<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Threat Modeling Insider (NO INDEX)</title>
    <link>https://staging.toreon.com/en/insights/threat-modeling-insider</link>
    <description>Threat Modeling Insider</description>
    <language>en</language>
    <pubDate>Tue, 25 Aug 2026 15:50:11 GMT</pubDate>
    <dc:date>2026-08-25T15:50:11Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Threat Modeling Insider - June 1 2026 - Toreon</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-1-2026</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-1-2026" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Threat-Modeling-Insider-Thumbnail-2-1.webp" alt="Threat Modeling Insider - June 1 2026 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;53rd Edition – June 2026&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;In this issue, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/amir-kavousian/"&gt;Amir Kavousian&lt;/a&gt;&lt;/strong&gt; from &lt;strong&gt;&lt;a href="https://www.devarmor.com/"&gt;DevArmor&lt;/a&gt;&lt;/strong&gt; explains why threat modelers need to focus less on static documents and more on code.&lt;/p&gt; 
     &lt;p&gt;He breaks down how policies, rules, tests, and fitness functions can make threat models truly live within the systems they describe.&lt;/p&gt; 
     &lt;p&gt;Next over on the Toreon Blog, &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;&lt;strong&gt;Sebastien Deleersnyder&lt;/strong&gt;&lt;/a&gt; expands on the proposed ENISA draft for a Security-by-Design playbook, sharing key insights from our OWASP community input.&lt;/p&gt; 
     &lt;p&gt;We also have plenty of other actionable insights for you, including a core threat modeling lesson from BIML, the story behind a $10,000 iPhone heist, and a practical tip on how to better target your threat models.&lt;/p&gt; 
     &lt;p&gt;Settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-insider-archive/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;In this issue, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/amir-kavousian/"&gt;Amir Kavousian&lt;/a&gt;&lt;/strong&gt; from &lt;strong&gt;&lt;a href="https://www.devarmor.com/"&gt;DevArmor&lt;/a&gt;&lt;/strong&gt; explains why threat modelers need to focus less on static documents and more on code.&lt;/p&gt; 
     &lt;p&gt;He breaks down how policies, rules, tests, and fitness functions can make threat models truly live within the systems they describe.&lt;/p&gt; 
     &lt;p&gt;Next over on the Toreon Blog, &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;&lt;strong&gt;Sebastien Deleersnyder&lt;/strong&gt;&lt;/a&gt; expands on the proposed ENISA draft for a Security-by-Design playbook, sharing key insights from our OWASP community input.&lt;/p&gt; 
     &lt;p&gt;We also have plenty of other actionable insights for you, including a core threat modeling lesson from BIML, the story behind a $10,000 iPhone heist, and a practical tip on how to better target your threat models.&lt;/p&gt; 
     &lt;p&gt;Settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-insider-archive/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;In this edition&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest Article&lt;br&gt;&lt;/b&gt;From findings to guardrails: Closing the threat model enforcement gap&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; ENISA’s secure by design playbook: Good start, hard questions​​&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;/b&gt;&lt;b&gt;&lt;br&gt;&lt;/b&gt;No security meter for AI&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated Content&lt;br&gt;&lt;/b&gt;How easy is it to steal $10,000 from a locked phone?&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;Consider realistic attacker personas​&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt;
       Guest Article 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;From Findings to Guardrails:&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Closing the Threat Model Enforcement Gap&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What Is The Enforcement Gap&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Here is a scene most security practitioners will recognize: a cross-functional team spends two hours in a room with a whiteboard. They map data flows, identify trust boundaries, brainstorm threats using STRIDE, and walk out with a sense of accomplishment. The resulting threat model (a PDF, a Confluence page, maybe an export from a tool) gets filed somewhere reasonable. And then nothing happens.&lt;/p&gt; 
     &lt;p&gt;The threats identified don’t become work tickets with acceptance criteria. The mitigations discussed don’t become policy gates in CI/CD. The architectural constraints agreed upon don’t become linter rules that gate a bad build. Six months later, a penetration test discovers the exact vulnerability the team identified on that whiteboard.&lt;/p&gt; 
     &lt;p&gt;This is what we call “the enforcement gap”: the space between &lt;em&gt;producing&lt;/em&gt; a threat model and &lt;em&gt;operationalizing&lt;/em&gt; it as guardrails that live in developer workflows. And in my experience building security tooling for engineering teams, it is where the vast majority of threat modeling value is lost.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Why the Gap Exists&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The enforcement gap is essentially a systems design problem. Three structural forces keep threat model outputs from becoming enforceable controls:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Abstraction mismatch.&lt;/strong&gt;&lt;br&gt; Threat models speak in the language of risk: “An attacker could exploit insufficient input validation on the API gateway to achieve privilege escalation.” Developers need implementation-level specificity: “All endpoints in /api/v2/admin/* must validate JWT claims against the RBAC policy before processing requests.” The translation between these two levels of abstraction is manual, error-prone, and rarely prioritized.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;No feedback loop.&lt;/strong&gt;&lt;br&gt; A threat model is typically a point-in-time artifact. The system it describes evolves continuously with new endpoints, new data stores, and new integrations. Without a mechanism to detect drift between the threat model and the live system, mitigations that were once adequate become irrelevant, and new attack surfaces emerge unnoticed.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Wrong handoff point.&lt;/strong&gt;&lt;br&gt; Threat models are often handed off as documents to development teams who are already deep in implementation. By the time a developer reads “consider rate-limiting this endpoint,” the endpoint has been in production. The output arrives too late to influence design and too early to inform a specific pull request.&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What "Enforceable" Actually Means&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;When I say enforceable, I don’t mean “written down more clearly.” I mean threat model findings that are translated into automated controls that &lt;em&gt;prevent non-compliant code from reaching production&lt;/em&gt;. Specifically:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Generation guardrails&lt;/strong&gt; that enforce the mitigation plan the threat model defined at code generation time&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Policy gates&lt;/strong&gt; that block a merge if a security requirement isn’t met&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Architecture fitness functions&lt;/strong&gt; that detect structural drift from the threat model’s assumptions&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Security tests&lt;/strong&gt; derived directly from identified threats, running on every commit as integration test, penetration test, and later on as bug bounty scope&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The goal is to make it harder to violate the threat model than to comply with it. Not through bureaucracy, but through automation. This is the spirit of “secure-by-design” and “secure-by-default”.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A Practical Framework: Threat-to-Guardrail Pipeline&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Over the past two years, I’ve been working with security teams to close this gap. The pattern that works is a pipeline that transforms threat model outputs into enforceable artifacts at each stage of the SDLC.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 1: Structured Threat Outputs&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The first requirement is that your threat model produces &lt;em&gt;structured, machine-readable outputs&lt;/em&gt;, not just prose. Each identified threat should have:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;A unique identifier (for traceability)&lt;/li&gt; 
      &lt;li&gt;The component or trust boundary it applies to&lt;/li&gt; 
      &lt;li&gt;The specific security property at risk (confidentiality, integrity, availability, etc.)&lt;/li&gt; 
      &lt;li&gt;One or more mitigations, expressed as testable requirements&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;This is where most processes break down immediately. If your threat model output is a paragraph describing a risk in natural language, there is no automated system that can act on it. Structured output is the bridge.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 2: Mitigation-to-Policy Translation&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Once you have structured mitigations, the next step is translating them into policies that your CI/CD system can evaluate. This is where Policy-as-Code frameworks like Open Policy Agent (OPA) become essential.&lt;/p&gt; 
     &lt;p&gt;Consider a concrete example. Your threat model identifies: &lt;em&gt;“The application stores PII in the user-profile service database. An insider threat could exfiltrate this data if encryption at rest is not enforced.”&lt;/em&gt;&lt;/p&gt; 
     &lt;p&gt;The structured mitigation becomes: &lt;em&gt;“All databases in the&lt;/em&gt;&lt;em&gt;user-profile namespace must have encryption at rest enabled.”&lt;/em&gt;&lt;/p&gt; 
     &lt;p&gt;The OPA policy becomes:&lt;/p&gt; 
     &lt;p&gt;package infrastructure.database&lt;/p&gt; 
     &lt;p&gt;deny[msg] {&lt;/p&gt; 
     &lt;p&gt;input.resource.type == “aws_rds_instance”&lt;/p&gt; 
     &lt;p&gt;input.resource.labels.namespace == “user-profile”&lt;/p&gt; 
     &lt;p&gt;not input.resource.config.storage_encrypted&lt;/p&gt; 
     &lt;p&gt;msg := “TM-042: Database in user-profile namespace must have encryption at rest (threat: insider data exfiltration)”&lt;/p&gt; 
     &lt;p&gt;}&lt;/p&gt; 
     &lt;p&gt;&lt;/p&gt; 
     &lt;p&gt;Notice the TM-042 reference: it traces directly back to the threat model finding. When this gate fires in a pull request, the developer sees exactly what they need to do (“encryption required”), but they also see &lt;em&gt;why&lt;/em&gt;, linked to the specific threat.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 3: Architecture Fitness Functions&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Some threat model assumptions are structural: “The payment service must never directly access the user database” or “All external API calls must route through the API gateway.” These are architectural invariants.&lt;/p&gt; 
     &lt;p&gt;Architecture fitness functions encode these as automated tests. Tools like ArchUnit (Java), dependency-cruiser (JavaScript), or custom linter rules can enforce these controls on every commit:&lt;/p&gt; 
     &lt;p&gt;// dependency-cruiser rule derived from threat model boundary TM-017&lt;/p&gt; 
     &lt;p&gt;{&lt;/p&gt; 
     &lt;p&gt;name: “payment-service-isolation”,&lt;/p&gt; 
     &lt;p&gt;severity: “error”,&lt;/p&gt; 
     &lt;p&gt;comment: “TM-017: Payment service must not directly access user-db (threat: lateral movement after payment service compromise)”,&lt;/p&gt; 
     &lt;p&gt;from: { path: “^src/services/payment” },&lt;/p&gt; 
     &lt;p&gt;to: { path: “^src/services/user/db”, severity: “error” }&lt;/p&gt; 
     &lt;p&gt;}&lt;/p&gt; 
     &lt;p&gt;&lt;/p&gt; 
     &lt;p&gt;When a developer inadvertently introduces a direct database import in the payment service, the build fails because a specific threat model boundary has been violated.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 4: Threat-Derived Security Tests&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Every threat in your model implies a test case. “An attacker could bypass authentication by manipulating the session token” implies a test that attempts exactly that. These are more than just traditional unit tests; they’re &lt;em&gt;abuse cases&lt;/em&gt; encoded as automated tests.&lt;/p&gt; 
     &lt;p&gt;The most effective pattern I’ve seen is generating test scaffolds directly from the threat model. These tests can loosely follow threat categories, although that is not a requirement:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Spoofing&lt;/strong&gt; threats → authentication bypass tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Tampering&lt;/strong&gt; threats → input validation and integrity tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Repudiation&lt;/strong&gt; threats → audit logging verification tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Information Disclosure&lt;/strong&gt; threats → data leakage boundary tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Denial of Service&lt;/strong&gt; threats → rate limiting and resource exhaustion tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Elevation of Privilege&lt;/strong&gt; threats → authorization boundary tests&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The true value starts to be realized when these tests become part of the CI pipeline, running on every pull request and raising an alert if a mitigation control is violated.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 5: Continuous Reconciliation&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The final piece is a mechanism to detect when the live system has drifted from the threat model’s assumptions. This includes:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Automated architecture discovery&lt;/strong&gt; that compares actual service dependencies against the threat model’s data flow diagram&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;New surface detection&lt;/strong&gt; that flags new endpoints, new data stores, or new integrations that weren’t covered in the last threat model&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Mitigation regression alerts&lt;/strong&gt; that fire when a previously-passing security test starts failing&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;This creates the feedback loop that keeps the threat model alive as a living set of constraints that the system continuously validates against.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A Real-World Example&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Let me share a concrete case. A fintech team I worked with had produced a thorough STRIDE-based threat model for their payment processing system. Among the findings: “An attacker who compromises the notification service could pivot to access payment transaction data through a shared database connection pool.”&lt;/p&gt; 
     &lt;p&gt;In the old world, this would live as a line item in a triage spreadsheet. Maybe someone would eventually create a Jira ticket.&lt;/p&gt; 
     &lt;p&gt;Instead, the team:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Created an OPA policy&lt;/strong&gt; that denied any infrastructure-as-code change granting the notification service’s IAM role access to the payments database&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Added a dependency-cruiser rule&lt;/strong&gt; preventing code in the notification service from importing payment data models&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Wrote an integration test&lt;/strong&gt; that verified the notification service could not establish a connection to the payment database, even with valid network access&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Set up drift detection&lt;/strong&gt; that would alert if a new IAM policy was attached to the notification service role&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;Three months later, during a sprint to add payment confirmation notifications, a developer naturally reached for a direct database query to the payments table. The build failed at three different points: the dependency rule, the OPA policy (when they tried to update the IAM role), and the integration test. Each failure message referenced the original threat model finding, explaining &lt;em&gt;why&lt;/em&gt; this boundary existed.&lt;/p&gt; 
     &lt;p&gt;The developer understood the threat, redesigned the feature to use an event-driven approach, and the payment service boundary remained intact.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Getting Started: The 80/20 Path&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;You don’t need to implement all five stages at once. Here’s the progression I recommend:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 1: Structure your outputs.&lt;/strong&gt;&lt;br&gt; Pick your most recent threat model and restructure its findings into a machine-readable format. JSON, YAML, even a well-structured spreadsheet. Each finding needs an ID, component, security property, and testable mitigation.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 2: Pick your top 3 threats and write policies.&lt;/strong&gt;&lt;br&gt; Choose the three findings with the highest risk and clearest mitigation path. Write OPA policies, linter rules, or CI checks that enforce them. Run them in “warn” mode first.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 3: Promote policies to blocking.&lt;/strong&gt;&lt;br&gt; Once you have tuned out false positives, flip the warnings to hard blocks. Your first enforced threat model findings are now live.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 4: Build the feedback loop.&lt;/strong&gt;&lt;br&gt; Add drift detection for covered components. Expand coverage to more findings. Iterate.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;The Cultural Shift&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The technical implementation is the easy part. The harder shift is cultural: moving threat modeling from a “security team activity that produces documents” to a “collaborative process that produces enforceable code.”&lt;/p&gt; 
     &lt;p&gt;When developers see their builds fail with a message like TM-042: Database must have encryption at rest (threat: insider data exfiltration), they start to &lt;em&gt;internalize&lt;/em&gt; the threat model. It’s no longer an abstract document, but it’s a constraint they interact with daily. Over time, they start designing with those constraints in mind from the start.&lt;/p&gt; 
     &lt;p&gt;This is the real win. Not that you caught a violation, but that the next developer doesn’t create one in the first place because the guardrails made the threat model’s reasoning visible and immediate.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Conclusion&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The threat modeling community has made enormous progress on the &lt;em&gt;production&lt;/em&gt; side: better methodologies, better tools, better training. But until we close the enforcement gap, we’re leaving most of that value on the table.&lt;/p&gt; 
     &lt;p&gt;The path forward is not more documents or data flow diagrams. It’s fewer documents and more code: policies, rules, tests, and fitness functions that make threat models &lt;em&gt;live&lt;/em&gt; in the systems they describe. The whiteboard session is where understanding begins. The CI/CD pipeline is where it becomes durable.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;Amir Kavousian is the founder and CEO of DevArmor, an AI-native platform that helps security teams create threat models and turn them into enforceable guardrails. He can be reached on&lt;/em&gt;&lt;a href="https://www.linkedin.com/in/amir-kavousian/"&gt;&lt;em&gt;LinkedIn&lt;/em&gt;&lt;/a&gt;&lt;em&gt;or at&lt;/em&gt;&lt;a href="mailto:amir@devarmor.com"&gt;&lt;em&gt;amir@devarmor.com&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt; 
