Trust Input means always checking what users type or send. Never assume it is safe.


Lesson 7 โ€” Keep It Open

Definition

Keep It Open means not relying on secrecy as your only protection. Your design should be safe even if everyone knows how it works.

Why it is important

Secrets often leak. If your system is safe without secrets, you are stronger.

Simple explanation

Think of a lock. Everyone knows how a lock works. But only you have the key. The lock is safe even though its design is open.

How to Keep It Open

  • Do not rely only on hidden passwords.
  • Use well-tested methods.
  • Share your design for review.
  • Test openly with experts.

Real-life example

Everyone knows how a bank's security cameras work. But the cameras still protect the bank.

School example

Everyone knows how the school's exam rules work. But students still cannot cheat.

Home example

Everyone knows how a house lock works. But only your family has the key.

Nigerian example

Everyone knows how Nigerian bank cards work. But only you have your PIN.

Illustration

KEEP IT OPEN
============

[ Everyone knows how the lock works ]
        |
        V
[ But only you have the key ]
        |
        V
[ System stays safe ]

Mini summary

Keep It Open means not relying on secrecy as your only protection. Your design should be safe even if everyone knows how it works.


Lesson 8 โ€” Using Principles Together

Definition

Using principles together means applying more than one rule at the same time. This makes your design even stronger.

Why it is important

Each principle protects you in a different way. Together, they build a much safer system.

Simple explanation

Think of a football team. Passing, defending, and scoring all matter. Using them together wins matches.

Example Combination

  • Keep It Simple
  • Least Privilege
  • Defence in Depth
  • Fail Safely
  • Do Not Trust Input
  • Keep It Open

Real-life example

A bank uses all six principles at once. That is why banks are hard to rob.

School example

A school uses simple portals, limited access, and backups. All together.

Home example

Your home uses locks, alarms, and safe habits. All together.

Nigerian example

Nigerian banks use all six principles to protect customers.

Illustration

ALL PRINCIPLES TOGETHER
=======================

[ Keep It Simple ]
[ Least Privilege ]
[ Defence in Depth ]
[ Fail Safely ]
[ Do Not Trust Input ]
[ Keep It Open ]
        |
        V
[ Very strong design ]

Mini summary

Using principles together makes your design much stronger. Each one protects you in a different way.


Lesson 9 โ€” Principles in Real Life

Definition

Principles in real life means seeing how these ideas are used in banks, hospitals, schools, and homes.

Why it is important

Seeing them in real life helps you remember and apply them.

Simple explanation

Think of a hospital. Patients have different access. Doctors have their own access. Visitors stay in the waiting area. That is least privilege.

Real-Life Examples

  • Banks โ€” keep it simple + defence in depth
  • Hospitals โ€” least privilege + fail safely
  • Schools โ€” keep it simple + do not trust input
  • Homes โ€” defence in depth + keep it open

Real-life example

A bank uses passwords (simple) and cameras (defence in depth).

School example

A school uses simple portals and checks every exam number.

Home example

Your home uses locked doors (defence in depth) and safe habits (keep it simple).

Nigerian example

Nigerian banks use many principles together to protect customer money.

Illustration

PRINCIPLES IN REAL LIFE
=======================

Banks:     Simple + Defence
Hospitals: Least Priv + Fail Safe
Schools:   Simple + No Trust
Homes:     Defence + Open

Mini summary

Principles are used everywhere โ€” banks, hospitals, schools, and homes.


Lesson 10 โ€” Principles in Daily Habits

Definition

Principles in daily habits means using these ideas in small, everyday actions.

Why it is important

Small habits build strong security over time.

Simple explanation

Think of brushing your teeth. It is small. But doing it daily protects you. Same for security principles.

Daily Habits

  • Use a strong password (keep it simple).
  • Do not share your PIN (least privilege).
  • Use 2FA (defence in depth).
  • Log out on shared devices (fail safely).
  • Check messages before clicking (do not trust input).
  • Teach your family (keep it open).

Real-life example

A student checks their messages before clicking any link.

School example

A student uses a different password for the school portal.

Home example

Your family sets a strong Wi-Fi password.

Nigerian example

A Nigerian family covers their PIN at the ATM.

Illustration

DAILY HABITS
============

Strong password    -> Keep It Simple
Do not share PIN   -> Least Privilege
Use 2FA            -> Defence in Depth
Log out            -> Fail Safely
Check messages     -> Do Not Trust Input
Teach family       -> Keep It Open

Mini summary

Small daily habits use the principles of secure design. Together, they protect you.


Lesson 11 โ€” Spotting Missing Principles

Definition

Spotting missing principles means noticing when a design has forgotten one of the six principles.

Why it is important

When a principle is missing, the design is weaker. Spotting it helps you fix problems before they happen.

Simple explanation

Think of a football team missing a goalkeeper. Anyone can score. That is a missing principle.

How to Spot Missing Principles

  • Is the design too complicated? (Keep It Simple missing)
  • Does everyone have full access? (Least Privilege missing)
  • Is there only one layer of protection? (Defence in Depth missing)
  • Does the system expose data on failure? (Fail Safely missing)
  • Is input taken without checking? (Do Not Trust Input missing)
  • Is secrecy the only protection? (Keep It Open missing)

Real-life example

A website that asks for 20 details to log in is missing "Keep It Simple."

School example

A portal where every student can see all results is missing "Least Privilege."

Home example

A Wi-Fi router without a password is missing "Defence in Depth."

Nigerian example

A bank without OTPs is missing "Defence in Depth."

Illustration

SPOTTING MISSING PRINCIPLES
===========================

Too complex?           -> Keep It Simple missing
Everyone full access?  -> Least Privilege missing
One layer only?        -> Defence in Depth missing
Data exposed?          -> Fail Safely missing
Input unchecked?       -> Do Not Trust Input missing
Secrecy only?          -> Keep It Open missing

Mini summary

Spotting missing principles helps you fix problems before they cause harm.


Lesson 12 โ€” Becoming a Secure Designer

Definition

A secure designer is someone who uses the six principles every time they plan something.

Why it is important

This habit protects you, your family, and your projects. It prepares you for future work.

Simple explanation

Think of a careful planner. They always consider safety, cost, and time. A secure designer always considers the six principles.

How to Become One

  1. Learn the six principles.
  2. Ask "which principle is missing?"
  3. Apply them in daily life.
  4. Teach others.
  5. Review your designs regularly.

Real-life example

A student designs their class project with the six principles.

School example

A student helps build a safer class portal.

Home example

Your family uses all six principles to protect their devices.

Nigerian example

Nigerian cybersecurity professionals use the six principles daily.

Illustration

BECOMING A SECURE DESIGNER
==========================

[ Learn principles ]
        |
        V
[ Ask which is missing ]
        |
        V
[ Apply in daily life ]
        |
        V
[ Teach others ]
        |
        V
[ Review and improve ]

Mini summary

A secure designer uses the six principles every time they plan something. Anyone can become one.


5. Key Vocabulary

Word Simple Definition
Principle A rule or guide that helps you decide.
Keep It Simple Design in the easiest way possible.
Least Privilege Give each person only what they need.
Defence in Depth Use many layers of protection.
Fail Safely When something goes wrong, protect users.
Input What users type or send.
Do Not Trust Input Always check what users send.
Keep It Open Do not rely on secrecy alone.
Design The way something is built or arranged.
Layer One level of protection.
Access Being able to use or see something.
Secure Designer Someone who plans with the six principles.

Summary of Key Vocabulary

These words are the foundation of secure design. Use them often so they become easy.


6. Important Concepts

Concept 1 โ€” Principles Guide Design

Rules help you make good decisions again and again.

Concept 2 โ€” Simple Is Safer

Simple systems are easier to protect and harder to break.

