I’ll use my approach on you:
Step 1: what is The Problem? In other words in simple words what is not right with what?
The basic approach is to state the Problem then work backwards to the causal mechanism. Along the way it may be possible to implement a containment that prevents the Problem from getting to the Customer in some way. But beyond that the exact tools and methods are based on the nature of the problem. Behavior based problems and physics based problems have very different tools.