        &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Browse Trainings&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;ENISA’s Secure by Design Playbook: Good Start, Hard Questions&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;p&gt;ENISA deserves credit.&lt;/p&gt; 
            &lt;p&gt;Its&amp;nbsp;&lt;a href="https://www.enisa.europa.eu/sites/default/files/2026-03/ENISA_Secure_By_Design_and_Default_Playbook_v0.4_draft_for_consultation.pdf"&gt;&lt;em&gt;Security by Design and Default Playbook&lt;/em&gt;&lt;/a&gt;&amp;nbsp;tackles a problem many product teams already&amp;nbsp;face:&amp;nbsp;how to translate high-level secure-by-design expectations into practical engineering work. The playbook&amp;nbsp;provides SMEs and manufacturers&amp;nbsp;with&amp;nbsp;concrete actions, release gates, and evidence expectations&amp;nbsp;rather&amp;nbsp;than&amp;nbsp;another abstract security framework. That matters under the&amp;nbsp;&lt;a href="https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act"&gt;Cyber Resilience Act&lt;/a&gt;, where “we thought about security” will not be enough. ENISA’s draft maps secure-by-design and secure-by-default principles to lifecycle activities, practical playbooks, and CRA-related evidence expectations.&lt;/p&gt; 
            &lt;p&gt;The question is not whether the playbook is useful.&amp;nbsp;It is.&lt;/p&gt; 
            &lt;p&gt;The harder question is whether teams will use it to improve product security, or whether it becomes another checklist that product teams complete without changing design decisions.&amp;nbsp;That distinction is where threat modeling matters.&lt;/p&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/enisa-secure-by-design-threat-modeling-training/"&gt;Read the blog&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;&lt;br&gt; Curated Content&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;NO SECURITY METER FOR AI&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Your AI scored 92% secure — please enjoy this beautifully calibrated false sense of safety.” Relevant for our readers because this BIML paper lands squarely on a core threat modeling lesson: security is not a leaderboard score, a benchmark result, or a shiny “AI safety” badge. It argues that AI security is an emergent system property, so teams need to model architecture, data provenance, agent behavior, assurance processes, and failure modes rather than trusting black-box benchmark scores as a proxy for real resilience.&lt;/p&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;How easy is it to steal $10,000 from a locked phone?&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;p&gt;The $10,000 “Express” Leak – In a sleek collaboration with MKBHD, Veritasium demonstrates a “nerdy David Blaine” stunt siphoning $10,000 from a locked iPhone by exploiting Apple’s Express Transit mode. For threat modelers, it’s a masterclass in trust boundary erosion: a feature designed for $2 subway fares was tricked into authorizing a high-value heist because the design assumed “transit” always meant “low-risk.” It’s a reminder that when we bridge a gap for convenience, we often build the exact path an attacker needs to bypass our strongest authentication.&lt;/p&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://berryvilleiml.com/docs/no-security-meter-ai.pdf"&gt;Read more&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.youtube.com/watch?v=PPJ6NJkmDAo"&gt;Watch video&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;ENISA’s Secure by Design Playbook: Good Start, Hard Questions​&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;p&gt;Your AI scored 92% secure — please enjoy this beautifully calibrated false sense of safety.” Relevant for our readers because this BIML paper lands squarely on a core threat modeling lesson: security is not a leaderboard score, a benchmark result, or a shiny “AI safety” badge. It argues that AI security is an emergent system property, so teams need to model architecture, data provenance, agent behavior, assurance processes, and failure modes rather than trusting black-box benchmark scores as a proxy for real resilience.&lt;/p&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/enisa-secure-by-design-threat-modeling-training/"&gt;Read the blog&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;&lt;br&gt; Curated Content&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;NO SECURITY METER FOR AI&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;Your AI scored 92% secure — please enjoy this beautifully calibrated false sense of safety.” Relevant for our readers because this BIML paper lands squarely on a core threat modeling lesson: security is not a leaderboard score, a benchmark result, or a shiny “AI safety” badge. It argues that AI security is an emergent system property, so teams need to model architecture, data provenance, agent behavior, assurance processes, and failure modes rather than trusting black-box benchmark scores as a proxy for real resilience.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://berryvilleiml.com/docs/no-security-meter-ai.pdf"&gt;Read more&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;How easy is it to steal $10,000 from a locked phone?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;div&gt; 
              &lt;div&gt; 
               &lt;div&gt; 
                &lt;div&gt; 
                 &lt;div&gt; 
                  &lt;div&gt; 
                   &lt;p&gt;The $10,000 “Express” Leak – In a sleek collaboration with MKBHD, Veritasium demonstrates a “nerdy David Blaine” stunt siphoning $10,000 from a locked iPhone by exploiting Apple’s Express Transit mode. For threat modelers, it’s a masterclass in trust boundary erosion: a feature designed for $2 subway fares was tricked into authorizing a high-value heist because the design assumed “transit” always meant “low-risk.” It’s a reminder that when we bridge a gap for convenience, we often build the exact path an attacker needs to bypass our strongest authentication.&lt;/p&gt; 
                  &lt;/div&gt; 
                 &lt;/div&gt; 
                &lt;/div&gt; 
               &lt;/div&gt; 
              &lt;/div&gt; 
             &lt;/div&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.youtube.com/watch?v=PPJ6NJkmDAo"&gt;Watch video&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Consider realistic attacker personas&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Model threats from the perspective of realistic attacker personas relevant for your system. The same system has different risks depending on whether the attacker is an insider, external cybercriminal, competitor, hacktivist, or nation-state actor.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.youtube.com/@ApplicationSecurityPodcast"&gt;Go to channel&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking aka Hands-on Threat Modeling Training, TROOPERS, Heidelberg&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-23 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://troopers.de/troopers26/trainings/hzpsck/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;2 Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling, in-person, OWASP Global AppSec USA, San Francisco&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;3-4 November 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://tickets.ernw.de/troopers/tr26/?event=HZPSCK"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking aka Hands-on Threat Modeling Training, TROOPERS, Heidelberg&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-23 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://troopers.de/troopers26/trainings/hzpsck/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;2 Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling, in-person, OWASP Global AppSec USA, San Francisco&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;3-4&lt;/em&gt;&lt;em&gt;November 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappsecusa2026.sched.com/event/2O5GN"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Webinar – Threat Modeling in the Age of Mythos:&lt;/strong&gt;&lt;br&gt; What Threat Modelers Need to Do Differently&lt;br&gt; June 30 | 8 AM – 8:45 AM (EDT), Webinar together with QA&lt;/p&gt; 
     &lt;p&gt;Join &lt;b&gt;Toreon&lt;/b&gt;&amp;nbsp;and our partner &lt;b&gt;QA&lt;/b&gt;&amp;nbsp;for a timely discussion on how AI-enabled security capabilities, including Anthropic’s Mythos, are changing the way organizations approach application security, product security, and secure-by-design practices.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.qa.com/resources/events/threat-modelling-in-the-age-of-mythos-what-threat-modelers-need-to-do-differently/"&gt;Register&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Conference – ThreatModCon Vienna&lt;/strong&gt;&lt;br&gt; 26 – 27 June | Meliá Vienna&lt;/p&gt; 
     &lt;p&gt;Gather with the world’s leading security architects and engineers in the heart of Vienna. Join us for a full day of uncompromising, deeply technical focus.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.threatmodcon.com/vienna-2026"&gt;More info&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://zoom.us/meeting/register/eRPxJhaHQ42wzEralV4rVg?utm_campaign=351069431-US%20Requests%202026&amp;amp;utm_content=565702899&amp;amp;utm_medium=social&amp;amp;utm_source=linkedin&amp;amp;hss_channel=lcp-3499405"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-1-2026" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Threat-Modeling-Insider-Thumbnail-2-1.webp" alt="Threat Modeling Insider - June 1 2026 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;53rd Edition – June 2026&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;In this issue, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/amir-kavousian/"&gt;Amir Kavousian&lt;/a&gt;&lt;/strong&gt; from &lt;strong&gt;&lt;a href="https://www.devarmor.com/"&gt;DevArmor&lt;/a&gt;&lt;/strong&gt; explains why threat modelers need to focus less on static documents and more on code.&lt;/p&gt; 
     &lt;p&gt;He breaks down how policies, rules, tests, and fitness functions can make threat models truly live within the systems they describe.&lt;/p&gt; 
     &lt;p&gt;Next over on the Toreon Blog, &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;&lt;strong&gt;Sebastien Deleersnyder&lt;/strong&gt;&lt;/a&gt; expands on the proposed ENISA draft for a Security-by-Design playbook, sharing key insights from our OWASP community input.&lt;/p&gt; 
     &lt;p&gt;We also have plenty of other actionable insights for you, including a core threat modeling lesson from BIML, the story behind a $10,000 iPhone heist, and a practical tip on how to better target your threat models.&lt;/p&gt; 
     &lt;p&gt;Settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-insider-archive/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;In this issue, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/amir-kavousian/"&gt;Amir Kavousian&lt;/a&gt;&lt;/strong&gt; from &lt;strong&gt;&lt;a href="https://www.devarmor.com/"&gt;DevArmor&lt;/a&gt;&lt;/strong&gt; explains why threat modelers need to focus less on static documents and more on code.&lt;/p&gt; 
     &lt;p&gt;He breaks down how policies, rules, tests, and fitness functions can make threat models truly live within the systems they describe.&lt;/p&gt; 
     &lt;p&gt;Next over on the Toreon Blog, &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;&lt;strong&gt;Sebastien Deleersnyder&lt;/strong&gt;&lt;/a&gt; expands on the proposed ENISA draft for a Security-by-Design playbook, sharing key insights from our OWASP community input.&lt;/p&gt; 
     &lt;p&gt;We also have plenty of other actionable insights for you, including a core threat modeling lesson from BIML, the story behind a $10,000 iPhone heist, and a practical tip on how to better target your threat models.&lt;/p&gt; 
     &lt;p&gt;Settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-insider-archive/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;In this edition&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest Article&lt;br&gt;&lt;/b&gt;From findings to guardrails: Closing the threat model enforcement gap&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; ENISA’s secure by design playbook: Good start, hard questions​​&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;/b&gt;&lt;b&gt;&lt;br&gt;&lt;/b&gt;No security meter for AI&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated Content&lt;br&gt;&lt;/b&gt;How easy is it to steal $10,000 from a locked phone?&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;Consider realistic attacker personas​&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt;
       Guest Article 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;From Findings to Guardrails:&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Closing the Threat Model Enforcement Gap&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What Is The Enforcement Gap&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Here is a scene most security practitioners will recognize: a cross-functional team spends two hours in a room with a whiteboard. They map data flows, identify trust boundaries, brainstorm threats using STRIDE, and walk out with a sense of accomplishment. The resulting threat model (a PDF, a Confluence page, maybe an export from a tool) gets filed somewhere reasonable. And then nothing happens.&lt;/p&gt; 
     &lt;p&gt;The threats identified don’t become work tickets with acceptance criteria. The mitigations discussed don’t become policy gates in CI/CD. The architectural constraints agreed upon don’t become linter rules that gate a bad build. Six months later, a penetration test discovers the exact vulnerability the team identified on that whiteboard.&lt;/p&gt; 
     &lt;p&gt;This is what we call “the enforcement gap”: the space between &lt;em&gt;producing&lt;/em&gt; a threat model and &lt;em&gt;operationalizing&lt;/em&gt; it as guardrails that live in developer workflows. And in my experience building security tooling for engineering teams, it is where the vast majority of threat modeling value is lost.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Why the Gap Exists&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The enforcement gap is essentially a systems design problem. Three structural forces keep threat model outputs from becoming enforceable controls:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Abstraction mismatch.&lt;/strong&gt;&lt;br&gt; Threat models speak in the language of risk: “An attacker could exploit insufficient input validation on the API gateway to achieve privilege escalation.” Developers need implementation-level specificity: “All endpoints in /api/v2/admin/* must validate JWT claims against the RBAC policy before processing requests.” The translation between these two levels of abstraction is manual, error-prone, and rarely prioritized.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;No feedback loop.&lt;/strong&gt;&lt;br&gt; A threat model is typically a point-in-time artifact. The system it describes evolves continuously with new endpoints, new data stores, and new integrations. Without a mechanism to detect drift between the threat model and the live system, mitigations that were once adequate become irrelevant, and new attack surfaces emerge unnoticed.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Wrong handoff point.&lt;/strong&gt;&lt;br&gt; Threat models are often handed off as documents to development teams who are already deep in implementation. By the time a developer reads “consider rate-limiting this endpoint,” the endpoint has been in production. The output arrives too late to influence design and too early to inform a specific pull request.&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What "Enforceable" Actually Means&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;When I say enforceable, I don’t mean “written down more clearly.” I mean threat model findings that are translated into automated controls that &lt;em&gt;prevent non-compliant code from reaching production&lt;/em&gt;. Specifically:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Generation guardrails&lt;/strong&gt; that enforce the mitigation plan the threat model defined at code generation time&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Policy gates&lt;/strong&gt; that block a merge if a security requirement isn’t met&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Architecture fitness functions&lt;/strong&gt; that detect structural drift from the threat model’s assumptions&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Security tests&lt;/strong&gt; derived directly from identified threats, running on every commit as integration test, penetration test, and later on as bug bounty scope&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The goal is to make it harder to violate the threat model than to comply with it. Not through bureaucracy, but through automation. This is the spirit of “secure-by-design” and “secure-by-default”.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A Practical Framework: Threat-to-Guardrail Pipeline&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Over the past two years, I’ve been working with security teams to close this gap. The pattern that works is a pipeline that transforms threat model outputs into enforceable artifacts at each stage of the SDLC.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 1: Structured Threat Outputs&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The first requirement is that your threat model produces &lt;em&gt;structured, machine-readable outputs&lt;/em&gt;, not just prose. Each identified threat should have:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;A unique identifier (for traceability)&lt;/li&gt; 
      &lt;li&gt;The component or trust boundary it applies to&lt;/li&gt; 
      &lt;li&gt;The specific security property at risk (confidentiality, integrity, availability, etc.)&lt;/li&gt; 
      &lt;li&gt;One or more mitigations, expressed as testable requirements&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;This is where most processes break down immediately. If your threat model output is a paragraph describing a risk in natural language, there is no automated system that can act on it. Structured output is the bridge.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 2: Mitigation-to-Policy Translation&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Once you have structured mitigations, the next step is translating them into policies that your CI/CD system can evaluate. This is where Policy-as-Code frameworks like Open Policy Agent (OPA) become essential.&lt;/p&gt; 
     &lt;p&gt;Consider a concrete example. Your threat model identifies: &lt;em&gt;“The application stores PII in the user-profile service database. An insider threat could exfiltrate this data if encryption at rest is not enforced.”&lt;/em&gt;&lt;/p&gt; 
     &lt;p&gt;The structured mitigation becomes: &lt;em&gt;“All databases in the&lt;/em&gt;&lt;em&gt;user-profile namespace must have encryption at rest enabled.”&lt;/em&gt;&lt;/p&gt; 
     &lt;p&gt;The OPA policy becomes:&lt;/p&gt; 
     &lt;p&gt;package infrastructure.database&lt;/p&gt; 
     &lt;p&gt;deny[msg] {&lt;/p&gt; 
     &lt;p&gt;input.resource.type == “aws_rds_instance”&lt;/p&gt; 
     &lt;p&gt;input.resource.labels.namespace == “user-profile”&lt;/p&gt; 
     &lt;p&gt;not input.resource.config.storage_encrypted&lt;/p&gt; 
     &lt;p&gt;msg := “TM-042: Database in user-profile namespace must have encryption at rest (threat: insider data exfiltration)”&lt;/p&gt; 
     &lt;p&gt;}&lt;/p&gt; 
     &lt;p&gt;&lt;/p&gt; 