Concept 3 โ€” Many Layers Beat One

If one protection fails, the others still protect you.

Concept 4 โ€” Check Everything

Do not trust input. Do not rely on secrecy. Always verify.

Concept 5 โ€” Failures Should Not Hurt Users

When something goes wrong, the system should protect users.

Summary of Important Concepts

These five concepts are the heart of Module 2. Read them again before moving on.


7. Step-by-step Explanations

Step-by-step: How to Apply the Six Principles

  1. Understand what you are building.
  2. Keep it simple. Remove extra parts.
  3. Give each person only what they need.
  4. Add many layers of protection.
  5. Plan how it will fail safely.
  6. Check every input.
  7. Do not rely on secrecy alone.
APPLYING THE SIX PRINCIPLES
===========================

[ Understand ]
        |
        V
[ Keep It Simple ]
        |
        V
[ Least Privilege ]
        |
        V
[ Defence in Depth ]
        |
        V
[ Fail Safely ]
        |
        V
[ Do Not Trust Input ]
        |
        V
[ Keep It Open ]
        |
        V
[ Safe design! ]

Step-by-step: How to Spot Missing Principles

  1. Look at the design.
  2. Is it complex? Check "Keep It Simple."
  3. Does everyone have full access? Check "Least Privilege."
  4. Is there only one layer? Check "Defence in Depth."
  5. Does it expose data on failure? Check "Fail Safely."
  6. Is input taken without checking? Check "Do Not Trust Input."
  7. Is secrecy the only protection? Check "Keep It Open."
SPOTTING MISSING PRINCIPLES
===========================

[ Complex? ]      -> Keep It Simple missing
[ Full access? ]  -> Least Privilege missing
[ One layer? ]    -> Defence in Depth missing
[ Data exposed? ] -> Fail Safely missing
[ Unchecked? ]    -> Do Not Trust Input missing
[ Secrecy? ]      -> Keep It Open missing

Step-by-step: How to Fix a Weak Design

  1. Identify the missing principle.
  2. Plan how to add it.
  3. Make the change.
  4. Test the change.
  5. Review again.
FIXING A WEAK DESIGN
====================

[ Identify missing principle ]
        |
        V
[ Plan the fix ]
        |
        V
[ Make the change ]
        |
        V
[ Test ]
        |
        V
[ Review ]

Summary of Step-by-step Explanations

Applying principles, spotting missing ones, and fixing weak designs all follow simple steps. Follow them, and your design stays strong.


8. Real-life Examples

Example 1 โ€” A Bank

A bank uses all six principles: simple logins, limited access, many layers, safe failure, input checks, and open designs.

Example 2 โ€” A Hospital

A hospital uses least privilege (doctors, nurses, visitors) and fail safely (protect records on failure).

Example 3 โ€” A School

A school uses simple portals, limited access, and input checks.

Example 4 โ€” An Online Shop

An online shop uses many layers and does not trust input.

Example 5 โ€” A Government Office

A government office uses all six principles to protect national data.

Summary of Real-life Examples

The six principles are used in banks, hospitals, schools, shops, and government offices.


9. Nigerian Examples

Example 1 โ€” Nigerian Banks

Nigerian banks use all six principles to protect customer money.

Example 2 โ€” Nigerian Fintechs

Paystack and Flutterwave use many layers and check every input.

Example 3 โ€” Nigerian Schools

Nigerian universities give different access to staff and students.

Example 4 โ€” Nigerian Government

NITDA uses least privilege and defence in depth.

Example 5 โ€” Nigerian Families

Families use defence in depth (locks, PINs, passwords).

Summary of Nigerian Examples

Nigeria uses the six principles in banks, fintechs, schools, government, and families.


10. Fun Examples Children Can Relate To

Example 1 โ€” A Football Team

Each player has a role (least privilege). The coach plans many defences (defence in depth).

Example 2 โ€” A Lunchbox

Each compartment holds a different food (keep it simple). You check food before eating (do not trust input).

Example 3 โ€” A Pencil Case

Each item has a place (keep it simple). You zip it closed (defence in depth).

Example 4 โ€” A House of Cards

If one card falls, the house falls. Many layers would make it strong.

Example 5 โ€” A Video Game

Games have many levels of defence (health, shields, armour).

Summary of Fun Examples

The principles appear in football teams, lunchboxes, pencil cases, card houses, and video games.


11. Everyday Examples

Situation Principle
Locking your door Defence in Depth
Using a PIN Least Privilege
Simple Wi-Fi password Keep It Simple
Checking messages Do Not Trust Input
Logging out Fail Safely

Summary of Everyday Examples

Even simple daily actions use the six principles. Now you can see them everywhere.


12. Parent Tips

  1. Teach the principles. Explain each one with examples.
  2. Use daily life. Point out principles in locks, PINs, and passwords.
  3. Ask "which principle is missing?". Do this with your child.
  4. Praise good design. When your child spots good design, praise them.
  5. Practice together. Design something simple as a family.
  6. Be patient. Learning takes time.
  7. Keep it fun. Use games and stories.
  8. Review often. Revisit the principles weekly.

Summary of Parent Tips

Parents can teach the principles at home through daily conversations and simple examples.


13. Interesting Facts

  1. Most cyber attacks succeed because one of the six principles is missing.
  2. Simple designs are 10 times easier to protect.
  3. Defence in depth is used in castles, banks, and space shuttles.
  4. Fail safely is used in elevators and ATM machines.
  5. Companies that follow all six principles save millions.
  6. Many Nigerian fintechs follow these principles strictly.
  7. Every smartphone uses defence in depth.
  8. Learning these principles helps you in any career.

Summary of Interesting Facts

The six principles are powerful and used everywhere.


14. Did You Know?

  • Did you know that "least privilege" is used in schools and banks?
  • Did you know that "defence in depth" comes from castle design?
  • Did you know that elevators use "fail safely"?
  • Did you know that "keep it open" is a principle used by scientists?
  • Did you know that many cybersecurity professionals use all six principles daily?
  • Did you know that simple designs save time and money?

Summary of Did You Know?

The six principles are full of surprises. The more you learn, the more useful they become.


15. Remember This

  • A principle is a rule or guide.
  • Keep It Simple means design in the easiest way.
  • Least Privilege means give only what is needed.
  • Defence in Depth means many layers.
  • Fail Safely means protect users on failure.
  • Do Not Trust Input means check everything.
  • Keep It Open means do not rely on secrecy.
  • Using principles together is strongest.
  • Spot missing principles in weak designs.
  • Anyone can become a secure designer.

Summary of Remember This

These ten points are the heart of Module 2. Read them again before moving on.


16. Common Mistakes

  1. Making things too complex. Simple is safer.
  2. Giving everyone full access. Use least privilege.
  3. Using only one layer of protection. Use defence in depth.
  4. Exposing data on failure. Fail safely.
  5. Trusting input. Always check.
  6. Relying on secrecy alone. Keep it open.
  7. Forgetting to test. Test your design.
  8. Ignoring small problems. They grow into big breaches.

Summary of Common Mistakes

Avoiding these mistakes will make your designs stronger than most.


17. Best Practices

  1. Keep designs simple.
  2. Give only what is needed.
  3. Use many layers.
  4. Plan for safe failure.
  5. Check all input.
  6. Do not rely on secrecy.
  7. Combine principles.
  8. Spot missing principles.
  9. Review designs regularly.
  10. Teach others the principles.

Summary of Best Practices

These ten practices will help you build strong, safe designs.


