Threat Modeling Depression
The Story
The premise of Matt’s most-referenced essay is a deliberate import: a security framework, applied to his own mental health.
“Cybersecurity uses threat modeling to identify potential risks, vulnerabilities, and attack vectors within complex systems. This proactive approach allows fortification of defenses and safeguard against potential breaches or cyber-attacks. But what if we could apply this same concept of threat modeling to mental health, specifically focusing on the enigmatic and often debilitating condition some of us know all too well?” (Source 1).
He sets up depression as a system with components and stakeholders — biological, psychological, social, environmental — and walks through it the way an AppSec engineer walks through a target (Source 1). Internal threats: biological imbalances, genetic predisposition, cognitive distortions. External threats: stressful life events, social isolation, stigma. Cognitive threats: hopelessness, self-criticism, rumination (Source 1). Then vulnerabilities and risk factors. Then impact analysis. Then mitigations.
The framework is academic; the disclosures inside it are not. “For me, depression looks like insomnia until 2am and then being glued to my bed in the morning. Wanting nothing to do with the things I know are good for me. It’s clothes piled up in my closet, and ‘when did I shower last?’ and ‘where are all my socks?‘” (Source 1). And: “Depression is the human suit I put on when I need to see people who I don’t want to bother with yet another depressive episode” (Source 1).
The mitigations section is openly personal: “For me, it’s been quite the journey to figure out what works and what doesn’t. I have some cheat codes that I talk about regularly. Lifting, not eating like an asshole, basic hygiene, practicing self compassion, and, a big one for me this last year, sobriety. But there have been other things too. Ketamine saved my life. Finding a good therapist really changed my perspective on things. And I moved my office to a space that had more light” (Source 1).
This isn’t a one-off post — it’s an explicit content pillar. The Shared Security podcast frames the episode around it: “his background as one of the original ‘Security Twits’, his career journey, his passion for mental health advocacy” (Source 2). Tines’ podcast lists “His decision to start creating content about mental health in security” and “Tools for safeguarding your mental health in incident response” as dedicated segments (Source 3).
His own framing of why the cross-domain framing matters: he had cycled through therapists for years and finally found one “who was able to stimulate my intellectual brain while talking through my depression and anxiety… This was it. The intellectual component. The parallels. The view of my mental health as a system. The aerial view of how pieces are fitting together, how this impacts that. It sounded a lot like what I do at work. This is what sparked the idea to apply models I use in cyber security to depression” (Source 1).
Lesson for Creators
The mechanic Matt is using is portable: take a framework your audience already trusts in one domain, and apply it to an adjacent topic they don’t usually associate with that framework. Two things happen. The audience gets a way into a topic that would otherwise feel foreign — security engineers who would tune out of a “self-help” post engage immediately when the format is threat modeling. And the writer earns the right to be vulnerable inside an analytical structure, because the analytics carry the emotional weight. The reason this piece works isn’t the topic and isn’t the framework — it’s the disclosure inside the framework. The framework is the permission slip; the disclosure is the actual asset.
Related
- How to kill impostor syndrome — adjacent mental-pattern essay; same lift-the-stigma intent
- Personal growth — broader index this fits into