     &lt;p&gt;Notice the TM-042 reference: it traces directly back to the threat model finding. When this gate fires in a pull request, the developer sees exactly what they need to do (“encryption required”), but they also see &lt;em&gt;why&lt;/em&gt;, linked to the specific threat.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 3: Architecture Fitness Functions&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Some threat model assumptions are structural: “The payment service must never directly access the user database” or “All external API calls must route through the API gateway.” These are architectural invariants.&lt;/p&gt; 
     &lt;p&gt;Architecture fitness functions encode these as automated tests. Tools like ArchUnit (Java), dependency-cruiser (JavaScript), or custom linter rules can enforce these controls on every commit:&lt;/p&gt; 
     &lt;p&gt;// dependency-cruiser rule derived from threat model boundary TM-017&lt;/p&gt; 
     &lt;p&gt;{&lt;/p&gt; 
     &lt;p&gt;name: “payment-service-isolation”,&lt;/p&gt; 
     &lt;p&gt;severity: “error”,&lt;/p&gt; 
     &lt;p&gt;comment: “TM-017: Payment service must not directly access user-db (threat: lateral movement after payment service compromise)”,&lt;/p&gt; 
     &lt;p&gt;from: { path: “^src/services/payment” },&lt;/p&gt; 
     &lt;p&gt;to: { path: “^src/services/user/db”, severity: “error” }&lt;/p&gt; 
     &lt;p&gt;}&lt;/p&gt; 
     &lt;p&gt;&lt;/p&gt; 
     &lt;p&gt;When a developer inadvertently introduces a direct database import in the payment service, the build fails because a specific threat model boundary has been violated.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 4: Threat-Derived Security Tests&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Every threat in your model implies a test case. “An attacker could bypass authentication by manipulating the session token” implies a test that attempts exactly that. These are more than just traditional unit tests; they’re &lt;em&gt;abuse cases&lt;/em&gt; encoded as automated tests.&lt;/p&gt; 
     &lt;p&gt;The most effective pattern I’ve seen is generating test scaffolds directly from the threat model. These tests can loosely follow threat categories, although that is not a requirement:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Spoofing&lt;/strong&gt; threats → authentication bypass tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Tampering&lt;/strong&gt; threats → input validation and integrity tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Repudiation&lt;/strong&gt; threats → audit logging verification tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Information Disclosure&lt;/strong&gt; threats → data leakage boundary tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Denial of Service&lt;/strong&gt; threats → rate limiting and resource exhaustion tests&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Elevation of Privilege&lt;/strong&gt; threats → authorization boundary tests&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;The true value starts to be realized when these tests become part of the CI pipeline, running on every pull request and raising an alert if a mitigation control is violated.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h4&gt;Stage 5: Continuous Reconciliation&lt;/h4&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The final piece is a mechanism to detect when the live system has drifted from the threat model’s assumptions. This includes:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Automated architecture discovery&lt;/strong&gt; that compares actual service dependencies against the threat model’s data flow diagram&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;New surface detection&lt;/strong&gt; that flags new endpoints, new data stores, or new integrations that weren’t covered in the last threat model&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Mitigation regression alerts&lt;/strong&gt; that fire when a previously-passing security test starts failing&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;This creates the feedback loop that keeps the threat model alive as a living set of constraints that the system continuously validates against.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A Real-World Example&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Let me share a concrete case. A fintech team I worked with had produced a thorough STRIDE-based threat model for their payment processing system. Among the findings: “An attacker who compromises the notification service could pivot to access payment transaction data through a shared database connection pool.”&lt;/p&gt; 
     &lt;p&gt;In the old world, this would live as a line item in a triage spreadsheet. Maybe someone would eventually create a Jira ticket.&lt;/p&gt; 
     &lt;p&gt;Instead, the team:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Created an OPA policy&lt;/strong&gt; that denied any infrastructure-as-code change granting the notification service’s IAM role access to the payments database&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Added a dependency-cruiser rule&lt;/strong&gt; preventing code in the notification service from importing payment data models&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Wrote an integration test&lt;/strong&gt; that verified the notification service could not establish a connection to the payment database, even with valid network access&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Set up drift detection&lt;/strong&gt; that would alert if a new IAM policy was attached to the notification service role&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;Three months later, during a sprint to add payment confirmation notifications, a developer naturally reached for a direct database query to the payments table. The build failed at three different points: the dependency rule, the OPA policy (when they tried to update the IAM role), and the integration test. Each failure message referenced the original threat model finding, explaining &lt;em&gt;why&lt;/em&gt; this boundary existed.&lt;/p&gt; 
     &lt;p&gt;The developer understood the threat, redesigned the feature to use an event-driven approach, and the payment service boundary remained intact.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Getting Started: The 80/20 Path&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;You don’t need to implement all five stages at once. Here’s the progression I recommend:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 1: Structure your outputs.&lt;/strong&gt;&lt;br&gt; Pick your most recent threat model and restructure its findings into a machine-readable format. JSON, YAML, even a well-structured spreadsheet. Each finding needs an ID, component, security property, and testable mitigation.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 2: Pick your top 3 threats and write policies.&lt;/strong&gt;&lt;br&gt; Choose the three findings with the highest risk and clearest mitigation path. Write OPA policies, linter rules, or CI checks that enforce them. Run them in “warn” mode first.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 3: Promote policies to blocking.&lt;/strong&gt;&lt;br&gt; Once you have tuned out false positives, flip the warnings to hard blocks. Your first enforced threat model findings are now live.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Step 4: Build the feedback loop.&lt;/strong&gt;&lt;br&gt; Add drift detection for covered components. Expand coverage to more findings. Iterate.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;The Cultural Shift&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The technical implementation is the easy part. The harder shift is cultural: moving threat modeling from a “security team activity that produces documents” to a “collaborative process that produces enforceable code.”&lt;/p&gt; 
     &lt;p&gt;When developers see their builds fail with a message like TM-042: Database must have encryption at rest (threat: insider data exfiltration), they start to &lt;em&gt;internalize&lt;/em&gt; the threat model. It’s no longer an abstract document, but it’s a constraint they interact with daily. Over time, they start designing with those constraints in mind from the start.&lt;/p&gt; 
     &lt;p&gt;This is the real win. Not that you caught a violation, but that the next developer doesn’t create one in the first place because the guardrails made the threat model’s reasoning visible and immediate.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Conclusion&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The threat modeling community has made enormous progress on the &lt;em&gt;production&lt;/em&gt; side: better methodologies, better tools, better training. But until we close the enforcement gap, we’re leaving most of that value on the table.&lt;/p&gt; 
     &lt;p&gt;The path forward is not more documents or data flow diagrams. It’s fewer documents and more code: policies, rules, tests, and fitness functions that make threat models &lt;em&gt;live&lt;/em&gt; in the systems they describe. The whiteboard session is where understanding begins. The CI/CD pipeline is where it becomes durable.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;Amir Kavousian is the founder and CEO of DevArmor, an AI-native platform that helps security teams create threat models and turn them into enforceable guardrails. He can be reached on&lt;/em&gt;&lt;a href="https://www.linkedin.com/in/amir-kavousian/"&gt;&lt;em&gt;LinkedIn&lt;/em&gt;&lt;/a&gt;&lt;em&gt;or at&lt;/em&gt;&lt;a href="mailto:amir@devarmor.com"&gt;&lt;em&gt;amir@devarmor.com&lt;/em&gt;&lt;/a&gt;&lt;em&gt;.&lt;/em&gt;&lt;/p&gt; 
        &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Browse Trainings&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;ENISA’s Secure by Design Playbook: Good Start, Hard Questions&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;p&gt;ENISA deserves credit.&lt;/p&gt; 
            &lt;p&gt;Its&amp;nbsp;&lt;a href="https://www.enisa.europa.eu/sites/default/files/2026-03/ENISA_Secure_By_Design_and_Default_Playbook_v0.4_draft_for_consultation.pdf"&gt;&lt;em&gt;Security by Design and Default Playbook&lt;/em&gt;&lt;/a&gt;&amp;nbsp;tackles a problem many product teams already&amp;nbsp;face:&amp;nbsp;how to translate high-level secure-by-design expectations into practical engineering work. The playbook&amp;nbsp;provides SMEs and manufacturers&amp;nbsp;with&amp;nbsp;concrete actions, release gates, and evidence expectations&amp;nbsp;rather&amp;nbsp;than&amp;nbsp;another abstract security framework. That matters under the&amp;nbsp;&lt;a href="https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act"&gt;Cyber Resilience Act&lt;/a&gt;, where “we thought about security” will not be enough. ENISA’s draft maps secure-by-design and secure-by-default principles to lifecycle activities, practical playbooks, and CRA-related evidence expectations.&lt;/p&gt; 
            &lt;p&gt;The question is not whether the playbook is useful.&amp;nbsp;It is.&lt;/p&gt; 
            &lt;p&gt;The harder question is whether teams will use it to improve product security, or whether it becomes another checklist that product teams complete without changing design decisions.&amp;nbsp;That distinction is where threat modeling matters.&lt;/p&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/enisa-secure-by-design-threat-modeling-training/"&gt;Read the blog&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;&lt;br&gt; Curated Content&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;NO SECURITY METER FOR AI&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Your AI scored 92% secure — please enjoy this beautifully calibrated false sense of safety.” Relevant for our readers because this BIML paper lands squarely on a core threat modeling lesson: security is not a leaderboard score, a benchmark result, or a shiny “AI safety” badge. It argues that AI security is an emergent system property, so teams need to model architecture, data provenance, agent behavior, assurance processes, and failure modes rather than trusting black-box benchmark scores as a proxy for real resilience.&lt;/p&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;How easy is it to steal $10,000 from a locked phone?&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;p&gt;The $10,000 “Express” Leak – In a sleek collaboration with MKBHD, Veritasium demonstrates a “nerdy David Blaine” stunt siphoning $10,000 from a locked iPhone by exploiting Apple’s Express Transit mode. For threat modelers, it’s a masterclass in trust boundary erosion: a feature designed for $2 subway fares was tricked into authorizing a high-value heist because the design assumed “transit” always meant “low-risk.” It’s a reminder that when we bridge a gap for convenience, we often build the exact path an attacker needs to bypass our strongest authentication.&lt;/p&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://berryvilleiml.com/docs/no-security-meter-ai.pdf"&gt;Read more&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.youtube.com/watch?v=PPJ6NJkmDAo"&gt;Watch video&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;ENISA’s Secure by Design Playbook: Good Start, Hard Questions​&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;p&gt;Your AI scored 92% secure — please enjoy this beautifully calibrated false sense of safety.” Relevant for our readers because this BIML paper lands squarely on a core threat modeling lesson: security is not a leaderboard score, a benchmark result, or a shiny “AI safety” badge. It argues that AI security is an emergent system property, so teams need to model architecture, data provenance, agent behavior, assurance processes, and failure modes rather than trusting black-box benchmark scores as a proxy for real resilience.&lt;/p&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/enisa-secure-by-design-threat-modeling-training/"&gt;Read the blog&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;&lt;br&gt; Curated Content&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;NO SECURITY METER FOR AI&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;p&gt;Your AI scored 92% secure — please enjoy this beautifully calibrated false sense of safety.” Relevant for our readers because this BIML paper lands squarely on a core threat modeling lesson: security is not a leaderboard score, a benchmark result, or a shiny “AI safety” badge. It argues that AI security is an emergent system property, so teams need to model architecture, data provenance, agent behavior, assurance processes, and failure modes rather than trusting black-box benchmark scores as a proxy for real resilience.&lt;/p&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://berryvilleiml.com/docs/no-security-meter-ai.pdf"&gt;Read more&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;How easy is it to steal $10,000 from a locked phone?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;div&gt; 
              &lt;div&gt; 
               &lt;div&gt; 
                &lt;div&gt; 
                 &lt;div&gt; 
                  &lt;div&gt; 
                   &lt;p&gt;The $10,000 “Express” Leak – In a sleek collaboration with MKBHD, Veritasium demonstrates a “nerdy David Blaine” stunt siphoning $10,000 from a locked iPhone by exploiting Apple’s Express Transit mode. For threat modelers, it’s a masterclass in trust boundary erosion: a feature designed for $2 subway fares was tricked into authorizing a high-value heist because the design assumed “transit” always meant “low-risk.” It’s a reminder that when we bridge a gap for convenience, we often build the exact path an attacker needs to bypass our strongest authentication.&lt;/p&gt; 
                  &lt;/div&gt; 
                 &lt;/div&gt; 
                &lt;/div&gt; 
               &lt;/div&gt; 
              &lt;/div&gt; 
             &lt;/div&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.youtube.com/watch?v=PPJ6NJkmDAo"&gt;Watch video&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Consider realistic attacker personas&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Model threats from the perspective of realistic attacker personas relevant for your system. The same system has different risks depending on whether the attacker is an insider, external cybercriminal, competitor, hacktivist, or nation-state actor.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.youtube.com/@ApplicationSecurityPodcast"&gt;Go to channel&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;br&gt;&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking aka Hands-on Threat Modeling Training, TROOPERS, Heidelberg&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-23 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://troopers.de/troopers26/trainings/hzpsck/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;2 Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling, in-person, OWASP Global AppSec USA, San Francisco&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;3-4 November 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://tickets.ernw.de/troopers/tr26/?event=HZPSCK"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking aka Hands-on Threat Modeling Training, TROOPERS, Heidelberg&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-23 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://troopers.de/troopers26/trainings/hzpsck/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;2 Day Training: Beyond Whiteboard Hacking: Embracing AI-Assisted Threat Modeling, in-person, OWASP Global AppSec USA, San Francisco&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;3-4&lt;/em&gt;&lt;em&gt;November 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappsecusa2026.sched.com/event/2O5GN"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Webinar – Threat Modeling in the Age of Mythos:&lt;/strong&gt;&lt;br&gt; What Threat Modelers Need to Do Differently&lt;br&gt; June 30 | 8 AM – 8:45 AM (EDT), Webinar together with QA&lt;/p&gt; 
     &lt;p&gt;Join &lt;b&gt;Toreon&lt;/b&gt;&amp;nbsp;and our partner &lt;b&gt;QA&lt;/b&gt;&amp;nbsp;for a timely discussion on how AI-enabled security capabilities, including Anthropic’s Mythos, are changing the way organizations approach application security, product security, and secure-by-design practices.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.qa.com/resources/events/threat-modelling-in-the-age-of-mythos-what-threat-modelers-need-to-do-differently/"&gt;Register&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Conference – ThreatModCon Vienna&lt;/strong&gt;&lt;br&gt; 26 – 27 June | Meliá Vienna&lt;/p&gt; 
     &lt;p&gt;Gather with the world’s leading security architects and engineers in the heart of Vienna. Join us for a full day of uncompromising, deeply technical focus.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.threatmodcon.com/vienna-2026"&gt;More info&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://zoom.us/meeting/register/eRPxJhaHQ42wzEralV4rVg?utm_campaign=351069431-US%20Requests%202026&amp;amp;utm_content=565702899&amp;amp;utm_medium=social&amp;amp;utm_source=linkedin&amp;amp;hss_channel=lcp-3499405"&gt;&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthreat-modeling-insider-june-1-2026&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <pubDate>Mon, 01 Jun 2026 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-1-2026</guid>
      <dc:date>2026-06-01T22:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Threat Modeling Insider - February 2026 - Toreon</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-february-2026</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-february-2026" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/TMI-46-Thumbnail-1-1.webp" alt="Threat Modeling Insider - February 2026 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;51st Edition – February 2026&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;In this edition, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/dimitri-van-landuyt-4b881b2/"&gt;Dimitri Van Landuyt&lt;/a&gt;&lt;/strong&gt; shares his view on usign LLM tools for complete threat models.&lt;/p&gt; 