18. ASCII Illustrations, Diagrams, Flowcharts, and Timelines

Diagram 1 โ€” Six Principles

SIX PRINCIPLES OF SECURE DESIGN
===============================

[ Keep It Simple ]
[ Least Privilege ]
[ Defence in Depth ]
[ Fail Safely ]
[ Do Not Trust Input ]
[ Keep It Open ]

Diagram 2 โ€” Keep It Simple

KEEP IT SIMPLE
==============

Simple:   [ User ] -> [ Password ] -> [ Login ]

Complex:  [ User ] -> [ Many steps ] -> [ Problems ]

Diagram 3 โ€” Least Privilege

LEAST PRIVILEGE
===============

[ Head Teacher ] -> All rooms
[ Teacher ]      -> Classroom + Staff Room
[ Student ]      -> Classroom only
[ Visitor ]      -> Front gate only

Diagram 4 โ€” Defence in Depth

DEFENCE IN DEPTH
================

[ Password ]
        |
        V
[ 2FA ]
        |
        V
[ Antivirus ]
        |
        V
[ Firewall ]
        |
        V
[ Backup ]

Diagram 5 โ€” Fail Safely

FAIL SAFELY
===========

[ Problem happens ]
        |
        V
[ System locks down ]
        |
        V
[ Users protected ]

Diagram 6 โ€” Becoming a Secure Designer

BECOMING A SECURE DESIGNER
==========================

[ Learn principles ]
        |
        V
[ Spot missing ones ]
        |
        V
[ Apply daily ]
        |
        V
[ Teach others ]
        |
        V
[ Review and improve ]

Summary of Illustrations

These diagrams help you see the six principles clearly. Draw them yourself to remember them better.


19. Comparison Tables

Table 1 โ€” The Six Principles

Principle Meaning
Keep It Simple Design in the easiest way possible.
Least Privilege Give only what is needed.
Defence in Depth Use many layers of protection.
Fail Safely Protect users on failure.
Do Not Trust Input Always check what users send.
Keep It Open Do not rely on secrecy alone.

Table 2 โ€” Simple vs Complex Design

Simple Design Complex Design
Easier to protect Harder to protect
Fewer places for problems Many places for problems
Easier to fix Harder to fix
Users understand it Users get confused

Table 3 โ€” One Layer vs Many Layers

One Layer Many Layers
One protection only Many protections
Easy to break Hard to break
Risky Safe
Example: password only Example: password + 2FA + antivirus

Summary of Comparison Tables

Comparing ideas side by side helps you remember the differences clearly.


20. Summary After Every Lesson

Lesson Main Idea
Lesson 1 A principle is a rule or guide.
Lesson 2 Keep It Simple means design in the easiest way.
Lesson 3 Least Privilege means give only what is needed.
Lesson 4 Defence in Depth means many layers.
Lesson 5 Fail Safely means protect users on failure.
Lesson 6 Do Not Trust Input means check everything.
Lesson 7 Keep It Open means do not rely on secrecy.
Lesson 8 Using principles together is strongest.
Lesson 9 Principles appear in banks, hospitals, schools, homes.
Lesson 10 Small daily habits use the principles.
Lesson 11 Spotting missing principles prevents harm.
Lesson 12 Anyone can become a secure designer.

21. End-of-Module Summary

Congratulations! You have completed Module 2. Let us review what you have learned.

You began by learning that a principle is a rule or guide.

You learned to Keep It Simple โ€” design in the easiest way possible.

You discovered Least Privilege โ€” give each person only what they need.

You explored Defence in Depth โ€” use many layers of protection.

You learned to Fail Safely โ€” protect users when something goes wrong.

You discovered the principle of Do Not Trust Input โ€” always check what users send.

You explored Keep It Open โ€” do not rely on secrecy alone.

You learned how to use principles together for strong designs.

You found principles in real life โ€” banks, hospitals, schools, homes.

You saw how daily habits use the principles.

You learned to spot missing principles in weak designs.

Finally, you learned how to become a secure designer.

MODULE 2 SUMMARY MAP
====================

[ Keep It Simple ]
        |
        V
[ Least Privilege ] -> [ Defence in Depth ]
        |
        V
[ Fail Safely ] -> [ Do Not Trust Input ] -> [ Keep It Open ]
        |
        V
[ Use Together ] -> [ Spot Missing ] -> [ Secure Designer! ]

Well done! You now understand the six principles of secure design. In Module 3, you will learn how to think about threats and build safe systems from the start.


22. Frequently Asked Questions (10 Questions)

Question 1: What is a principle?

A principle is a rule or guide that helps you make good decisions.

Question 2: What does "Keep It Simple" mean?

Design things in the easiest way possible. Avoid extra parts.

Question 3: What is "Least Privilege"?

Give each person only the access they need. Nothing more.

Question 4: What is "Defence in Depth"?

Use many layers of protection. If one fails, the others still protect you.

Question 5: What does "Fail Safely" mean?

When something goes wrong, the system should protect users instead of exposing them.

Question 6: Why should I "Do Not Trust Input"?

Attackers use input to break into systems. Always check what users send.

Question 7: What does "Keep It Open" mean?

Do not rely on secrecy alone. Your design should be safe even if everyone knows how it works.

Question 8: Can I use more than one principle at the same time?

Yes. Using many together makes your design stronger.

Question 9: How do I spot missing principles?

Look at the design and ask if it is too complex, gives too much access, has only one layer, exposes data, trusts input, or relies on secrecy.

Question 10: What will I learn in Module 3?

You will learn how to think about threats and build safe systems from the start.


23. Matching Exercises

Exercise 1 โ€” Match the Principle to the Meaning

Column A (Principle) Column B (Meaning)
1. Keep It Simple A. Give only what is needed
2. Least Privilege B. Use many layers
3. Defence in Depth C. Protect users on failure
4. Fail Safely D. Design in the easiest way
5. Do Not Trust Input E. Always check what users send
6. Keep It Open F. Do not rely on secrecy

Answers: 1-D, 2-A, 3-B, 4-C, 5-E, 6-F

Exercise 2 โ€” Match the Situation to the Principle

Column A (Situation) Column B (Principle)
1. Locking your door A. Least Privilege
2. A student uses only their class portal B. Defence in Depth
3. Checking a link before clicking C. Do Not Trust Input
4. Using 2FA D. Defence in Depth

Answers: 1-B, 2-A, 3-C, 4-D

Summary of Matching Exercises

Matching helps you connect principles to meanings quickly.


24. Scenario-based Exercises

Scenario 1 โ€” The New School Portal

A school is building a new portal. Any student can see any result. Anyone can change anything.

Questions:

  1. Which principle is missing?
  2. What could go wrong?
  3. How can the school fix it?

Scenario 2 โ€” The Family Wi-Fi

Your family's Wi-Fi router has no password. Anyone can use it.

Questions:

  1. Which principle is missing?
  2. What could go wrong?
  3. How can the family fix it?

Scenario 3 โ€” The Online Shop

An online shop takes the customer's name and address without checking. It also exposes customer data on errors.

Questions:

  1. Which two principles are missing?
  2. What could go wrong?
  3. How can the shop fix it?

Summary of Scenario-based Exercises

These scenarios help you apply what you have learned to real situations.


25. Group Activity

Activity: Apply the Six Principles

Group size: 3โ€“5 students

Time: 40 minutes

Materials: Paper, pencil

Instructions:

  1. Choose a simple system (school portal, family app, small shop).
  2. List all six principles.
  3. Write how your system will use each one.
  4. Present your plan to the class.

Goal: To practise applying all six principles together.


26. Individual Activity

Activity: My Six Principles Plan

Time: 20 minutes

Materials: Notebook, pencil

Instructions:

  1. Write the six principles.
  2. Write one example of each in your daily life.
  3. Write one thing you will improve in your life using these principles.

Goal: To connect principles to your own life.