     &lt;p&gt;Next, on the Toreon Blog, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;Georges Bolssens&lt;/a&gt;&lt;/strong&gt; shares his take on “Managing unknowns assumptions in Threat Modeling”. Very interesting read on hidden risks.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;In this edition, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/dimitri-van-landuyt-4b881b2/"&gt;Dimitri Van Landuyt&lt;/a&gt;&lt;/strong&gt; shares his view on usign LLM tools for complete threat models.&lt;/p&gt; 
     &lt;p&gt;Next, on the Toreon Blog, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;Georges Bolssens&lt;/a&gt;&lt;/strong&gt; shares his take on “Managing unknowns assumptions in Threat Modeling”. Very interesting read on hidden risks.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;In this edition&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest Article&lt;br&gt;&lt;/b&gt;Dimitri Van Landuyt shares his take on the usage of LLMs when generating complete threat models.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; The Hidden Risk in Your Security Design: Managing Unknowns and Assumptions in Threat Modeling, by &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;Georges Bolssens&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;/b&gt;&lt;b&gt;&lt;br&gt;&lt;/b&gt;Securing Agentic AI: New Risks Require New Safeguards&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated Content&lt;br&gt;&lt;/b&gt;Agent Skills for Continuous Threat Modeling&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;the C4 model for diagramming / aiming for a certain abstraction level&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt;
       Guest Article 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;Should we generate complete threat models with LLM tools?&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In a relatively short time frame, Large Language Model (LLM) technology has emerged, matured, and proven itself not only to be applicable but actually transformational for a wide range of practices. The core capability to ingest large volumes of information, to reason, and to generate structured or unstructured outputs on demand, at volume, and at velocity provides a unique and unprecedented value proposition. There is no doubt today: LLMs represent a paradigm shift.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;On paper, this value proposition translates well to the specific context of threat modeling, which starts from collecting and reconciling different information elements about the system under design to construct a comprehensive system model. In the threat elicitation step, concrete potential threats –situations in which the security or privacy of the system may be harmed– are actively envisioned, articulated, and evaluated. This specific step, perhaps the actual heart of the overall threat modeling process, requires a unique blend of expertise, experience, system and domain knowledge and creativity. For these reasons, threat elicitation in practice remains a costly and time-consuming activity.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;We have witnessed integrations of the LLM capabilities into diverse threat modeling methods and tools, in a variety of initiatives, some academic and some commercial in nature.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;The growing landscape of LLM-based tools and methods&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The well-known 4Q-model divides the overall threat modeling process into four steps, centered around four key questions:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;What are we working on? (System description)&lt;/li&gt; 
      &lt;li&gt;What can go wrong? (Threat elicitation, and threat prioritization)&lt;/li&gt; 
      &lt;li&gt;What will we do about it? (Threat mitigation)&lt;/li&gt; 
      &lt;li&gt;Did we do a good job?&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;The below table provides overview of the identied threat modeling tools that have currently integrated LLM capabilities in support of the overall threat modeling process. The table make distinction between which of these steps of the threat modeling process are targeted with LLM automation, and furthermore indicates whether the tool provides complete automation rather than LLM-based assistance to the human threat modeling.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Tool&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;System description&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Threat elicitation&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Threat prioritization&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Threat mitigation&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Auspex&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;IriusRisk Jeff&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Threatmodeler WingMan&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;ThreatModelCompanion&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;SecureFlag ThreatCanvas&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;StrideGPT&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full*&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Fabric-Miessler&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Dragon-GPT&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;PILLAR (Simple, Go, Pro)&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full*&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;ThreatModelinLLM&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;AWS threat-designer&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Asssistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;As shown, many of these integration focus on supporting the threat elicitation activity, either by automating the process altogether or by providing the threat modeler with access to a supportive generative sparring partner. A number of these currently-available tools implement and provide complete automation of the threat elicitation step.&lt;/p&gt; 
     &lt;p&gt;But, are these LLM-based threat elicitation tools legitimate replacements of human threat modelers in the performance of threat elicitation?&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A scientic evaluation of the automated threat elicitation capability&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Or, the same question phrased differently: do the LLM capabilities to incorporate, process, evaluate, summarize and reason lead to sufficient results to actually take over the job the human threat modeler?&lt;/p&gt; 
     &lt;p&gt;To address this question, we have conducted a scientic evaluation study involving the publicly-available tools that automate the threat elicitation step: StrideGPT, PILLA-Go, and PILLA-Simple, FabricMiessler, Dragon-GPT, and ThreatModelingCompanion.&lt;/p&gt; 
     &lt;p&gt;The study is based on two complex and contemporary application cases that involve the use of biometry in support of recognition and authentation, once in the context of a personal device (face-based phone unlock), and once in a shared enviroment (access control in a shart building such as an appartment complex or oce building). The data ow diagram (DFD) for the phone unlock system is shown below.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For each of these cases, we use the different LLM-based threat elicitation tools and collect their outputs. We furthermore explore the effect of using different LLMs, a mix of local and hosted models, and in total process 56 distinct threat models generated by automated tools.&lt;/p&gt; 
     &lt;p&gt;We compare these outputs against a set of ground truth baselines, created by human threat modelers. In these baselines, we further distinguish between threats identied by novices and experts, and we further take into account the amount of agreement among the human threat modelers about the identied threats as a weight or penalty factor. This allows for in-depth evaluation of the generated results against human threat analysis.&lt;/p&gt; 
     &lt;p&gt;We use NLP technology –sentence transformers– to perform threat mapping, i.e. to decide whether a generated threat indeed refers to the same issue as one of the threats documented by the human threat modelers. More specically, the attack-BET sentence transformer is used, which was trained specically on security terminology, and not surprisingly proved most capable for this purpose. We calculate &lt;em&gt;semantic similarity&lt;/em&gt;, which expresses the extent to which two threat descriptions refer to the same core issue, regardless of phrasing. Based on that, we quantify performance, expressed in precision, recall, F1-score.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Results and findings&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;In the above graph, the red line represents the semantic similarity threshold (0.85) used as the criterion for considering a generated threat equivalent to one of the ground truth. As shown, the majority of threats generated per tool fall below this threshold line, and t within the 0.5-0.75 similarity range. Close, but not cigar. While the LLM tools generate threats that look similar to the relevant threats, they are not quite at the same level as the threats identied by human threat modelers (yet). &lt;strong&gt;Despite the toolgenerated threats being more similar than dissimilar to the relevant threats, overall performance is low.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;For over 60% of the threats generated by the LLM-based threat elicitation tools, their closest baseline match was identied by novice threat modelers. Threat recall is very low for the threats uniquely elicited by the experts. &lt;strong&gt;LLM tools are not (yet) replacing threat modeling experts.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Overall, and in large part due to generating large volumes of less applicable threats, the absolute &lt;strong&gt;precision and recall of relevant threats remains lower than that performance of human threat modelers.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Tools with more more sophisticated prompting techniques score better on the more complex distributed building access control case, but such advantages are not seen in more the simpler application case. This suggests that the appropriate prompting technique may depend highly on the specics of the application case: &lt;strong&gt;there is no single-size-ts-all solution to instruct LLMs for threat modeling.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;While there are notable dierences between the tools (which can mainly be considered to be a set of LLM prompt instructions, and conguration settings such as LLM temperature), a similar effect on performance results can be seen when changing the actual LLM models being used. &lt;strong&gt;The choice of underlying LLM model is of equal important to picking the right tool&lt;/strong&gt;. In our study, the best results were consistently attained with Google’s gemini2.0-flash model.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Want to know more?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Complete details can be found in the scientic publication: A comparative benchmark study of LLM-based threat elicitation tools, Dimitri Van Landuyt, Majid Mollaeefar, Mario Raciti, Stef Verreydt, Abdulaziz Kalash, Andrea Bissoli, Davy Preuveneers, Giampaolo Bella, Silvio Ranise, Future Generation Computer Systems (special issue on Generative AI in Cybersecurity), Volume 177, 2026, ISSN 0167-739X, &lt;a href="https://doi.org/10.1016/j.future.2025.108243"&gt;https://doi.org/10.1016/j.future.2025.108243&lt;/a&gt;.&lt;/p&gt; 
     &lt;p&gt;(&lt;a href="https://www.sciencedirect.com/science/article/pii/S0167739X25005370"&gt;https://www.sciencedirect.com/science/article/pii/S0167739X25005370&lt;/a&gt;)&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Additional materials such as case description, benchmark code, detailed results, and more can be found in the supporting materials package: &lt;a href="https://zenodo.org/records/17305023"&gt;https://zenodo.org/records/17305023&lt;/a&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Browse Trainings&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Toreon Blog: The Hidden Risk in Your Security Design: Managing Unknowns and Assumptions in Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;p&gt;In the world of cybersecurity, what you&amp;nbsp;&lt;i&gt;know&lt;/i&gt;&amp;nbsp;can protect you, but what you&lt;i&gt;assume&lt;/i&gt;&amp;nbsp;can&amp;nbsp;destroy you. Threat modeling is a foundational pillar of&amp;nbsp;&lt;b&gt;secure design&lt;/b&gt;, yet even the most rigorous models are often built on a shaky foundation of “unknowns” and “unspoken assumptions”.&lt;/p&gt; 
            &lt;p&gt;Whether you are “shifting left”&amp;nbsp;leveraging&amp;nbsp;modern DevOps&amp;nbsp;processes&amp;nbsp;or managing a legacy monolith, understanding how to document and&amp;nbsp;validate&amp;nbsp;these gaps is the difference between a resilient system and one waiting for a breach.&lt;/p&gt; 
           &lt;/div&gt; 
           &lt;p&gt;Most security teams follow the industry-standard “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps"&gt;DICE&amp;nbsp;framework&lt;/a&gt;” for threat modeling.&amp;nbsp;However,&amp;nbsp;this approach does&amp;nbsp;(by far) not prevent assumptions from being made.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/the-hidden-risk-in-your-security-design/"&gt;Read the blog&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;&lt;br&gt; &lt;br&gt; Curated Content&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Securing Agentic AI: New Risks Require New Safeguards&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Autonomous AI agents require a shift in threat modeling: treat them as “digital employees” requiring behavioral boundaries, not just traditional software.&lt;/p&gt; 
         &lt;p&gt;&lt;strong&gt;Key Attack Vectors &amp;amp; Mitigations&lt;/strong&gt;&lt;/p&gt; 
         &lt;ul&gt; 
          &lt;li&gt;&lt;strong&gt;Unbounded Autonomy:&lt;/strong&gt; Mitigate rogue actions with human-in-the-loop (HITL) oversight, utilizing dynamic escalation or mandatory approvals for high-risk operations.&lt;/li&gt; 
          &lt;li&gt;&lt;strong&gt;Compromised Agent Blast Radius:&lt;/strong&gt; Contain lateral movement and unauthorized access using application sandboxing, Just-in-Time (JIT) provisioning, and strict least-privilege enforcement.&lt;/li&gt; 
          &lt;li&gt;&lt;strong&gt;Training Data Poisoning:&lt;/strong&gt; Implement rigorous data validation. The threshold for compromise is alarmingly low: injecting just 5 malicious texts into a dataset of millions can achieve a 90% manipulation success rate&lt;/li&gt; 
         &lt;/ul&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Agent Skills for Continuous Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;p&gt;This MIT-licensed repository provides agent-agnostic tools to automate Continuous Threat Modeling within developer workflows, integrating directly with AI coding assistants like Claude Code and OpenAI Codex.&lt;/p&gt; 
             &lt;p&gt;&lt;strong&gt;Available Core Skills:&lt;/strong&gt;&lt;/p&gt; 
             &lt;ul&gt; 
              &lt;li&gt;&lt;strong&gt;pytm:&lt;/strong&gt; Automatically generates comprehensive threat models, outputting both structural diagrams and actionable security findings.&lt;/li&gt; 
              &lt;li&gt;&lt;strong&gt;ctm:&lt;/strong&gt; Monitors code commits to evaluate and flag security-notable changes in real-time.&lt;/li&gt; 
              &lt;li&gt;&lt;strong&gt;4qpytm:&lt;/strong&gt; Facilitates an interactive, four-question threat modeling session guided by user input.&lt;/li&gt; 
             &lt;/ul&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.ibm.com/think/insights/agentic-ai-security"&gt;Read More&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://github.com/izar/tm_skills"&gt;Read More&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Toreon Blog: The Hidden Risk in Your Security Design: Managing Unknowns and Assumptions in Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;p&gt;In the world of cybersecurity, what you&amp;nbsp;&lt;i&gt;know&lt;/i&gt;&amp;nbsp;can protect you, but what you&lt;i&gt;assume&lt;/i&gt;&amp;nbsp;can&amp;nbsp;destroy you. Threat modeling is a foundational pillar of&amp;nbsp;&lt;b&gt;secure design&lt;/b&gt;, yet even the most rigorous models are often built on a shaky foundation of “unknowns” and “unspoken assumptions”.&lt;/p&gt; 
            &lt;p&gt;Whether you are “shifting left”&amp;nbsp;leveraging&amp;nbsp;modern DevOps&amp;nbsp;processes&amp;nbsp;or managing a legacy monolith, understanding how to document and&amp;nbsp;validate&amp;nbsp;these gaps is the difference between a resilient system and one waiting for a breach.&lt;/p&gt; 
           &lt;/div&gt; 
           &lt;p&gt;Most security teams follow the industry-standard “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps"&gt;DICE&amp;nbsp;framework&lt;/a&gt;” for threat modeling.&amp;nbsp;However,&amp;nbsp;this approach does&amp;nbsp;(by far) not prevent assumptions from being made.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt;
         Read the blog 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;&lt;br&gt; &lt;br&gt; Curated Content&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;STRIDE-GPT As an MCP Server: A Composable Tool That AI Agents Can Use Autonomously&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;STRIDE-GPT has been released as an MCP server, enabling AI agents to autonomously perform full threat modeling on a codebase or architecture while fitting seamlessly into agent-based workflows. It delivers STRIDE-based threat analysis, risk scoring, mitigations, and executive-ready reports, all composable with other MCP tools like GitHub and Terraform.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Key Takeaways are:&lt;/strong&gt;&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;p&gt;STRIDE-GPT turns threat modeling into an autonomous, composable AI workflow, integrating code, infrastructure, and security analysis in a single session&lt;/p&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;p&gt;It provides comprehensive coverage, including all six STRIDE categories, DREAD risk scoring, attack trees, and OWASP LLM Top 10 (2025) AI/ML threats&lt;/p&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;p&gt;The tool is free, open source, and flexible—usable interactively or fully autonomously—while supporting modern domains beyond web apps, such as cloud, APIs, IoT, and mobile&lt;/p&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.linkedin.com/posts/matthewrwadams_threatmodeling-stride-stridegpt-activity-7413904789048152065-Vdwi/?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAAAAdeaMB84mKBOPIDf2ubXJ-mcYin9V5UAc"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Global Risks Report 2026 - World Economic Forum​&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;The Global Risks Report 2026 frames “Uncertainty” as the defining condition of a new Age of Competition, marked by weakening cooperation, rising multipolar rivalry, and eroding trust. The outlook is starkly pessimistic, with escalating geoeconomic conflict, accelerating AI risks, and long-term environmental threats reshaping how global and systemic risks must be understood.&lt;/p&gt; 
         &lt;p&gt;&lt;strong&gt;Key Takeaways are:&lt;/strong&gt;&lt;/p&gt; 
         &lt;ul&gt; 
          &lt;li&gt;&lt;p&gt;Geoeconomic confrontation is now the top short-term global risk, pushing threat modeling to include infrastructure sabotage, supply-chain weaponization, and cyber-physical attacks on critical systems&lt;/p&gt;&lt;/li&gt; 
          &lt;li&gt;&lt;p&gt;AI has shifted from a tool-level risk to a systemic one, with concerns ranging from misinformation and deepfakes to adversarial data poisoning, automated escalation, and long-term governance failures&lt;/p&gt;&lt;/li&gt; 