27. Mini Project

Project: Design a System Using All Six Principles

Time: 1โ€“2 hours

Materials: Paper, pencil, colour pencils

Instructions:

  1. Choose a system (class page, family app, small shop).
  2. Draw what it will look like.
  3. Show how each of the six principles is used.
  4. Present it to the class.

Goal: To practise using all six principles in one design.


28. Practical Assignment

Assignment: Spot the Missing Principles

Time: 1 week

Materials: Notebook, pencil

Instructions:

  1. Look around your home, school, or community.
  2. Find 5 designs and identify which principle they use.
  3. Find 2 designs missing a principle.
  4. Write what could go wrong.
  5. Suggest how to fix them.

Goal: To practise spotting missing principles in real life.


29. Key Takeaways

  1. A principle is a rule or guide.
  2. Keep It Simple means design in the easiest way.
  3. Least Privilege means give only what is needed.
  4. Defence in Depth means many layers.
  5. Fail Safely means protect users on failure.
  6. Do Not Trust Input means check everything.
  7. Keep It Open means do not rely on secrecy.
  8. Using principles together is strongest.
  9. Spot missing principles in weak designs.
  10. Anyone can become a secure designer.

30. Classroom Discussion Questions

  1. What is a principle in your own words?
  2. Which principle do you think is most important?
  3. Why is simple design safer than complex design?
  4. Can you give an example of least privilege in your school?
  5. Why do we need many layers of protection?
  6. What does it mean to fail safely?
  7. Why should we not trust input?
  8. Why should we keep our design open?
  9. How can you apply these principles in your own life?
  10. What did you enjoy most in this module?

31. Preparation for the Next Module

You have finished Module 2. Well done! Here is how to prepare for Module 3, which is all about Thinking About Threats and Building Safely.

  1. Review the six principles. Make sure you can explain each one.
  2. Notice principles around you. Look at home, school, and shops.
  3. Practice spotting missing principles. Look for weak designs.
  4. Think about threats. What could go wrong in systems you use?
  5. Bring your curiosity. Module 3 will teach you about threat models, planning for problems, and testing your design.
TRANSITION TO MODULE 3
======================

[ Module 2: Principles of Secure Design ]
          |
          V
[ Module 3: Thinking About Threats and Building Safely ]
          |
          V
[ You will learn: threat models, planning for mistakes,
  testing your design, and keeping systems safe ]

See you in Module 3. Keep thinking like a secure designer!


End of Module 2 โ€” Principles of Secure Design

โฌ… Back to Course Outline | Go to Module 3 โžก

Security by Design ยท Beginner Level ยท 2026

4

Module Three

Module 3 ยท Thinking About Threats and Building Safely

โฌ… Back to Course Outline

๐ŸŽฏ Module 3 โ€” Thinking About Threats and Building Safely

Security by Design ยท Beginner Level ยท 2026


1. Module Introduction

Welcome to Module 3 โ€” the final module of Security by Design. You have come a long way. In Module 1, you learned what Security by Design means. In Module 2, you learned the six principles of secure design.

Now we come to the last piece of the puzzle. You will learn how to think about threats before you build. You will learn how to plan for problems. You will learn how to test your design. And you will learn how to keep systems safe after they are built.

Think of a goalkeeper. Before a match, they study the other team. They think about how the other team will attack. They plan how to stop them. A security designer does the same for systems.

In this module, you will learn what a threat model is. You will learn to ask "what could go wrong?". You will learn to plan for mistakes and attacks. You will also learn how to keep systems safe after they are built.

This module is written for complete beginners. You do not need to know any coding. Every new word is explained in very simple language. Every idea comes with examples from real life, school, home, and Nigeria. So relax, read slowly, and let us begin.

YOUR LEARNING JOURNEY IN MODULE 3
=================================

[ Start ]
    |
    V
What is a Threat Model?
    |
    V
Asking "What Could Go Wrong?"
    |
    V
Planning for Mistakes and Attacks
    |
    V
Testing Your Design
    |
    V
Keeping Systems Safe After Building
    |
    V
[ You are ready to build safely! ]

Summary of the Introduction

This module teaches you how to think about threats and build safe systems. You will learn about threat models, planning for problems, testing, and keeping systems safe.


2. Learning Objectives

By the end of this module, you will be able to:

  1. Explain what a threat model is in your own words.
  2. Describe how to ask "what could go wrong?" in any project.
  3. Explain how to plan for mistakes and attacks.
  4. Describe how to test a design before building.
  5. Explain how to keep systems safe after building.
  6. Create a simple threat model for a small project.
  7. Identify common threats in daily systems.
  8. Describe how to fix problems before they happen.
  9. Use all the principles from Module 2 together.
  10. Feel confident to build safely and think like a secure designer.

Summary of Learning Objectives

You will learn to think about threats, plan for problems, test designs, and keep systems safe after they are built.


3. Warm-up Story โ€” Ngozi Plans the School Play

Ngozi is a 13-year-old girl who lives in Enugu. She loves drama. One day, her teacher asked her to plan the school play.

Ngozi was very excited. She started writing the script immediately.

Her friend Amina came to visit. "Ngozi, have you thought about what could go wrong?" Amina asked.

"What could go wrong?" Ngozi said. "We just act the play!"

Amina smiled. "Let me show you."

She took a piece of paper and wrote:

  1. What if an actor gets sick?
  2. What if the microphone stops working?
  3. What if the lights fail?
  4. What if the audience does not come?
  5. What if the stage is too small?
  6. What if it rains on the outdoor stage?

Ngozi looked at the list. She had not thought about any of these things.

"You are right," Ngozi said. "I need to plan for these problems."

So Ngozi and Amina planned together. They chose a backup actor. They tested the microphone twice. They borrowed a small generator for the lights. They printed more invitations. They measured the stage. They chose an indoor hall in case of rain.

The day of the play arrived. The play was a big success. Nothing went wrong โ€” because they had planned for problems before they happened.

Ngozi learned a big lesson. Thinking about problems first is the secret to success. That is what a threat model is all about.

NGOZI'S PLAN
============

[ Plan the play ]
        |
        V
[ Ask "what could go wrong?" ]
        |
        V
[ Plan for each problem ]
        |
        V
[ The play is a success! ]

Summary of the Warm-up Story

Ngozi planned the school play. Her friend Amina taught her to think about problems first. Because they planned, the play was a success. This story introduces the whole module.


4. Main Lessons

In this section, you will go through 12 short lessons. Each lesson teaches one big idea. Each lesson ends with a mini summary. Read slowly. Think about the examples. Ask questions. That is how you learn.

Lesson 1 โ€” What is a Threat Model?

Definition

A threat model is a simple plan that lists what could go wrong in a project and how to stop it.

Why it is important

Without a threat model, you are blind to problems. With one, you plan for safety before you build.

Simple explanation

Think of planning a trip. You make a list of what could go wrong: rain, traffic, lost luggage. You plan for each one. A threat model is the same.

Parts of a Threat Model

  • What you are building
  • Who will use it
  • What could go wrong
  • How you will prevent it
  • What you will do if it happens

Real-life example

A bank creates a threat model before opening a new branch.

School example

A school creates a threat model before launching a portal.

Home example

Your family creates a simple threat model for a trip.

Nigerian example

Nigerian banks create threat models before launching new apps.

Illustration

THREAT MODEL
============

[ What we're building ]
        |
        V
[ Who will use it ]
        |
        V
[ What could go wrong ]
        |
        V
[ How to prevent it ]
        |
        V
[ What to do if it happens ]

Mini summary

A threat model is a simple plan that lists what could go wrong and how to stop it.


Lesson 2 โ€” Asking "What Could Go Wrong?"

Definition

Asking "what could go wrong?" means thinking of all the problems before they happen.

Why it is important

If you think about problems first, you can plan for them. If you ignore them, they will surprise you.

Simple explanation

Think of a picnic. "What could go wrong?" โ€” rain, ants, no food. You plan for each.

Common Questions

  • What if someone steals this?
  • What if someone breaks this?
  • What if someone shares this?
  • What if this fails?
  • What if the wrong person sees this?
  • What if the power goes off?
  • What if the internet stops working?

Real-life example

A bank asks, "What if someone steals a customer's card?" and plans for it.

School example

A school asks, "What if a student shares their password?" and plans to reset it.

Home example

Your family asks, "What if a stranger uses our Wi-Fi?" and sets a password.

Nigerian example

A Nigerian bank asks, "What if a fraudster pretends to be a customer?" and uses 2FA.

Illustration

ASK "WHAT COULD GO WRONG?"
==========================

[ What if someone steals? ]
[ What if someone breaks? ]
[ What if the wrong person sees? ]
[ What if power goes off? ]
        |
        V
[ Plan for each problem ]

Mini summary

Asking "what could go wrong?" helps you plan for safety before problems happen.


Lesson 3 โ€” Identifying Threats

Definition

Identifying threats means listing all the dangers that could affect your project.

Why it is important

You cannot protect against a threat you have not noticed.

Simple explanation

Think of a hospital. The threats are illness, injury, infection. They list them all.

Common Threats

  • Attackers โ€” hackers, thieves, scammers
  • Mistakes โ€” user error, typing mistakes
  • Accidents โ€” power cut, flood, fire
  • Failures โ€” broken servers, no internet
  • Insiders โ€” staff or family who misuse access

Real-life example

A bank identifies threats: robbers, hackers, fraudsters, and staff mistakes.

School example

A school identifies threats: cheating students, hackers, and system failures.

Home example

Your family identifies threats: thieves, strangers, and accidents.

Nigerian example

A Nigerian bank identifies threats: phishing, insider fraud, and system failures.

Illustration

IDENTIFYING THREATS
===================

[ Attackers ]
[ Mistakes ]
[ Accidents ]
[ Failures ]
[ Insiders ]
        |
        V
[ Plan for each type ]

Mini summary

Identifying threats means listing all the dangers that could affect your project.


Lesson 4 โ€” Planning for Mistakes

Definition

Planning for mistakes means thinking about how users might do something wrong and planning for it.

Why it is important

Mistakes are common. If you plan for them, they do not cause big problems.

Simple explanation

Think of a cashier. They might type the wrong amount. You plan for this by asking for confirmation.

Common Mistakes

  • Typing the wrong password
  • Clicking the wrong button
  • Sharing private information
  • Forgetting to log out
  • Sending money to the wrong person

How to Plan for Mistakes

  • Ask for confirmation before important actions
  • Show clear warnings
  • Allow undo for small mistakes
  • Train users
  • Keep backups

Real-life example

A bank asks, "Are you sure you want to send โ‚ฆ50,000?" before sending money.

School example

A school portal asks, "Are you sure you want to submit?" before final submission.

Home example

Your family has a backup key in case someone forgets theirs.

Nigerian example

Nigerian banks ask for confirmation before every large transaction.

Illustration

PLANNING FOR MISTAKES
=====================

[ User makes mistake ]
        |
        V
[ System asks for confirmation ]
        |
        V
[ User corrects the mistake ]
        |
        V
[ No damage done ]

Mini summary

Planning for mistakes means thinking about what users might do wrong and planning for it.


Lesson 5 โ€” Planning for Attacks

Definition

Planning for attacks means thinking about how bad people might attack your system and how to stop them.

Why it is important

Attacks do happen. If you have planned, you can defend your system.

Simple explanation

Think of a castle. It has walls, a moat, and guards. Each protects against a different kind of attack.

Common Attacks

  • Phishing messages
  • Password guessing
  • Malware and ransomware
  • Fake websites
  • Stolen OTPs
  • Insider fraud

How to Plan for Attacks

  • Use strong passwords and 2FA
  • Train users about phishing
  • Use antivirus and firewalls
  • Check everything
  • Keep backups
  • Review and update regularly

Real-life example

A bank uses many layers of defence to stop attacks.

School example

A school trains students about fake exam-result messages.

Home example

Your family does not click strange links.

Nigerian example

Nigerian banks train staff and customers about phishing attacks.

Illustration

PLANNING FOR ATTACKS
====================

[ Attack comes ]
        |
        V
[ Many layers of defence ]
        |
        V
[ Attack blocked ]
        |
        V
[ System stays safe ]

Mini summary

Planning for attacks means thinking about how bad people might attack and how to stop them.


Lesson 6 โ€” Building the Threat Model

Definition

Building the threat model means putting your threats and plans into a simple document.

Why it is important

A written threat model keeps you organised. You can review and update it.

Simple explanation

Think of writing a shopping list. Once it is on paper, you do not forget items.

Steps to Build a Threat Model

  1. Describe what you are building.
  2. List who will use it.
  3. Write down what could go wrong.
  4. Write how you will prevent each problem.
  5. Write what to do if it happens.
  6. Review and update the model.

Real-life example

A bank writes a threat model before launching any new product.

School example

A school writes a threat model before launching a portal.

Home example

Your family writes a simple plan for trips and events.

Nigerian example

Nigerian banks document their threat models formally.

Illustration

BUILDING A THREAT MODEL
=======================

[ Describe project ]
        |
        V
[ List users ]
        |
        V
[ List problems ]
        |
        V
[ Plan prevention ]
        |
        V
[ Plan response ]
        |
        V
[ Review and update ]

Mini summary

Building a threat model means putting your threats and plans into a simple document.


Lesson 7 โ€” Testing Your Design

Definition

Testing your design means checking if your plan works before you build.

Why it is important

Testing finds problems before they become real. It saves time, money, and stress.

Simple explanation

Think of rehearsing a play. You practice before the real show. Testing is the rehearsal for a design.

How to Test a Design

  • Walk through the design step by step.
  • Ask a friend to review it.
  • Try to break your own design.
  • Look for missing principles.
  • Fix problems before building.

Real-life example

A bank tests its new app with a small group before launching to everyone.

School example

A school tests a portal with a few students before opening it to all.

Home example

Your family tests the new Wi-Fi password on one device before changing all.

Nigerian example

Nigerian banks test new features in a safe environment first.

Illustration

TESTING YOUR DESIGN
===================

[ Walk through ]
        |
        V
[ Ask a friend ]
        |
        V
[ Try to break it ]
        |
        V
[ Fix problems ]
        |
        V
[ Ready to build ]

Mini summary

Testing your design means checking if your plan works before you build.


Lesson 8 โ€” Planning for Failures

Definition

Planning for failures means having a backup plan in case something breaks.

Why it is important

Systems fail. If you have a backup, you can recover quickly.

Simple explanation

Think of having a spare tyre in a car. You hope you never need it. But if you do, you are ready.

Common Failures

  • Power cut
  • No internet
  • Broken phone or computer
  • Lost password
  • Data loss

How to Plan for Failures

  • Keep backups
  • Use a spare device if possible
  • Save emergency contacts
  • Keep backup codes for 2FA
  • Write down recovery steps

Real-life example

A bank has backup servers in another city in case of disaster.

School example

A school keeps paper backups of important records.

Home example

Your family keeps a spare key outside the house (safely hidden).

Nigerian example

Nigerian banks have backup systems and power generators.

Illustration

PLANNING FOR FAILURES
=====================

[ Main system ]
        |
        V
[ Something fails ]
        |
        V
[ Backup ready ]
        |
        V
[ System recovers ]

Mini summary

Planning for failures means having a backup plan in case something breaks.