          &lt;li&gt;&lt;p&gt;Cryptographic complacency, information warfare, and fragmented supply chains demand forward-looking models that account for quantum “harvest now, decrypt later” threats and the erosion of digital trust and strategic dependencies&lt;/p&gt;&lt;/li&gt; 
         &lt;/ul&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.weforum.org/publications/global-risks-report-2026/"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;the C4 model for diagramming / aiming for a certain abstraction level&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;The “&lt;a href="https://c4model.com/"&gt;C4 model&lt;/a&gt;” offers a structured and hierarchical way to visualize software architecture, which greatly facilitates threat modeling by clarifying system context, allowing to “zoom in” to increased levels of detail when needed. This clear depiction helps identify interactions and allows for identification of potential attack surfaces, forming a solid foundation for pinpointing (and mitigating) security risks.&lt;/p&gt; 
        &lt;p&gt;Inspired by the C4-model’s philosophy, a diagram-as-code framework known as “&lt;a href="https://structurizr.com/"&gt;Structurizr&lt;/a&gt;” was developed to accompany it, featuring native export to other formats, avoiding any type of tool lock-in.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://c4model.com/"&gt;The C4 model&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://structurizr.com/"&gt;More on Structurizr&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;April 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking – aka Hands-on Threat Modeling, NorthSec Training, Montreal&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;May 10-11 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://nsec.io/training/2025-advanced-whiteboard-hacking1aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;March 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;April 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking – aka Hands-on Threat Modeling, NorthSec Training, Montreal&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;May 10-11 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://nsec.io/training/2025-advanced-whiteboard-hacking1aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Supernova/Cybernova&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You’ll be able to find us at both&amp;nbsp;&lt;a href="https://www.linkedin.com/company/96627234"&gt;SuperNova&lt;/a&gt;&amp;nbsp;on March 25th and March 26th, and&amp;nbsp;&lt;a href="https://www.linkedin.com/company/107751048"&gt;CyberNova&lt;/a&gt;&amp;nbsp;on March 24th. With Supernova being an internationally renowned event for tech and innovation, and this years first edition of Cybernova, focusing on all things related cybersecurity. Moreover we are also present at the&amp;nbsp;&lt;a href="https://www.linkedin.com/company/14691"&gt;Agoria&lt;/a&gt;&amp;nbsp;boothspace.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Webinar Toreon x IriusRisk&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;This session is the first in our two-part series with IriusRisk and takes a maturity-based look at how threat modeling evolves as organizations scale from startup to enterprise.&lt;/p&gt; 
     &lt;p&gt;You’ll learn how high-performing teams maintain consistent security standards while avoiding common pitfalls such as fragmented processes, inconsistent risk coverage, and duplicated or missed controls.&lt;/p&gt; 
     &lt;p&gt;We’ll explore how the right mix of services, tooling, and best practices helps organizations build scalable, sustainable threat modeling programs, ensuring security keeps pace with business growth.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-february-2026" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/TMI-46-Thumbnail-1-1.webp" alt="Threat Modeling Insider - February 2026 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;51st Edition – February 2026&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;In this edition, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/dimitri-van-landuyt-4b881b2/"&gt;Dimitri Van Landuyt&lt;/a&gt;&lt;/strong&gt; shares his view on usign LLM tools for complete threat models.&lt;/p&gt; 
     &lt;p&gt;Next, on the Toreon Blog, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;Georges Bolssens&lt;/a&gt;&lt;/strong&gt; shares his take on “Managing unknowns assumptions in Threat Modeling”. Very interesting read on hidden risks.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider!&lt;/strong&gt;In this edition, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/dimitri-van-landuyt-4b881b2/"&gt;Dimitri Van Landuyt&lt;/a&gt;&lt;/strong&gt; shares his view on usign LLM tools for complete threat models.&lt;/p&gt; 
     &lt;p&gt;Next, on the Toreon Blog, &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;Georges Bolssens&lt;/a&gt;&lt;/strong&gt; shares his take on “Managing unknowns assumptions in Threat Modeling”. Very interesting read on hidden risks.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;In this edition&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest Article&lt;br&gt;&lt;/b&gt;Dimitri Van Landuyt shares his take on the usage of LLMs when generating complete threat models.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; The Hidden Risk in Your Security Design: Managing Unknowns and Assumptions in Threat Modeling, by &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;Georges Bolssens&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;/b&gt;&lt;b&gt;&lt;br&gt;&lt;/b&gt;Securing Agentic AI: New Risks Require New Safeguards&lt;br&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated Content&lt;br&gt;&lt;/b&gt;Agent Skills for Continuous Threat Modeling&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;the C4 model for diagramming / aiming for a certain abstraction level&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt;
       Guest Article 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;Should we generate complete threat models with LLM tools?&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In a relatively short time frame, Large Language Model (LLM) technology has emerged, matured, and proven itself not only to be applicable but actually transformational for a wide range of practices. The core capability to ingest large volumes of information, to reason, and to generate structured or unstructured outputs on demand, at volume, and at velocity provides a unique and unprecedented value proposition. There is no doubt today: LLMs represent a paradigm shift.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;On paper, this value proposition translates well to the specific context of threat modeling, which starts from collecting and reconciling different information elements about the system under design to construct a comprehensive system model. In the threat elicitation step, concrete potential threats –situations in which the security or privacy of the system may be harmed– are actively envisioned, articulated, and evaluated. This specific step, perhaps the actual heart of the overall threat modeling process, requires a unique blend of expertise, experience, system and domain knowledge and creativity. For these reasons, threat elicitation in practice remains a costly and time-consuming activity.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;We have witnessed integrations of the LLM capabilities into diverse threat modeling methods and tools, in a variety of initiatives, some academic and some commercial in nature.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;The growing landscape of LLM-based tools and methods&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The well-known 4Q-model divides the overall threat modeling process into four steps, centered around four key questions:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;What are we working on? (System description)&lt;/li&gt; 
      &lt;li&gt;What can go wrong? (Threat elicitation, and threat prioritization)&lt;/li&gt; 
      &lt;li&gt;What will we do about it? (Threat mitigation)&lt;/li&gt; 
      &lt;li&gt;Did we do a good job?&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;The below table provides overview of the identied threat modeling tools that have currently integrated LLM capabilities in support of the overall threat modeling process. The table make distinction between which of these steps of the threat modeling process are targeted with LLM automation, and furthermore indicates whether the tool provides complete automation rather than LLM-based assistance to the human threat modeling.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Tool&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;System description&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Threat elicitation&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Threat prioritization&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;strong&gt;Threat mitigation&lt;/strong&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Auspex&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;IriusRisk Jeff&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Threatmodeler WingMan&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;ThreatModelCompanion&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;SecureFlag ThreatCanvas&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;StrideGPT&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full*&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Fabric-Miessler&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;Dragon-GPT&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;PILLAR (Simple, Go, Pro)&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full*&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;ThreatModelinLLM&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Full&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;strong&gt;AWS threat-designer&lt;/strong&gt;&lt;/td&gt; 
        &lt;td&gt;Asssistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Assistant&lt;/td&gt; 
        &lt;td&gt;Not supported&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;As shown, many of these integration focus on supporting the threat elicitation activity, either by automating the process altogether or by providing the threat modeler with access to a supportive generative sparring partner. A number of these currently-available tools implement and provide complete automation of the threat elicitation step.&lt;/p&gt; 
     &lt;p&gt;But, are these LLM-based threat elicitation tools legitimate replacements of human threat modelers in the performance of threat elicitation?&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A scientic evaluation of the automated threat elicitation capability&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Or, the same question phrased differently: do the LLM capabilities to incorporate, process, evaluate, summarize and reason lead to sufficient results to actually take over the job the human threat modeler?&lt;/p&gt; 
     &lt;p&gt;To address this question, we have conducted a scientic evaluation study involving the publicly-available tools that automate the threat elicitation step: StrideGPT, PILLA-Go, and PILLA-Simple, FabricMiessler, Dragon-GPT, and ThreatModelingCompanion.&lt;/p&gt; 
     &lt;p&gt;The study is based on two complex and contemporary application cases that involve the use of biometry in support of recognition and authentation, once in the context of a personal device (face-based phone unlock), and once in a shared enviroment (access control in a shart building such as an appartment complex or oce building). The data ow diagram (DFD) for the phone unlock system is shown below.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;For each of these cases, we use the different LLM-based threat elicitation tools and collect their outputs. We furthermore explore the effect of using different LLMs, a mix of local and hosted models, and in total process 56 distinct threat models generated by automated tools.&lt;/p&gt; 
     &lt;p&gt;We compare these outputs against a set of ground truth baselines, created by human threat modelers. In these baselines, we further distinguish between threats identied by novices and experts, and we further take into account the amount of agreement among the human threat modelers about the identied threats as a weight or penalty factor. This allows for in-depth evaluation of the generated results against human threat analysis.&lt;/p&gt; 
     &lt;p&gt;We use NLP technology –sentence transformers– to perform threat mapping, i.e. to decide whether a generated threat indeed refers to the same issue as one of the threats documented by the human threat modelers. More specically, the attack-BET sentence transformer is used, which was trained specically on security terminology, and not surprisingly proved most capable for this purpose. We calculate &lt;em&gt;semantic similarity&lt;/em&gt;, which expresses the extent to which two threat descriptions refer to the same core issue, regardless of phrasing. Based on that, we quantify performance, expressed in precision, recall, F1-score.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Results and findings&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;In the above graph, the red line represents the semantic similarity threshold (0.85) used as the criterion for considering a generated threat equivalent to one of the ground truth. As shown, the majority of threats generated per tool fall below this threshold line, and t within the 0.5-0.75 similarity range. Close, but not cigar. While the LLM tools generate threats that look similar to the relevant threats, they are not quite at the same level as the threats identied by human threat modelers (yet). &lt;strong&gt;Despite the toolgenerated threats being more similar than dissimilar to the relevant threats, overall performance is low.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;For over 60% of the threats generated by the LLM-based threat elicitation tools, their closest baseline match was identied by novice threat modelers. Threat recall is very low for the threats uniquely elicited by the experts. &lt;strong&gt;LLM tools are not (yet) replacing threat modeling experts.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Overall, and in large part due to generating large volumes of less applicable threats, the absolute &lt;strong&gt;precision and recall of relevant threats remains lower than that performance of human threat modelers.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Tools with more more sophisticated prompting techniques score better on the more complex distributed building access control case, but such advantages are not seen in more the simpler application case. This suggests that the appropriate prompting technique may depend highly on the specics of the application case: &lt;strong&gt;there is no single-size-ts-all solution to instruct LLMs for threat modeling.&lt;/strong&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;While there are notable dierences between the tools (which can mainly be considered to be a set of LLM prompt instructions, and conguration settings such as LLM temperature), a similar effect on performance results can be seen when changing the actual LLM models being used. &lt;strong&gt;The choice of underlying LLM model is of equal important to picking the right tool&lt;/strong&gt;. In our study, the best results were consistently attained with Google’s gemini2.0-flash model.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Want to know more?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Complete details can be found in the scientic publication: A comparative benchmark study of LLM-based threat elicitation tools, Dimitri Van Landuyt, Majid Mollaeefar, Mario Raciti, Stef Verreydt, Abdulaziz Kalash, Andrea Bissoli, Davy Preuveneers, Giampaolo Bella, Silvio Ranise, Future Generation Computer Systems (special issue on Generative AI in Cybersecurity), Volume 177, 2026, ISSN 0167-739X, &lt;a href="https://doi.org/10.1016/j.future.2025.108243"&gt;https://doi.org/10.1016/j.future.2025.108243&lt;/a&gt;.&lt;/p&gt; 
     &lt;p&gt;(&lt;a href="https://www.sciencedirect.com/science/article/pii/S0167739X25005370"&gt;https://www.sciencedirect.com/science/article/pii/S0167739X25005370&lt;/a&gt;)&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Additional materials such as case description, benchmark code, detailed results, and more can be found in the supporting materials package: &lt;a href="https://zenodo.org/records/17305023"&gt;https://zenodo.org/records/17305023&lt;/a&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Browse Trainings&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Toreon Blog: The Hidden Risk in Your Security Design: Managing Unknowns and Assumptions in Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;p&gt;In the world of cybersecurity, what you&amp;nbsp;&lt;i&gt;know&lt;/i&gt;&amp;nbsp;can protect you, but what you&lt;i&gt;assume&lt;/i&gt;&amp;nbsp;can&amp;nbsp;destroy you. Threat modeling is a foundational pillar of&amp;nbsp;&lt;b&gt;secure design&lt;/b&gt;, yet even the most rigorous models are often built on a shaky foundation of “unknowns” and “unspoken assumptions”.&lt;/p&gt; 
            &lt;p&gt;Whether you are “shifting left”&amp;nbsp;leveraging&amp;nbsp;modern DevOps&amp;nbsp;processes&amp;nbsp;or managing a legacy monolith, understanding how to document and&amp;nbsp;validate&amp;nbsp;these gaps is the difference between a resilient system and one waiting for a breach.&lt;/p&gt; 
           &lt;/div&gt; 
           &lt;p&gt;Most security teams follow the industry-standard “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps"&gt;DICE&amp;nbsp;framework&lt;/a&gt;” for threat modeling.&amp;nbsp;However,&amp;nbsp;this approach does&amp;nbsp;(by far) not prevent assumptions from being made.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.toreon.com/the-hidden-risk-in-your-security-design/"&gt;Read the blog&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;&lt;br&gt; &lt;br&gt; Curated Content&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Securing Agentic AI: New Risks Require New Safeguards&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Autonomous AI agents require a shift in threat modeling: treat them as “digital employees” requiring behavioral boundaries, not just traditional software.&lt;/p&gt; 
         &lt;p&gt;&lt;strong&gt;Key Attack Vectors &amp;amp; Mitigations&lt;/strong&gt;&lt;/p&gt; 
         &lt;ul&gt; 
          &lt;li&gt;&lt;strong&gt;Unbounded Autonomy:&lt;/strong&gt; Mitigate rogue actions with human-in-the-loop (HITL) oversight, utilizing dynamic escalation or mandatory approvals for high-risk operations.&lt;/li&gt; 
          &lt;li&gt;&lt;strong&gt;Compromised Agent Blast Radius:&lt;/strong&gt; Contain lateral movement and unauthorized access using application sandboxing, Just-in-Time (JIT) provisioning, and strict least-privilege enforcement.&lt;/li&gt; 
          &lt;li&gt;&lt;strong&gt;Training Data Poisoning:&lt;/strong&gt; Implement rigorous data validation. The threshold for compromise is alarmingly low: injecting just 5 malicious texts into a dataset of millions can achieve a 90% manipulation success rate&lt;/li&gt; 
         &lt;/ul&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Agent Skills for Continuous Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;div&gt; 
             &lt;p&gt;This MIT-licensed repository provides agent-agnostic tools to automate Continuous Threat Modeling within developer workflows, integrating directly with AI coding assistants like Claude Code and OpenAI Codex.&lt;/p&gt; 
             &lt;p&gt;&lt;strong&gt;Available Core Skills:&lt;/strong&gt;&lt;/p&gt; 
             &lt;ul&gt; 
              &lt;li&gt;&lt;strong&gt;pytm:&lt;/strong&gt; Automatically generates comprehensive threat models, outputting both structural diagrams and actionable security findings.&lt;/li&gt; 
              &lt;li&gt;&lt;strong&gt;ctm:&lt;/strong&gt; Monitors code commits to evaluate and flag security-notable changes in real-time.&lt;/li&gt; 
              &lt;li&gt;&lt;strong&gt;4qpytm:&lt;/strong&gt; Facilitates an interactive, four-question threat modeling session guided by user input.&lt;/li&gt; 