Lesson 9 โ€” Keeping Systems Safe After Building

Definition

Keeping systems safe after building means continuing to protect them after they are launched.

Why it is important

Threats change over time. New attacks appear. You must keep up.

Simple explanation

Think of a garden. You do not just plant it. You water it, weed it, and protect it. Systems are the same.

How to Keep Systems Safe

  • Update apps and systems.
  • Change passwords regularly.
  • Review logs and alerts.
  • Train users often.
  • Test backups.
  • Review your threat model every few months.

Real-life example

A bank updates its apps every month to fix new threats.

School example

A school reviews its portal every term.

Home example

Your family changes the Wi-Fi password every year.

Nigerian example

Nigerian banks update their systems constantly to stop new attacks.

Illustration

KEEPING SYSTEMS SAFE
====================

[ Launch ]
        |
        V
[ Update regularly ]
        |
        V
[ Train users ]
        |
        V
[ Review threat model ]
        |
        V
[ Stay safe over time ]

Mini summary

Keeping systems safe after building means continuing to protect them after they are launched.


Lesson 10 โ€” Learning from Problems

Definition

Learning from problems means studying what went wrong and improving your design.

Why it is important

Mistakes teach us. Learning from them makes us stronger.

Simple explanation

Think of falling off a bicycle. You learn what caused it. Then you ride better.

How to Learn from Problems

  • Write down what went wrong.
  • Find the cause.
  • Plan how to prevent it.
  • Update your design.
  • Tell others.

Real-life example

When a bank has a breach, it studies what happened and improves security.

School example

When a portal fails, the school finds the cause and fixes it.

Home example

When your family's Wi-Fi is hacked, you learn to change the password more often.

Nigerian example

Nigerian banks learn from every incident to stay safer.

Illustration

LEARNING FROM PROBLEMS
======================

[ Problem happens ]
        |
        V
[ What caused it? ]
        |
        V
[ How to prevent it? ]
        |
        V
[ Update the design ]
        |
        V
[ Better system ]

Mini summary

Learning from problems means studying what went wrong and improving your design.


Lesson 11 โ€” Teaching Others About Threats

Definition

Teaching others means sharing what you know so everyone stays safe.

Why it is important

When everyone knows the threats, the whole community becomes stronger.

Simple explanation

Think of a class. If everyone knows the rules, no one breaks them.

What to Teach

  • What could go wrong
  • How to spot threats
  • Safe habits
  • What to do if something happens
  • How to report problems

Real-life example

A bank trains all staff about security threats.

School example

A teacher explains phishing to the class.

Home example

A parent teaches their child about safe browsing.

Nigerian example

Nigerian banks and schools run regular security awareness training.

Illustration

TEACHING OTHERS
===============

[ You learn ]
        |
        V
[ You teach family ]
        |
        V
[ They teach friends ]
        |
        V
[ Community stays safe ]

Mini summary

Teaching others about threats makes the whole community stronger.


Lesson 12 โ€” Becoming a Safe Builder

Definition

A safe builder is someone who plans, tests, and maintains systems with security in mind.

Why it is important

Safe builders protect their projects and their users. They also teach others.

Simple explanation

Think of a careful craftsman. They plan, build, and check their work. A safe builder does the same with systems.

How to Become One

  1. Plan before you build.
  2. Think about threats.
  3. Apply the six principles.
  4. Test your design.
  5. Keep systems safe after building.
  6. Learn from problems.
  7. Teach others.

Real-life example

A cybersecurity professional plans, builds, tests, and reviews systems.

School example

A student designs a school project using all the skills.

Home example

Your family uses safe habits and reviews them regularly.

Nigerian example

Nigerian cybersecurity professionals follow these steps daily.

Illustration

BECOMING A SAFE BUILDER
=======================

[ Plan ]
        |
        V
[ Think threats ]
        |
        V
[ Apply principles ]
        |
        V
[ Test ]
        |
        V
[ Keep safe ]
        |
        V
[ Learn ]
        |
        V
[ Teach others ]

Mini summary

A safe builder plans, tests, and maintains systems with security in mind. Anyone can become one.


5. Key Vocabulary

Word Simple Definition
Threat Anything that could harm your project.
Threat model A plan listing threats and how to stop them.
Attacker Someone who tries to break your system.
Mistake An error made by a user.
Accident Something that happens by chance.
Failure When something stops working.
Insider Someone inside the system with special access.
Backup An extra copy of data in case the original is lost.
Test Checking if something works.
Recovery Getting back to normal after a failure.
Review Looking at something again to find problems.
Safe Builder Someone who builds systems with security in mind.

Summary of Key Vocabulary

These words are the foundation of threat modelling and safe building. Use them often so they become easy.


6. Important Concepts

Concept 1 โ€” Plan for Problems First

Think about what could go wrong before you build. It saves time, money, and stress.

Concept 2 โ€” Threats Come in Many Forms

Attackers, mistakes, accidents, failures, and insiders are all threats.

Concept 3 โ€” Test Before You Build

Testing finds problems early. Fixing them is much cheaper than later.

Concept 4 โ€” Have a Backup Plan

Every system can fail. Plan for recovery.

Concept 5 โ€” Keep Learning and Teaching

Systems change. Threats change. Keep learning and teach others.

Summary of Important Concepts

These five concepts are the heart of Module 3. Read them again before finishing the course.


7. Step-by-step Explanations

Step-by-step: How to Create a Threat Model

  1. Describe what you are building.
  2. List who will use it.
  3. List what could go wrong.
  4. Write how you will prevent each problem.
  5. Write what to do if it happens.
  6. Review and update the model.
CREATING A THREAT MODEL
=======================

[ Describe ]
        |
        V
[ List users ]
        |
        V
[ List threats ]
        |
        V
[ Plan prevention ]
        |
        V
[ Plan response ]
        |
        V
[ Review ]

Step-by-step: How to Test a Design

  1. Walk through the design step by step.
  2. Ask a friend to review it.
  3. Try to break your own design.
  4. Look for missing principles.
  5. Fix problems before building.
  6. Test again after fixing.
TESTING A DESIGN
================

[ Walk through ]
        |
        V
[ Ask a friend ]
        |
        V
[ Try to break ]
        |
        V
[ Fix problems ]
        |
        V
[ Test again ]

Step-by-step: How to Keep Systems Safe After Building

  1. Update apps and systems.
  2. Change passwords regularly.
  3. Review logs and alerts.
  4. Train users often.
  5. Test backups.
  6. Review your threat model every few months.
KEEPING SYSTEMS SAFE
====================

[ Launch ]
        |
        V
[ Update ]
        |
        V
[ Train users ]
        |
        V
[ Review ]
        |
        V
[ Stay safe ]

Summary of Step-by-step Explanations

Creating threat models, testing designs, and keeping systems safe all follow simple steps. Follow them, and your systems stay strong.


8. Real-life Examples

Example 1 โ€” A Bank

A bank creates a threat model before opening a new branch or launching an app.

Example 2 โ€” A Hospital

A hospital plans for power cuts, record losses, and equipment failures.

Example 3 โ€” A School

A school plans for cheating, hacking, and system failures.

Example 4 โ€” An Online Shop

An online shop plans for scams, attacks, and payment failures.

Example 5 โ€” A Government Office

A government office plans for hacking, insider threats, and disasters.

Summary of Real-life Examples

Threat modelling and safe building are used in banks, hospitals, schools, shops, and government offices.


9. Nigerian Examples

Example 1 โ€” Nigerian Banks

Nigerian banks create detailed threat models before launching new products.

Example 2 โ€” Nigerian Fintechs

Paystack and Flutterwave plan for fraud, outages, and attacks.

Example 3 โ€” Nigerian Schools

Nigerian universities plan for cheating, hacking, and system failures.