             &lt;/ul&gt; 
            &lt;/div&gt; 
           &lt;/div&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.ibm.com/think/insights/agentic-ai-security"&gt;Read More&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://github.com/izar/tm_skills"&gt;Read More&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Toreon Blog: The Hidden Risk in Your Security Design: Managing Unknowns and Assumptions in Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;div&gt; 
            &lt;p&gt;In the world of cybersecurity, what you&amp;nbsp;&lt;i&gt;know&lt;/i&gt;&amp;nbsp;can protect you, but what you&lt;i&gt;assume&lt;/i&gt;&amp;nbsp;can&amp;nbsp;destroy you. Threat modeling is a foundational pillar of&amp;nbsp;&lt;b&gt;secure design&lt;/b&gt;, yet even the most rigorous models are often built on a shaky foundation of “unknowns” and “unspoken assumptions”.&lt;/p&gt; 
            &lt;p&gt;Whether you are “shifting left”&amp;nbsp;leveraging&amp;nbsp;modern DevOps&amp;nbsp;processes&amp;nbsp;or managing a legacy monolith, understanding how to document and&amp;nbsp;validate&amp;nbsp;these gaps is the difference between a resilient system and one waiting for a breach.&lt;/p&gt; 
           &lt;/div&gt; 
           &lt;p&gt;Most security teams follow the industry-standard “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps"&gt;DICE&amp;nbsp;framework&lt;/a&gt;” for threat modeling.&amp;nbsp;However,&amp;nbsp;this approach does&amp;nbsp;(by far) not prevent assumptions from being made.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
       &lt;div&gt;
         Read the blog 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;&lt;br&gt; &lt;br&gt; Curated Content&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;STRIDE-GPT As an MCP Server: A Composable Tool That AI Agents Can Use Autonomously&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;STRIDE-GPT has been released as an MCP server, enabling AI agents to autonomously perform full threat modeling on a codebase or architecture while fitting seamlessly into agent-based workflows. It delivers STRIDE-based threat analysis, risk scoring, mitigations, and executive-ready reports, all composable with other MCP tools like GitHub and Terraform.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Key Takeaways are:&lt;/strong&gt;&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;p&gt;STRIDE-GPT turns threat modeling into an autonomous, composable AI workflow, integrating code, infrastructure, and security analysis in a single session&lt;/p&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;p&gt;It provides comprehensive coverage, including all six STRIDE categories, DREAD risk scoring, attack trees, and OWASP LLM Top 10 (2025) AI/ML threats&lt;/p&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;p&gt;The tool is free, open source, and flexible—usable interactively or fully autonomously—while supporting modern domains beyond web apps, such as cloud, APIs, IoT, and mobile&lt;/p&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.linkedin.com/posts/matthewrwadams_threatmodeling-stride-stridegpt-activity-7413904789048152065-Vdwi/?utm_source=share&amp;amp;utm_medium=member_desktop&amp;amp;rcm=ACoAAAAdeaMB84mKBOPIDf2ubXJ-mcYin9V5UAc"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Global Risks Report 2026 - World Economic Forum​&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;The Global Risks Report 2026 frames “Uncertainty” as the defining condition of a new Age of Competition, marked by weakening cooperation, rising multipolar rivalry, and eroding trust. The outlook is starkly pessimistic, with escalating geoeconomic conflict, accelerating AI risks, and long-term environmental threats reshaping how global and systemic risks must be understood.&lt;/p&gt; 
         &lt;p&gt;&lt;strong&gt;Key Takeaways are:&lt;/strong&gt;&lt;/p&gt; 
         &lt;ul&gt; 
          &lt;li&gt;&lt;p&gt;Geoeconomic confrontation is now the top short-term global risk, pushing threat modeling to include infrastructure sabotage, supply-chain weaponization, and cyber-physical attacks on critical systems&lt;/p&gt;&lt;/li&gt; 
          &lt;li&gt;&lt;p&gt;AI has shifted from a tool-level risk to a systemic one, with concerns ranging from misinformation and deepfakes to adversarial data poisoning, automated escalation, and long-term governance failures&lt;/p&gt;&lt;/li&gt; 
          &lt;li&gt;&lt;p&gt;Cryptographic complacency, information warfare, and fragmented supply chains demand forward-looking models that account for quantum “harvest now, decrypt later” threats and the erosion of digital trust and strategic dependencies&lt;/p&gt;&lt;/li&gt; 
         &lt;/ul&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.weforum.org/publications/global-risks-report-2026/"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;the C4 model for diagramming / aiming for a certain abstraction level&lt;/h3&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;The “&lt;a href="https://c4model.com/"&gt;C4 model&lt;/a&gt;” offers a structured and hierarchical way to visualize software architecture, which greatly facilitates threat modeling by clarifying system context, allowing to “zoom in” to increased levels of detail when needed. This clear depiction helps identify interactions and allows for identification of potential attack surfaces, forming a solid foundation for pinpointing (and mitigating) security risks.&lt;/p&gt; 
        &lt;p&gt;Inspired by the C4-model’s philosophy, a diagram-as-code framework known as “&lt;a href="https://structurizr.com/"&gt;Structurizr&lt;/a&gt;” was developed to accompany it, featuring native export to other formats, avoiding any type of tool lock-in.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://c4model.com/"&gt;The C4 model&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://structurizr.com/"&gt;More on Structurizr&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;April 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking – aka Hands-on Threat Modeling, NorthSec Training, Montreal&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;May 10-11 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://nsec.io/training/2025-advanced-whiteboard-hacking1aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;March 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Our trainings &amp;amp; events for 2026&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;April 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking – aka Hands-on Threat Modeling, NorthSec Training, Montreal&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;May 10-11 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://nsec.io/training/2025-advanced-whiteboard-hacking1aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;3-Day Training: AI Whiteboard Hacking aka Hands-on Threat Modeling Training, in-person, OWASP Global AppSec EU, Vienna Austria&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;22-24 June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://owaspglobalappseceuvienna20.sched.com/event/2E75L"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, US Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;June 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI, Europe Cohort&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;em&gt;September 2026&lt;/em&gt;&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Supernova/Cybernova&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You’ll be able to find us at both&amp;nbsp;&lt;a href="https://www.linkedin.com/company/96627234"&gt;SuperNova&lt;/a&gt;&amp;nbsp;on March 25th and March 26th, and&amp;nbsp;&lt;a href="https://www.linkedin.com/company/107751048"&gt;CyberNova&lt;/a&gt;&amp;nbsp;on March 24th. With Supernova being an internationally renowned event for tech and innovation, and this years first edition of Cybernova, focusing on all things related cybersecurity. Moreover we are also present at the&amp;nbsp;&lt;a href="https://www.linkedin.com/company/14691"&gt;Agoria&lt;/a&gt;&amp;nbsp;boothspace.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Webinar Toreon x IriusRisk&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;This session is the first in our two-part series with IriusRisk and takes a maturity-based look at how threat modeling evolves as organizations scale from startup to enterprise.&lt;/p&gt; 
     &lt;p&gt;You’ll learn how high-performing teams maintain consistent security standards while avoiding common pitfalls such as fragmented processes, inconsistent risk coverage, and duplicated or missed controls.&lt;/p&gt; 
     &lt;p&gt;We’ll explore how the right mix of services, tooling, and best practices helps organizations build scalable, sustainable threat modeling programs, ensuring security keeps pace with business growth.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthreat-modeling-insider-february-2026&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <pubDate>Sun, 01 Mar 2026 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-february-2026</guid>
      <dc:date>2026-03-01T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Uncover Hidden Security Design Risks: Improve Threat Modeling &amp; Reduce Assumptions</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/the-hidden-risk-in-your-security-design</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/the-hidden-risk-in-your-security-design" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-4-1.png" alt="Uncover Hidden Security Design Risks: Improve Threat Modeling &amp;amp; Reduce Assumptions" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In the world of cybersecurity, what you&amp;nbsp;&lt;i&gt;know&lt;/i&gt;&amp;nbsp;can protect you, but what you&lt;i&gt;assume&lt;/i&gt;&amp;nbsp;can&amp;nbsp;destroy you. Threat modeling is a foundational pillar of&amp;nbsp;&lt;b&gt;secure design&lt;/b&gt;, yet even the most rigorous models are often built on a shaky foundation of “unknowns” and “unspoken assumptions”.&lt;/p&gt; 
     &lt;p&gt;Whether you are “shifting left”&amp;nbsp;leveraging&amp;nbsp;modern DevOps&amp;nbsp;processes&amp;nbsp;or managing a legacy monolith, understanding how to document and&amp;nbsp;validate&amp;nbsp;these gaps is the difference between a resilient system and one waiting for a breach.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Exploring unknowns via the DICE framework&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Most security teams follow the industry-standard “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps/"&gt;DICE&amp;nbsp;framework&lt;/a&gt;“&amp;nbsp;for threat modeling.&amp;nbsp;However,&amp;nbsp;this approach does&amp;nbsp;(by far) not prevent assumptions from being made.&lt;/p&gt; 
     &lt;p&gt;Just to refresh everyone’s mind, here are the 4 phases of this framework:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;D&lt;/b&gt;&amp;nbsp;is for&amp;nbsp;&lt;b&gt;D&lt;/b&gt;escription of the context (What are we building?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;I&lt;/b&gt;&amp;nbsp;is&amp;nbsp;for&amp;nbsp;&lt;b&gt;I&lt;/b&gt;dentification of threats (What can go wrong?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;C&lt;/b&gt;&amp;nbsp;is for&amp;nbsp;&lt;b&gt;C&lt;/b&gt;ountermeasure definition (What are we going to do about it?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;E&lt;/b&gt;&amp;nbsp;is for&amp;nbsp;&lt;b&gt;E&lt;/b&gt;valuation (Did we do a good enough job?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;While most mature organizations have standardized the first three&amp;nbsp;pretty well, validation of assumptions in the last phase is often overlooked.&amp;nbsp;This makes sense,&amp;nbsp;because&amp;nbsp;to enable validation of unknowns and assumptions&amp;nbsp;in the “Evaluation” phase, this obviously requires keeping track of them in the three phases that preceded it…&lt;/p&gt; 
     &lt;p&gt;This article&amp;nbsp;introduces the concept of an “assumption register” and&amp;nbsp;explores&amp;nbsp;how&amp;nbsp;to piggyback its creation&amp;nbsp;off of&amp;nbsp;the four phases of the DICE framework.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What are we working on?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While&amp;nbsp;seemingly a&amp;nbsp;straightforward question,&amp;nbsp;in&amp;nbsp;threat models&amp;nbsp;we&amp;nbsp;create&amp;nbsp;with our clients&amp;nbsp;there’s&amp;nbsp;rarely an all-encompassing answer.&lt;/p&gt; 
     &lt;p&gt;When threat modeling a system that&amp;nbsp;doesn’t&amp;nbsp;exist yet, technical details have&amp;nbsp;often&amp;nbsp;not crystallized&amp;nbsp;yet.&amp;nbsp;While this is&amp;nbsp;mostly&amp;nbsp;a&amp;nbsp;by-product&amp;nbsp;of threat modeling “too soon” in the design phase, it does present us with an opportunity to start documenting unknowns and assumptions.&lt;/p&gt; 
     &lt;p&gt;In existing / legacy&amp;nbsp;systems&amp;nbsp;the story is&amp;nbsp;very different.&amp;nbsp;Knowledge drain from staff churn and incomplete documentation often leaves&amp;nbsp;significant&amp;nbsp;gaps in&amp;nbsp;knowing&amp;nbsp;how the system&amp;nbsp;actually functions.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What can go wrong?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This source of unknowns is different&amp;nbsp;from&amp;nbsp;the other ones, mainly&amp;nbsp;because it&amp;nbsp;doesn’t&amp;nbsp;have the word “we” in it.&amp;nbsp;Consequently, the unknowns here&amp;nbsp;originate from others’ actions and are&amp;nbsp;an artefact of&amp;nbsp;“you don’t know what you don’t know”.&amp;nbsp;Specialized security&amp;nbsp;expertise&amp;nbsp;helps,&amp;nbsp;but&amp;nbsp;it’s&amp;nbsp;a luxury many teams simply&amp;nbsp;don’t&amp;nbsp;have. This is where assumptions&amp;nbsp;must be made&amp;nbsp;but also&amp;nbsp;where some important&amp;nbsp;&lt;b&gt;mis&lt;/b&gt;asumptions&amp;nbsp;are born.&lt;/p&gt; 
     &lt;p&gt;A few examples of these that we have come across in the past:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The “Good&amp;nbsp;employee”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;Assuming attackers only come from the outside.&amp;nbsp;In reality, employees&amp;nbsp;can be bribed, threatened,&amp;nbsp;vengeful&amp;nbsp;or in need of cash.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The “Security&amp;nbsp;through&amp;nbsp;obscurity”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;Thinking “only we understand how this works”&amp;nbsp;and/or “nobody would bother to&amp;nbsp;figure this out”. Advanced adversaries use automated tools to uncover precisely what you think is hidden.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The&amp;nbsp;“Nobody would actually do this”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;Underestimating the technical sophistication or motivation of potential threat actors.&amp;nbsp;People who have&amp;nbsp;relatively little&amp;nbsp;to&amp;nbsp;lose,&amp;nbsp;can&amp;nbsp;act in extremely unpredictable ways.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The “Hypothetical&amp;nbsp;attack;&amp;nbsp;zero&amp;nbsp;likelihood&amp;nbsp;”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;A&amp;nbsp;great example of&amp;nbsp;“you&amp;nbsp;don’t know what you don’t know”; we&amp;nbsp;have&amp;nbsp;literally&amp;nbsp;heard&amp;nbsp;this from&amp;nbsp;multiple&amp;nbsp;system&amp;nbsp;engineers&amp;nbsp;when&amp;nbsp;discussing&amp;nbsp;VM-to-host-escapes and VLAN-hopping&amp;nbsp;during threat elicitation.&amp;nbsp;This is the easiest one to debunk if&amp;nbsp;documented cases are available.&amp;nbsp;Sometimes, indeed, there&amp;nbsp;just&amp;nbsp;aren’t&amp;nbsp;any&amp;nbsp;documented cases,&amp;nbsp;and the threat is effectively hypothetical. Then&amp;nbsp;you&amp;nbsp;go ahead with&amp;nbsp;documenting&amp;nbsp;predictive&amp;nbsp;assumption&amp;nbsp;statements&amp;nbsp;along the lines of&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that an exploit for&amp;nbsp;breaking&amp;nbsp;TLS1.2&amp;nbsp;will&amp;nbsp;not to be&amp;nbsp;developed&amp;nbsp;during&amp;nbsp;the lifetime of this IoT device”.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What are we going to do about it?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Misassumptions also happen here, but for&amp;nbsp;different reasons.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The&amp;nbsp;“Our cloud vendor&amp;nbsp;surely&amp;nbsp;takes&amp;nbsp;care&amp;nbsp;of&amp;nbsp;this” fallacy&lt;/b&gt;&amp;nbsp;Teams often assume that use&amp;nbsp;of&amp;nbsp;a major cloud provider&amp;nbsp;solves all their&amp;nbsp;security&amp;nbsp;problems. This ignores the Shared Responsibility Model, where the vendor secures the “fabric” of their&amp;nbsp;cloud, but you&amp;nbsp;are responsible for&amp;nbsp;securing your data in the cloud.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Together with the&amp;nbsp;predictive claim&amp;nbsp;about the perceived lack of an&amp;nbsp;expoit, the real assumptions that support the “unhackability” of the TLS1.2 connection are&amp;nbsp;in this “What are we going to do about it”-phase:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that our infrastructure team implements TLS1.2 according to the current industry standards”.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that our infrastructure team DOES NOT implement TLS/SSL versions&amp;nbsp;that precede TLS1.2”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that the public-key-pinning mechanism prevents the IoT device from accepting any certificate other than the one we envisioned”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume&amp;nbsp;that the HTTP library in the IoT device doesn’t accidentally connect to the&amp;nbsp;HTTP endpoint with its authentication token to then be redirected”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that HTTPS implementations of our infrastructure are being validated in our quarterly penetration tests”.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that Certificate Authority X will refuse CSRs for our domain”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Getting these assumptions down is important but the work&amp;nbsp;it’s&amp;nbsp;not done to come to&amp;nbsp;an assumptions&amp;nbsp;register; more on this&amp;nbsp;in the next section.&lt;/p&gt; 
     &lt;p&gt;&lt;b&gt;The Rule of Thumb:&lt;/b&gt;&amp;nbsp;If you&amp;nbsp;don’t&amp;nbsp;have a definitive answer, you have two choices:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;If&amp;nbsp;acquiring&amp;nbsp;the answer is&amp;nbsp;feasible&amp;nbsp;in the short term,&amp;nbsp;document it as an&amp;nbsp;&lt;b&gt;open question&lt;/b&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;If&amp;nbsp;acquiring&amp;nbsp;the answer is not&amp;nbsp;feasible&amp;nbsp;(anymore)&amp;nbsp;document&amp;nbsp;it as an&amp;nbsp;&lt;b&gt;assumption&lt;/b&gt;&amp;nbsp;in&amp;nbsp;(drum roll…)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Assumption Register&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;A high-quality register&amp;nbsp;could, for example,&amp;nbsp;track&amp;nbsp;the following&amp;nbsp;properties for every assumption:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;The Assumption:&lt;/b&gt;&amp;nbsp;A clear statement (e.g.,&amp;nbsp;&lt;i&gt;“We assume the end user has an antivirus installed”&lt;/i&gt;).&amp;nbsp;If unclear from the&amp;nbsp;assumption&amp;nbsp;statement&amp;nbsp;itself, a temporal nature can be added&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Validation:&lt;/b&gt;A&amp;nbsp;test that can prove the&amp;nbsp;assumption is correct. (Not always&amp;nbsp;feasible,&amp;nbsp;like the&amp;nbsp;case of a&amp;nbsp;third party&amp;nbsp;computer having A/V installed)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Confidence (+ Justification):&lt;/b&gt;&amp;nbsp;How sure are you&amp;nbsp;when&amp;nbsp;stating&amp;nbsp;this assumption? (e.g.,&amp;nbsp;&lt;i&gt;“Almost guaranteed due to corporate environment policy”&lt;/i&gt;).&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Consequence if it Fails:&lt;/b&gt;&amp;nbsp;What happens if the assumption is wrong? (e.g.,&amp;nbsp;&lt;i&gt;“The user downloads a virus via our&amp;nbsp;platform&amp;nbsp;and we have no server-side scanning to stop it”&lt;/i&gt;).&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Owner:&lt;/b&gt;Person,&amp;nbsp;department&amp;nbsp;or role that owns the risk of getting the assumption wrong&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion: Don’t Let Unknowns Be Your Downfall&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling is a continuous process of discovery. By&amp;nbsp;identifying&amp;nbsp;your unknowns and tracking your assumptions, you turn “blind spots” into a prioritized list of things to&amp;nbsp;validate.&lt;/p&gt; 