Example 4 โ€” Nigerian Government

NITDA and NCC plan for cyber attacks and national emergencies.

Example 5 โ€” Nigerian Families

Families plan for theft, fraud, and device loss.

Summary of Nigerian Examples

Nigeria uses threat modelling and safe building in banks, fintechs, schools, government, and families.


10. Fun Examples Children Can Relate To

Example 1 โ€” Planning a Birthday Party

"What if the cake is late? What if guests do not come?" Plan for each.

Example 2 โ€” A School Trip

"What if it rains? What if someone gets lost?" Plan for each.

Example 3 โ€” A Football Match

"What if a player is injured? What if it rains?" Plan substitutes and indoor options.

Example 4 โ€” Building a Sandcastle

"What if the tide comes in?" Build further up the beach.

Example 5 โ€” A Video Game

"What if the player runs out of lives?" Give them a continue option.

Summary of Fun Examples

Threat modelling appears in parties, trips, matches, sandcastles, and video games.


11. Everyday Examples

Situation Threat Modelling
Planning a trip What if it rains?
Cooking a meal What if we run out of gas?
Going to school What if the bus breaks down?
Setting up Wi-Fi What if strangers use it?
Using a bank app What if the app fails?

Summary of Everyday Examples

Even simple daily activities use threat modelling. Now you can see it everywhere.


12. Parent Tips

  1. Ask "what could go wrong?". Do this before trips, events, and projects.
  2. Teach the six principles. Use everyday examples.
  3. Plan together. Involve your child in family planning.
  4. Praise good planning. When your child plans ahead, praise them.
  5. Review plans. Look at them again after events.
  6. Learn from problems. Discuss what went wrong and how to fix it.
  7. Be patient. Planning takes practice.
  8. Keep it fun. Use games and stories.

Summary of Parent Tips

Parents can teach threat modelling and safe building at home through daily planning and simple examples.


13. Interesting Facts

  1. Most successful companies use threat models before launching products.
  2. Fixing a problem after launch costs 100 times more than fixing it during design.
  3. Banks and hospitals test their designs with "what if" scenarios.
  4. Nigerian fintechs use threat modelling before launching new features.
  5. Simple threat models save time and money.
  6. Every safe system was planned by someone thinking about threats.
  7. Teaching others makes the whole community safer.
  8. Learning from every incident makes systems stronger.

Summary of Interesting Facts

Threat modelling is powerful and used everywhere.


14. Did You Know?

  • Did you know that threat modelling is used in every big tech company?
  • Did you know that a simple "what if" list can save millions?
  • Did you know that Nigerian banks review threat models regularly?
  • Did you know that hospitals plan for disasters using threat models?
  • Did you know that teaching others about threats protects the whole community?
  • Did you know that anyone can learn to create a threat model?

Summary of Did You Know?

Threat modelling is full of surprises. The more you learn, the safer you become.


15. Remember This

  • A threat model lists what could go wrong.
  • Always ask "what could go wrong?".
  • Threats include attackers, mistakes, and accidents.
  • Plan for both mistakes and attacks.
  • Test your design before building.
  • Have a backup plan.
  • Keep systems safe after building.
  • Learn from problems.
  • Teach others about threats.
  • Anyone can become a safe builder.

Summary of Remember This

These ten points are the heart of Module 3. Read them again before finishing the course.


16. Common Mistakes

  1. Ignoring "what could go wrong?". This question saves projects.
  2. Only thinking about attackers. Also plan for mistakes and accidents.
  3. Skipping the threat model. Write it down.
  4. Not testing. Test your design before building.
  5. Forgetting backups. Always have a backup plan.
  6. Not reviewing after launch. Review regularly.
  7. Not learning from problems. Mistakes teach us.
  8. Not teaching others. Share what you know.

Summary of Common Mistakes

Avoiding these mistakes will make your systems safer than most.


17. Best Practices

  1. Create a threat model for every project.
  2. Ask "what could go wrong?" for each step.
  3. Plan for mistakes, attacks, and accidents.
  4. Test your design before building.
  5. Keep backups and recovery plans.
  6. Review and update your threat model often.
  7. Learn from every problem.
  8. Teach your family and friends.
  9. Use the six principles from Module 2.
  10. Keep learning and growing.

Summary of Best Practices

These ten practices will help you build strong, safe systems.


18. ASCII Illustrations, Diagrams, Flowcharts, and Timelines

Diagram 1 โ€” Threat Model

THREAT MODEL
============

[ What we're building ]
        |
        V
[ Who will use it ]
        |
        V
[ What could go wrong ]
        |
        V
[ How to prevent it ]
        |
        V
[ What to do if it happens ]

Diagram 2 โ€” Asking "What Could Go Wrong?"

ASK "WHAT COULD GO WRONG?"
==========================

[ What if someone steals? ]
[ What if someone breaks? ]
[ What if the wrong person sees? ]
[ What if power goes off? ]
        |
        V
[ Plan for each problem ]

Diagram 3 โ€” Identifying Threats

IDENTIFYING THREATS
===================

[ Attackers ]
[ Mistakes ]
[ Accidents ]
[ Failures ]
[ Insiders ]
        |
        V
[ Plan for each type ]

Diagram 4 โ€” Testing Your Design

TESTING YOUR DESIGN
===================

[ Walk through ]
        |
        V
[ Ask a friend ]
        |
        V
[ Try to break it ]
        |
        V
[ Fix problems ]
        |
        V
[ Ready to build ]

Diagram 5 โ€” Keeping Systems Safe

KEEPING SYSTEMS SAFE
====================

[ Launch ]
        |
        V
[ Update regularly ]
        |
        V
[ Train users ]
        |
        V
[ Review threat model ]
        |
        V
[ Stay safe ]

Diagram 6 โ€” Becoming a Safe Builder

BECOMING A SAFE BUILDER
=======================

[ Plan ]
        |
        V
[ Think threats ]
        |
        V
[ Apply principles ]
        |
        V
[ Test ]
        |
        V
[ Keep safe ]
        |
        V
[ Learn ]
        |
        V
[ Teach others ]

Summary of Illustrations

These diagrams help you see threat modelling clearly. Draw them yourself to remember them better.


19. Comparison Tables

Table 1 โ€” Threat vs Vulnerability vs Risk

Threat Vulnerability Risk
Something that could harm A weakness The chance of harm
Example: hacker Example: weak password Example: account may be hacked

Table 2 โ€” Types of Threats

Threat Example
Attacker Hacker, scammer, thief
Mistake Typing wrong password, clicking wrong button
Accident Power cut, flood
Failure Broken server, no internet
Insider Employee or family member misusing access

Table 3 โ€” Plan First vs Fix Later

Plan First Fix Later
Cheaper More expensive
Faster Slower
Safer Riskier
Keeps trust Loses trust

Summary of Comparison Tables

Comparing ideas side by side helps you remember the differences clearly.


20. Summary After Every Lesson

Lesson Main Idea
Lesson 1 A threat model lists threats and prevention plans.
Lesson 2 Always ask "what could go wrong?".
Lesson 3 Identify all threats: attackers, mistakes, accidents.
Lesson 4 Plan for mistakes by confirming actions.
Lesson 5 Plan for attacks with many layers.
Lesson 6 Write your threat model down.
Lesson 7 Test your design before building.
Lesson 8 Always have a backup plan.
Lesson 9 Keep systems safe after building.
Lesson 10 Learn from problems to improve.
Lesson 11 Teach others about threats.
Lesson 12 Anyone can become a safe builder.

21. End-of-Module Summary

Congratulations! You have completed Module 3. Let us review what you have learned.

You began by learning what a threat model is โ€” a simple plan that lists what could go wrong and how to stop it.