     &lt;p&gt;&lt;b&gt;Next Step for Your Team:&lt;/b&gt;&amp;nbsp;Review your current&amp;nbsp;project’s&amp;nbsp;architecture diagram. Pick one&amp;nbsp;interaction across a trust boundary&amp;nbsp;and ask&amp;nbsp;yourself:&amp;nbsp;&lt;i&gt;“What are we assuming&amp;nbsp;that, if true,&amp;nbsp;makes this secure?”&lt;/i&gt;Converselyask the opposite:&amp;nbsp;&lt;i&gt;“What are we assuming&amp;nbsp;that, if&amp;nbsp;false,&amp;nbsp;makes this&amp;nbsp;insecure?”&lt;/i&gt;&lt;/p&gt; 
     &lt;p&gt;Add those items to&amp;nbsp;your Assumption Register.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Georges’ lifelong curiosity about ‘how stuff works’ culminated in a Master’s degree in Electro-Mechanical Engineering. With over 15 years of experience in technical and managerial roles within the biotech industry, he developed a deep proficiency in programming and a passion for cybersecurity.&lt;/p&gt; 
        &lt;p&gt;This unique combination of engineering logic and coding expertise makes Georges an ideal Application Security expert; he relates to the daily challenges of software developers while fully understanding the adversarial mindset of hackers. Since transitioning to AppSec in 2017, he has consulted for a wide variety of business contexts.&lt;/p&gt; 
        &lt;p&gt;Georges joined Toreon in 2021, where he currently serves as the Product Owner for Threat Modeling Consulting. He is also the Lead Trainer for Toreon’s globally recognized ‘Whiteboard Hacking’ training. Leveraging his background in electronics, Georges is a key member of the hardware penetration testing team, with specific expertise in threat modeling for embedded medical and non-medical devices.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Schedule a call&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Supernova/Cybernova&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You’ll be able to find us at both&amp;nbsp;&lt;a href="https://www.linkedin.com/company/96627234"&gt;SuperNova&lt;/a&gt;&amp;nbsp;on March 25th and March 26th, and&amp;nbsp;&lt;a href="https://www.linkedin.com/company/107751048"&gt;CyberNova&lt;/a&gt;&amp;nbsp;on March 24th. With Supernova being an internationally renowned event for tech and innovation, and this years first edition of Cybernova, focusing on all things related cybersecurity. Moreover we are also present at the&amp;nbsp;&lt;a href="https://www.linkedin.com/company/14691"&gt;Agoria&lt;/a&gt;&amp;nbsp;boothspace.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Webinar Toreon x IriusRisk&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;This session is the first in our two-part series with IriusRisk and takes a maturity-based look at how threat modeling evolves as organizations scale from startup to enterprise.&lt;/p&gt; 
     &lt;p&gt;You’ll learn how high-performing teams maintain consistent security standards while avoiding common pitfalls such as fragmented processes, inconsistent risk coverage, and duplicated or missed controls.&lt;/p&gt; 
     &lt;p&gt;We’ll explore how the right mix of services, tooling, and best practices helps organizations build scalable, sustainable threat modeling programs, ensuring security keeps pace with business growth.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/the-hidden-risk-in-your-security-design" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-4-1.png" alt="Uncover Hidden Security Design Risks: Improve Threat Modeling &amp;amp; Reduce Assumptions" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In the world of cybersecurity, what you&amp;nbsp;&lt;i&gt;know&lt;/i&gt;&amp;nbsp;can protect you, but what you&lt;i&gt;assume&lt;/i&gt;&amp;nbsp;can&amp;nbsp;destroy you. Threat modeling is a foundational pillar of&amp;nbsp;&lt;b&gt;secure design&lt;/b&gt;, yet even the most rigorous models are often built on a shaky foundation of “unknowns” and “unspoken assumptions”.&lt;/p&gt; 
     &lt;p&gt;Whether you are “shifting left”&amp;nbsp;leveraging&amp;nbsp;modern DevOps&amp;nbsp;processes&amp;nbsp;or managing a legacy monolith, understanding how to document and&amp;nbsp;validate&amp;nbsp;these gaps is the difference between a resilient system and one waiting for a breach.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Exploring unknowns via the DICE framework&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Most security teams follow the industry-standard “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps/"&gt;DICE&amp;nbsp;framework&lt;/a&gt;“&amp;nbsp;for threat modeling.&amp;nbsp;However,&amp;nbsp;this approach does&amp;nbsp;(by far) not prevent assumptions from being made.&lt;/p&gt; 
     &lt;p&gt;Just to refresh everyone’s mind, here are the 4 phases of this framework:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;D&lt;/b&gt;&amp;nbsp;is for&amp;nbsp;&lt;b&gt;D&lt;/b&gt;escription of the context (What are we building?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;I&lt;/b&gt;&amp;nbsp;is&amp;nbsp;for&amp;nbsp;&lt;b&gt;I&lt;/b&gt;dentification of threats (What can go wrong?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;C&lt;/b&gt;&amp;nbsp;is for&amp;nbsp;&lt;b&gt;C&lt;/b&gt;ountermeasure definition (What are we going to do about it?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;E&lt;/b&gt;&amp;nbsp;is for&amp;nbsp;&lt;b&gt;E&lt;/b&gt;valuation (Did we do a good enough job?)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;While most mature organizations have standardized the first three&amp;nbsp;pretty well, validation of assumptions in the last phase is often overlooked.&amp;nbsp;This makes sense,&amp;nbsp;because&amp;nbsp;to enable validation of unknowns and assumptions&amp;nbsp;in the “Evaluation” phase, this obviously requires keeping track of them in the three phases that preceded it…&lt;/p&gt; 
     &lt;p&gt;This article&amp;nbsp;introduces the concept of an “assumption register” and&amp;nbsp;explores&amp;nbsp;how&amp;nbsp;to piggyback its creation&amp;nbsp;off of&amp;nbsp;the four phases of the DICE framework.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What are we working on?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While&amp;nbsp;seemingly a&amp;nbsp;straightforward question,&amp;nbsp;in&amp;nbsp;threat models&amp;nbsp;we&amp;nbsp;create&amp;nbsp;with our clients&amp;nbsp;there’s&amp;nbsp;rarely an all-encompassing answer.&lt;/p&gt; 
     &lt;p&gt;When threat modeling a system that&amp;nbsp;doesn’t&amp;nbsp;exist yet, technical details have&amp;nbsp;often&amp;nbsp;not crystallized&amp;nbsp;yet.&amp;nbsp;While this is&amp;nbsp;mostly&amp;nbsp;a&amp;nbsp;by-product&amp;nbsp;of threat modeling “too soon” in the design phase, it does present us with an opportunity to start documenting unknowns and assumptions.&lt;/p&gt; 
     &lt;p&gt;In existing / legacy&amp;nbsp;systems&amp;nbsp;the story is&amp;nbsp;very different.&amp;nbsp;Knowledge drain from staff churn and incomplete documentation often leaves&amp;nbsp;significant&amp;nbsp;gaps in&amp;nbsp;knowing&amp;nbsp;how the system&amp;nbsp;actually functions.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What can go wrong?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This source of unknowns is different&amp;nbsp;from&amp;nbsp;the other ones, mainly&amp;nbsp;because it&amp;nbsp;doesn’t&amp;nbsp;have the word “we” in it.&amp;nbsp;Consequently, the unknowns here&amp;nbsp;originate from others’ actions and are&amp;nbsp;an artefact of&amp;nbsp;“you don’t know what you don’t know”.&amp;nbsp;Specialized security&amp;nbsp;expertise&amp;nbsp;helps,&amp;nbsp;but&amp;nbsp;it’s&amp;nbsp;a luxury many teams simply&amp;nbsp;don’t&amp;nbsp;have. This is where assumptions&amp;nbsp;must be made&amp;nbsp;but also&amp;nbsp;where some important&amp;nbsp;&lt;b&gt;mis&lt;/b&gt;asumptions&amp;nbsp;are born.&lt;/p&gt; 
     &lt;p&gt;A few examples of these that we have come across in the past:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The “Good&amp;nbsp;employee”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;Assuming attackers only come from the outside.&amp;nbsp;In reality, employees&amp;nbsp;can be bribed, threatened,&amp;nbsp;vengeful&amp;nbsp;or in need of cash.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The “Security&amp;nbsp;through&amp;nbsp;obscurity”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;Thinking “only we understand how this works”&amp;nbsp;and/or “nobody would bother to&amp;nbsp;figure this out”. Advanced adversaries use automated tools to uncover precisely what you think is hidden.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The&amp;nbsp;“Nobody would actually do this”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;Underestimating the technical sophistication or motivation of potential threat actors.&amp;nbsp;People who have&amp;nbsp;relatively little&amp;nbsp;to&amp;nbsp;lose,&amp;nbsp;can&amp;nbsp;act in extremely unpredictable ways.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The “Hypothetical&amp;nbsp;attack;&amp;nbsp;zero&amp;nbsp;likelihood&amp;nbsp;”&amp;nbsp;fallacy:&lt;/b&gt;&amp;nbsp;A&amp;nbsp;great example of&amp;nbsp;“you&amp;nbsp;don’t know what you don’t know”; we&amp;nbsp;have&amp;nbsp;literally&amp;nbsp;heard&amp;nbsp;this from&amp;nbsp;multiple&amp;nbsp;system&amp;nbsp;engineers&amp;nbsp;when&amp;nbsp;discussing&amp;nbsp;VM-to-host-escapes and VLAN-hopping&amp;nbsp;during threat elicitation.&amp;nbsp;This is the easiest one to debunk if&amp;nbsp;documented cases are available.&amp;nbsp;Sometimes, indeed, there&amp;nbsp;just&amp;nbsp;aren’t&amp;nbsp;any&amp;nbsp;documented cases,&amp;nbsp;and the threat is effectively hypothetical. Then&amp;nbsp;you&amp;nbsp;go ahead with&amp;nbsp;documenting&amp;nbsp;predictive&amp;nbsp;assumption&amp;nbsp;statements&amp;nbsp;along the lines of&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that an exploit for&amp;nbsp;breaking&amp;nbsp;TLS1.2&amp;nbsp;will&amp;nbsp;not to be&amp;nbsp;developed&amp;nbsp;during&amp;nbsp;the lifetime of this IoT device”.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What are we going to do about it?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Misassumptions also happen here, but for&amp;nbsp;different reasons.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;The&amp;nbsp;“Our cloud vendor&amp;nbsp;surely&amp;nbsp;takes&amp;nbsp;care&amp;nbsp;of&amp;nbsp;this” fallacy&lt;/b&gt;&amp;nbsp;Teams often assume that use&amp;nbsp;of&amp;nbsp;a major cloud provider&amp;nbsp;solves all their&amp;nbsp;security&amp;nbsp;problems. This ignores the Shared Responsibility Model, where the vendor secures the “fabric” of their&amp;nbsp;cloud, but you&amp;nbsp;are responsible for&amp;nbsp;securing your data in the cloud.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Together with the&amp;nbsp;predictive claim&amp;nbsp;about the perceived lack of an&amp;nbsp;expoit, the real assumptions that support the “unhackability” of the TLS1.2 connection are&amp;nbsp;in this “What are we going to do about it”-phase:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that our infrastructure team implements TLS1.2 according to the current industry standards”.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that our infrastructure team DOES NOT implement TLS/SSL versions&amp;nbsp;that precede TLS1.2”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that the public-key-pinning mechanism prevents the IoT device from accepting any certificate other than the one we envisioned”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume&amp;nbsp;that the HTTP library in the IoT device doesn’t accidentally connect to the&amp;nbsp;HTTP endpoint with its authentication token to then be redirected”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that HTTPS implementations of our infrastructure are being validated in our quarterly penetration tests”.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;“We assume that Certificate Authority X will refuse CSRs for our domain”&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;Getting these assumptions down is important but the work&amp;nbsp;it’s&amp;nbsp;not done to come to&amp;nbsp;an assumptions&amp;nbsp;register; more on this&amp;nbsp;in the next section.&lt;/p&gt; 
     &lt;p&gt;&lt;b&gt;The Rule of Thumb:&lt;/b&gt;&amp;nbsp;If you&amp;nbsp;don’t&amp;nbsp;have a definitive answer, you have two choices:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;If&amp;nbsp;acquiring&amp;nbsp;the answer is&amp;nbsp;feasible&amp;nbsp;in the short term,&amp;nbsp;document it as an&amp;nbsp;&lt;b&gt;open question&lt;/b&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;If&amp;nbsp;acquiring&amp;nbsp;the answer is not&amp;nbsp;feasible&amp;nbsp;(anymore)&amp;nbsp;document&amp;nbsp;it as an&amp;nbsp;&lt;b&gt;assumption&lt;/b&gt;&amp;nbsp;in&amp;nbsp;(drum roll…)&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Assumption Register&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;A high-quality register&amp;nbsp;could, for example,&amp;nbsp;track&amp;nbsp;the following&amp;nbsp;properties for every assumption:&lt;/p&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;The Assumption:&lt;/b&gt;&amp;nbsp;A clear statement (e.g.,&amp;nbsp;&lt;i&gt;“We assume the end user has an antivirus installed”&lt;/i&gt;).&amp;nbsp;If unclear from the&amp;nbsp;assumption&amp;nbsp;statement&amp;nbsp;itself, a temporal nature can be added&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Validation:&lt;/b&gt;A&amp;nbsp;test that can prove the&amp;nbsp;assumption is correct. (Not always&amp;nbsp;feasible,&amp;nbsp;like the&amp;nbsp;case of a&amp;nbsp;third party&amp;nbsp;computer having A/V installed)&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Confidence (+ Justification):&lt;/b&gt;&amp;nbsp;How sure are you&amp;nbsp;when&amp;nbsp;stating&amp;nbsp;this assumption? (e.g.,&amp;nbsp;&lt;i&gt;“Almost guaranteed due to corporate environment policy”&lt;/i&gt;).&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Consequence if it Fails:&lt;/b&gt;&amp;nbsp;What happens if the assumption is wrong? (e.g.,&amp;nbsp;&lt;i&gt;“The user downloads a virus via our&amp;nbsp;platform&amp;nbsp;and we have no server-side scanning to stop it”&lt;/i&gt;).&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Owner:&lt;/b&gt;Person,&amp;nbsp;department&amp;nbsp;or role that owns the risk of getting the assumption wrong&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion: Don’t Let Unknowns Be Your Downfall&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling is a continuous process of discovery. By&amp;nbsp;identifying&amp;nbsp;your unknowns and tracking your assumptions, you turn “blind spots” into a prioritized list of things to&amp;nbsp;validate.&lt;/p&gt; 
     &lt;p&gt;&lt;b&gt;Next Step for Your Team:&lt;/b&gt;&amp;nbsp;Review your current&amp;nbsp;project’s&amp;nbsp;architecture diagram. Pick one&amp;nbsp;interaction across a trust boundary&amp;nbsp;and ask&amp;nbsp;yourself:&amp;nbsp;&lt;i&gt;“What are we assuming&amp;nbsp;that, if true,&amp;nbsp;makes this secure?”&lt;/i&gt;Converselyask the opposite:&amp;nbsp;&lt;i&gt;“What are we assuming&amp;nbsp;that, if&amp;nbsp;false,&amp;nbsp;makes this&amp;nbsp;insecure?”&lt;/i&gt;&lt;/p&gt; 
     &lt;p&gt;Add those items to&amp;nbsp;your Assumption Register.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author:&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Georges’ lifelong curiosity about ‘how stuff works’ culminated in a Master’s degree in Electro-Mechanical Engineering. With over 15 years of experience in technical and managerial roles within the biotech industry, he developed a deep proficiency in programming and a passion for cybersecurity.&lt;/p&gt; 
        &lt;p&gt;This unique combination of engineering logic and coding expertise makes Georges an ideal Application Security expert; he relates to the daily challenges of software developers while fully understanding the adversarial mindset of hackers. Since transitioning to AppSec in 2017, he has consulted for a wide variety of business contexts.&lt;/p&gt; 
        &lt;p&gt;Georges joined Toreon in 2021, where he currently serves as the Product Owner for Threat Modeling Consulting. He is also the Lead Trainer for Toreon’s globally recognized ‘Whiteboard Hacking’ training. Leveraging his background in electronics, Georges is a key member of the hardware penetration testing team, with specific expertise in threat modeling for embedded medical and non-medical devices.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/georges-bolssens/"&gt;&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Schedule a call&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get in touch with our experts for a no-obligation advisory conversation.&lt;/p&gt; 
     &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://meetings-eu1.hubspot.com/lander-reynvoet"&gt;Contact an expert&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Upcoming Events/Webinars&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Supernova/Cybernova&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;You’ll be able to find us at both&amp;nbsp;&lt;a href="https://www.linkedin.com/company/96627234"&gt;SuperNova&lt;/a&gt;&amp;nbsp;on March 25th and March 26th, and&amp;nbsp;&lt;a href="https://www.linkedin.com/company/107751048"&gt;CyberNova&lt;/a&gt;&amp;nbsp;on March 24th. With Supernova being an internationally renowned event for tech and innovation, and this years first edition of Cybernova, focusing on all things related cybersecurity. Moreover we are also present at the&amp;nbsp;&lt;a href="https://www.linkedin.com/company/14691"&gt;Agoria&lt;/a&gt;&amp;nbsp;boothspace.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Webinar Toreon x IriusRisk&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;This session is the first in our two-part series with IriusRisk and takes a maturity-based look at how threat modeling evolves as organizations scale from startup to enterprise.&lt;/p&gt; 
     &lt;p&gt;You’ll learn how high-performing teams maintain consistent security standards while avoiding common pitfalls such as fragmented processes, inconsistent risk coverage, and duplicated or missed controls.&lt;/p&gt; 
     &lt;p&gt;We’ll explore how the right mix of services, tooling, and best practices helps organizations build scalable, sustainable threat modeling programs, ensuring security keeps pace with business growth.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthe-hidden-risk-in-your-security-design&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <pubDate>Wed, 25 Feb 2026 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/the-hidden-risk-in-your-security-design</guid>
      <dc:date>2026-02-25T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Why Thinking Like a Defender Beats the Attacker Mindset</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/why-thinking-like-a-defender-beats-the-attacker-mindset</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/why-thinking-like-a-defender-beats-the-attacker-mindset" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-1-1.webp" alt="Why Thinking Like a Defender Beats the Attacker Mindset" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;By &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Sebastien Deleersnyder&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;“Think like an attacker.” It’s our industry’s favorite mantra, but for most engineering teams, it’s a setup for failure. It expects developers – who spend their days perfecting “happy flows” – to suddenly pivot into a destructive mindset that goes entirely against their nature.&lt;/p&gt; 