You learned to always ask "what could go wrong?".

You discovered how to identify threats โ€” attackers, mistakes, accidents, failures, and insiders.

You explored planning for mistakes by confirming actions.

You learned how to plan for attacks with many layers of defence.

You discovered how to build a threat model step by step.

You learned how to test your design before building.

You explored planning for failures with backups and recovery plans.

You learned how to keep systems safe after building.

You discovered how to learn from problems.

You learned how to teach others about threats.

Finally, you learned how to become a safe builder.

MODULE 3 SUMMARY MAP
====================

[ Threat Model ]
        |
        V
[ Ask "What Could Go Wrong?" ] -> [ Identify Threats ]
        |
        V
[ Plan for Mistakes ] -> [ Plan for Attacks ]
        |
        V
[ Build the Model ] -> [ Test the Design ]
        |
        V
[ Plan for Failures ] -> [ Keep Safe After Building ]
        |
        V
[ Learn from Problems ] -> [ Teach Others ] -> [ Safe Builder! ]

Well done! You have completed the entire Security by Design course. You now have strong skills to plan, build, and maintain safe systems.


22. Frequently Asked Questions (10 Questions)

Question 1: What is a threat model?

A threat model is a simple plan that lists what could go wrong in a project and how to stop it.

Question 2: Why is it important?

Because thinking about problems first saves time, money, and stress.

Question 3: What should I ask?

"What could go wrong?"

Question 4: What are the main types of threats?

Attackers, mistakes, accidents, failures, and insiders.

Question 5: How do I plan for mistakes?

Ask for confirmation before important actions. Show clear warnings. Allow undo.

Question 6: How do I plan for attacks?

Use many layers of defence: strong passwords, 2FA, antivirus, and training.

Question 7: How do I test a design?

Walk through it step by step. Ask a friend to review it. Try to break it yourself.

Question 8: What is planning for failures?

Having a backup plan in case something breaks.

Question 9: What does "keeping systems safe after building" mean?

Continuing to update, train, and review your system after it is launched.

Question 10: What did I learn in this module?

How to think about threats, plan for problems, test designs, and keep systems safe.


23. Matching Exercises

Exercise 1 โ€” Match the Word to the Meaning

Column A (Word) Column B (Meaning)
1. Threat model A. Something that could harm
2. Threat B. A plan listing threats
3. Backup C. An error made by a user
4. Mistake D. Getting back to normal after a failure
5. Recovery E. An extra copy of data

Answers: 1-B, 2-A, 3-E, 4-C, 5-D

Exercise 2 โ€” Match the Threat to Its Example

Column A (Threat) Column B (Example)
1. Attacker A. Typing wrong password
2. Mistake B. Hacker
3. Accident C. Staff misusing access
4. Failure D. Power cut
5. Insider E. Broken server

Answers: 1-B, 2-A, 3-D, 4-E, 5-C

Summary of Matching Exercises

Matching helps you connect words to meanings quickly.


24. Scenario-based Exercises

Scenario 1 โ€” The New School Portal

A school is launching a new portal next week. The developers have not created a threat model.

Questions:

  1. What is missing?
  2. What could go wrong?
  3. What should the school do before launching?

Scenario 2 โ€” The Family Wi-Fi

Your family just set up Wi-Fi but did not plan for problems.

Questions:

  1. What could go wrong?
  2. How can you plan for these problems?
  3. What backup options exist?

Scenario 3 โ€” The New Online Shop

A trader is opening an online shop. She has not thought about attacks or failures.

Questions:

  1. What threats should she consider?
  2. How can she plan for them?
  3. What should she do after launching?

Summary of Scenario-based Exercises

These scenarios help you apply what you have learned to real situations.


25. Group Activity

Activity: Build a Simple Threat Model

Group size: 3โ€“5 students

Time: 40 minutes

Materials: Paper, pencil

Instructions:

  1. Choose a simple system (class page, family app, small shop).
  2. Write what it does and who uses it.
  3. List at least 5 threats.
  4. Write how you will prevent each one.
  5. Present your threat model to the class.

Goal: To practise creating a threat model as a team.


26. Individual Activity

Activity: My Personal Threat Model

Time: 20 minutes

Materials: Notebook, pencil

Instructions:

  1. Think of your own daily life.
  2. List 5 things that could go wrong (lost phone, stolen PIN, etc.).
  3. Write how you will prevent each one.
  4. Write what to do if it happens.
  5. Share with your family.

Goal: To apply threat modelling to your own life.


27. Mini Project

Project: Threat Model for a Small Project

Time: 1โ€“2 hours

Materials: Paper, pencil, colour pencils

Instructions:

  1. Choose a small project (school event, family trip, class website).
  2. Write a threat model for it.
  3. Include 5 threats and plans for each.
  4. Include a backup plan.
  5. Present to the class.

Goal: To practise creating a full threat model.


28. Practical Assignment

Assignment: Review a Real System's Threats

Time: 1 week

Materials: Notebook, pencil

Instructions:

  1. Choose a real system (bank app, school portal, family Wi-Fi).
  2. List 5 threats it faces.
  3. List 5 protections it uses.
  4. Identify any missing protections.
  5. Suggest improvements.
  6. Write a short report on what you learned.

Goal: To see threat modelling in real systems.


29. Key Takeaways

  1. A threat model lists what could go wrong.
  2. Always ask "what could go wrong?".
  3. Threats include attackers, mistakes, and accidents.
  4. Plan for both mistakes and attacks.
  5. Test your design before building.
  6. Have a backup plan.
  7. Keep systems safe after building.
  8. Learn from problems.
  9. Teach others about threats.
  10. Anyone can become a safe builder.

30. Classroom Discussion Questions

  1. What is a threat model in your own words?
  2. Why is "what could go wrong?" such a powerful question?
  3. What are the main types of threats?
  4. How can you plan for mistakes?
  5. How can you plan for attacks?
  6. Why is it important to test a design before building?
  7. Why do we need backup plans?
  8. How do we keep systems safe after they are built?
  9. Why is it important to teach others about threats?
  10. What did you enjoy most in this module?

31. Course Completion & Next Steps

You have completed the entire Security by Design course. Well done! Here is what to do next.

  1. Review all modules. Go back through Module 1, 2, and 3. Make sure you can explain every key idea in your own words.
  2. Start using threat models. Create one for your next project.
  3. Apply the six principles. Use them in every design.
  4. Test your ideas. Before building anything, test it.
  5. Teach others. Share what you have learned.
  6. Keep learning. Security by Design is a lifelong skill.
YOUR COURSE JOURNEY
===================

[ Module 1: What is Security by Design? ]
              |
              V
[ Module 2: Principles of Secure Design ]
              |
              V
[ Module 3: Thinking About Threats and Building Safely ]
              |
              V
[ You are now a secure designer and safe builder! ] ๐ŸŽ‰

Congratulations on completing the course. Keep thinking like a secure designer and a safe builder. The world needs people like you.


End of Module 3 โ€” Thinking About Threats and Building Safely

End of the Security by Design Course

โฌ… Back to Course Outline | โฌ… Back to Module 2

Security by Design ยท Beginner Level ยท 2026

๐Ÿ† Get Certified

๐Ÿ”’

Earn this certificate

Every lesson is already free to read. Sign up, pass the exam, and unlock Practice Tools plus a verified certificate with your name on it โ€” โ‚ฆ4,000/month.

๐ŸŽ“ Sign Up & Unlock for โ‚ฆ4,000/month
๐Ÿ› ๏ธ Practice Tools
Hands-on simulators & labs - subscription required.
โ†’
๐ŸŽฏ Internship Tasks
Real-world tasks to build your portfolio - try them free for 7 days, no card required.
โ†’