     &lt;p&gt;This creates a bottleneck for organizations attempting to scale threat modeling, as engineers frequently find themselves paralyzed by “creator-blindness”—the natural cognitive inability to see flaws in a system they have specifically designed to succeed. To overcome this paralysis, many teams turn to GenAI for rapid answers, only to be caught in a validation gap where they lack the specialized security expertise required to distinguish between a helpful insight and a dangerous hallucination.&lt;/p&gt; 
     &lt;p&gt;The truth is, you don’t need more “attackers” on your payroll. You need to lean into the &lt;b&gt;Defender’s Advantage&lt;/b&gt;. Here’s why shifting the focus back to your own domain is the better way to make threat modeling stick.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Myth of the "Attacker Mindset"&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Telling a developer to think like an attacker is like telling a home cook to “think like a Michelin-starred chef”. In our &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;threat modeling training&lt;/a&gt;, we often say: &lt;b&gt;“When I’m in the kitchen, my wife saying ‘Think like Jamie Oliver’ doesn’t make me a better chef.”&lt;/b&gt; It’s a nice sentiment, but it isn’t prescriptive or clear.&lt;/p&gt; 
     &lt;p&gt;Most people don’t know how an attacker spends their day or what tools they use. When we demand this mindset, we often just make engineers feel siloed or embarrassed that they “don’t get it”.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Sa&lt;i&gt;ying “It would be helpful to you if you learned to think like an attacker” is exhorting people to learn that skill. Demanding that they do it, or implying that they’re stupid for not knowing how to do it is actively counter-productive.&lt;/i&gt;&lt;/p&gt; 
     &lt;div&gt;
       Adam Shostack, 2008 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Stop the “Attacker Mindset” struggle.&lt;/b&gt; Our&lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Threat Modeling Training&lt;/a&gt; teaches engineers to secure what they build using the systems they already know.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Why a Defender Mindset Makes Threat Modeling Scalable for Developers&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The “Defender’s Mindset” is built on what your engineers already know: their own software design. Instead of chasing an ever-evolving body of attacker knowledge, they focus on their span of control.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Leverage Domain Expertise:&lt;/b&gt; Your devs know their technology stack and the application architecture better than any external threat modeler.&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Predictable Security:&lt;/b&gt; Focusing on security-by-design principles and best practices is a more stable way to improve security posture than reacting to the latest exploit.&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Reduced Friction:&lt;/b&gt; It aligns security with DevOps speed by integrating it into existing workflows rather than imposing a “pull-down” requirement.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The GenAI Trap&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Nowadays, when developers are told to think like attackers, they often turn to Generative AI. This can create a false sense of security, giving them a lot of “knowledge” on attacks without the ability to validate it. AI can list vulnerabilities, but it doesn’t make someone a threat modeler.&lt;/p&gt; 
     &lt;p&gt;Training your team to be defenders allows them to use AI as a tool rather than a crutch, ensuring security is measured alongside your success objectives.&lt;/p&gt; 
     &lt;p&gt;Our training doesn’t just teach you to find threats; it provides the &lt;b&gt;structured framework&lt;/b&gt; necessary to validate AI outputs against your specific architecture, closing the dangerous ‘hallucination gap’ in automated security.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Bridging the Gap: Practical Steps&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;You don’t have to ignore attacks entirely. Use “thinking like an attacker” as a specific awareness tool to show how threats are realized in the real world. But for the day-to-day threat modeling, follow these steps:&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Start with the diagram:&lt;/b&gt; Use structured methods, such as “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps/"&gt;STRIDE-per-interaction&lt;/a&gt;” to help people step outside their “creator-blindness”.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Focus on the stack:&lt;/b&gt; Train teams on the best practices for implementing security in their specific technology stack.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Empower, don’t outsource:&lt;/b&gt; Build the expertise internally in the product teams to reduce reliance on external experts.&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Relying on the “attacker mindset” keeps security as an afterthought, driven by product compliance. By reframing threat modeling as a &lt;b&gt;Defender’s Discipline&lt;/b&gt;, you empower your architects and engineers to take ownership of their security posture. This shift improves risk management, maintains compliance, and ensures you aren’t waiting for a breach to find your vulnerabilities.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Ready to empower your team to own their security?&lt;/b&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Stop letting your architects and engineers feel siloed by unrealistic expectations. It’s time to move beyond the abstract “attacker” mantra and start “doing” with a practical, defender-first framework that actually fits your engineering workflow. By building this expertise internally, you bridge the validation gap and turn security from a bottleneck into a baseline.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Explore our Threat Modeling Trainging for teams&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Sebastien (Seba) Deleersnyder&lt;/strong&gt;, co-founder and CTO of Toreon, combines software engineering expertise with a passion for holistic product security. After earning his Master’s in Software Engineering from the University of Ghent, with a thesis on “Hyphenation using neural networks,” he became a driving force in the security community as&amp;nbsp;the&amp;nbsp;founder of the Belgian OWASP chapter, a member of the OWASP Foundation Board, and co-founder of BruCON, Belgium’s annual security conference. His leadership of OWASP SAMM and&amp;nbsp;his&amp;nbsp;decade-long role as a highly&amp;nbsp;rated Black Hat trainer have significantly impacted global software security, earning consistently outstanding feedback from participants. Currently, Seba focuses on adapting security models for DevOps and expanding awareness of AI Threat Modeling.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Connect with Sebastien Deleersnyder&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/why-thinking-like-a-defender-beats-the-attacker-mindset" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Designing-Cyber-Governance-Board-Structures-and-Practices-for-Effective-Oversight-1-1.webp" alt="Why Thinking Like a Defender Beats the Attacker Mindset" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;By &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Sebastien Deleersnyder&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;“Think like an attacker.” It’s our industry’s favorite mantra, but for most engineering teams, it’s a setup for failure. It expects developers – who spend their days perfecting “happy flows” – to suddenly pivot into a destructive mindset that goes entirely against their nature.&lt;/p&gt; 
     &lt;p&gt;This creates a bottleneck for organizations attempting to scale threat modeling, as engineers frequently find themselves paralyzed by “creator-blindness”—the natural cognitive inability to see flaws in a system they have specifically designed to succeed. To overcome this paralysis, many teams turn to GenAI for rapid answers, only to be caught in a validation gap where they lack the specialized security expertise required to distinguish between a helpful insight and a dangerous hallucination.&lt;/p&gt; 
     &lt;p&gt;The truth is, you don’t need more “attackers” on your payroll. You need to lean into the &lt;b&gt;Defender’s Advantage&lt;/b&gt;. Here’s why shifting the focus back to your own domain is the better way to make threat modeling stick.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Myth of the "Attacker Mindset"&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Telling a developer to think like an attacker is like telling a home cook to “think like a Michelin-starred chef”. In our &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;threat modeling training&lt;/a&gt;, we often say: &lt;b&gt;“When I’m in the kitchen, my wife saying ‘Think like Jamie Oliver’ doesn’t make me a better chef.”&lt;/b&gt; It’s a nice sentiment, but it isn’t prescriptive or clear.&lt;/p&gt; 
     &lt;p&gt;Most people don’t know how an attacker spends their day or what tools they use. When we demand this mindset, we often just make engineers feel siloed or embarrassed that they “don’t get it”.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Sa&lt;i&gt;ying “It would be helpful to you if you learned to think like an attacker” is exhorting people to learn that skill. Demanding that they do it, or implying that they’re stupid for not knowing how to do it is actively counter-productive.&lt;/i&gt;&lt;/p&gt; 
     &lt;div&gt;
       Adam Shostack, 2008 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Stop the “Attacker Mindset” struggle.&lt;/b&gt; Our&lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Threat Modeling Training&lt;/a&gt; teaches engineers to secure what they build using the systems they already know.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Why a Defender Mindset Makes Threat Modeling Scalable for Developers&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The “Defender’s Mindset” is built on what your engineers already know: their own software design. Instead of chasing an ever-evolving body of attacker knowledge, they focus on their span of control.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;b&gt;Leverage Domain Expertise:&lt;/b&gt; Your devs know their technology stack and the application architecture better than any external threat modeler.&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Predictable Security:&lt;/b&gt; Focusing on security-by-design principles and best practices is a more stable way to improve security posture than reacting to the latest exploit.&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Reduced Friction:&lt;/b&gt; It aligns security with DevOps speed by integrating it into existing workflows rather than imposing a “pull-down” requirement.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The GenAI Trap&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Nowadays, when developers are told to think like attackers, they often turn to Generative AI. This can create a false sense of security, giving them a lot of “knowledge” on attacks without the ability to validate it. AI can list vulnerabilities, but it doesn’t make someone a threat modeler.&lt;/p&gt; 
     &lt;p&gt;Training your team to be defenders allows them to use AI as a tool rather than a crutch, ensuring security is measured alongside your success objectives.&lt;/p&gt; 
     &lt;p&gt;Our training doesn’t just teach you to find threats; it provides the &lt;b&gt;structured framework&lt;/b&gt; necessary to validate AI outputs against your specific architecture, closing the dangerous ‘hallucination gap’ in automated security.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Bridging the Gap: Practical Steps&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;You don’t have to ignore attacks entirely. Use “thinking like an attacker” as a specific awareness tool to show how threats are realized in the real world. But for the day-to-day threat modeling, follow these steps:&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;b&gt;Start with the diagram:&lt;/b&gt; Use structured methods, such as “&lt;a href="https://www.toreon.com/threat-modeling-in-4-steps/"&gt;STRIDE-per-interaction&lt;/a&gt;” to help people step outside their “creator-blindness”.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Focus on the stack:&lt;/b&gt; Train teams on the best practices for implementing security in their specific technology stack.&lt;br&gt; &lt;br&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;b&gt;Empower, don’t outsource:&lt;/b&gt; Build the expertise internally in the product teams to reduce reliance on external experts.&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Relying on the “attacker mindset” keeps security as an afterthought, driven by product compliance. By reframing threat modeling as a &lt;b&gt;Defender’s Discipline&lt;/b&gt;, you empower your architects and engineers to take ownership of their security posture. This shift improves risk management, maintains compliance, and ensures you aren’t waiting for a breach to find your vulnerabilities.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;b&gt;Ready to empower your team to own their security?&lt;/b&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Stop letting your architects and engineers feel siloed by unrealistic expectations. It’s time to move beyond the abstract “attacker” mantra and start “doing” with a practical, defender-first framework that actually fits your engineering workflow. By building this expertise internally, you bridge the validation gap and turn security from a bottleneck into a baseline.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Explore our Threat Modeling Trainging for teams&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Sebastien (Seba) Deleersnyder&lt;/strong&gt;, co-founder and CTO of Toreon, combines software engineering expertise with a passion for holistic product security. After earning his Master’s in Software Engineering from the University of Ghent, with a thesis on “Hyphenation using neural networks,” he became a driving force in the security community as&amp;nbsp;the&amp;nbsp;founder of the Belgian OWASP chapter, a member of the OWASP Foundation Board, and co-founder of BruCON, Belgium’s annual security conference. His leadership of OWASP SAMM and&amp;nbsp;his&amp;nbsp;decade-long role as a highly&amp;nbsp;rated Black Hat trainer have significantly impacted global software security, earning consistently outstanding feedback from participants. Currently, Seba focuses on adapting security models for DevOps and expanding awareness of AI Threat Modeling.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Connect with Sebastien Deleersnyder&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fwhy-thinking-like-a-defender-beats-the-attacker-mindset&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <pubDate>Wed, 14 Jan 2026 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/why-thinking-like-a-defender-beats-the-attacker-mindset</guid>
      <dc:date>2026-01-14T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Threat Modeling &amp; Embedded Systems</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-embedded-systems</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-embedded-systems" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Blog-preview-CVE-2025-9709-1.webp" alt="Threat Modeling &amp;amp; Embedded Systems" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;By &lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Robert Hurlbut&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In modern society, everywhere we look, we see examples of embedded systems at work: IoT devices in our homes, critical controllers in industrial facilities, medical devices, and all kinds of vehicles. Despite their ubiquity and importance, these systems often lack robust security frameworks comparable to those in traditional IT systems. This is where threat modeling becomes critical, providing a way to think about secure design and focusing on understanding and mitigating embedded system threats.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Embedded Systems Need Special Attention&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Embedded systems present unique security challenges:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Resource Constraints&lt;/strong&gt;: Typically, embedded devices have limited processing power, memory, and storage. This makes it challenging to implement robust security controls such as encryption or complex authentication mechanisms.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Long Lifecycles&lt;/strong&gt;: Unlike other systems that may be replaced every few years (such as your laptop), embedded systems in industrial control systems or medical devices can remain in service for decades, often without regular security updates.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Physical Accessibility&lt;/strong&gt;: Embedded devices are frequently deployed in locations that are easy to access physically, enabling attackers to gain direct access to hardware.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-Time Requirements&lt;/strong&gt;: Many embedded systems utilize strict timing requirements when responding to inputs, which leaves little room for security overhead that might introduce latency.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Diverse Attack Surfaces&lt;/strong&gt;: Embedded systems can be attacked through software vulnerabilities, hardware manipulation, side-channel attacks, supply chain compromises, and more.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Introducing MITRE EMB3D&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The &lt;a href="https://emb3d.mitre.org/"&gt;MITRE Embedded Device Security (EMB3D) Threat Model&lt;/a&gt; is a comprehensive framework specifically designed to address the unique security challenges of embedded systems. Released as an open-source knowledge base in September 2024, EMB3D (most recently updated to v2.0.1 in April 2025) provides a structured approach to identifying and mitigating threats throughout the embedded device lifecycle.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Key Threats in EMB3D&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;EMB3D organizes threats into a hierarchical taxonomy, which makes it easier to analyze embedded systems systematically:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Device Properties&lt;/strong&gt;: High-level groupings of related threats (Hardware, Application Software, System Software, and Network – see Figure 1 below) 
       &lt;ul&gt; 
        &lt;li&gt;&lt;strong&gt;Threats&lt;/strong&gt;: Specific security concerns within each device property (cataloged through Threat Identifications – TIDs) 
         &lt;ul&gt; 
          &lt;li&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;: Countermeasures to reduce or eliminate threat impacts (cataloged through Mitigation Identifications – MIDs)&lt;/li&gt; 
         &lt;/ul&gt;&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This structure allows security teams (and threat modelers) to methodically review potential threats and vulnerabilities rather than relying on ad-hoc analysis.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The EMB3D Framework Structure&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Threat type&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Examples&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Hardware Threats&lt;/strong&gt;&lt;/p&gt; 
        &lt;p&gt;Hardware is one of the most challenging attack surfaces for embedded systems, as physical access can bypass many software protections.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Debug interface exploitation (JTAG, UART)&lt;/li&gt; 
         &lt;li&gt;Side-channel attacks that extract secrets by analyzing power consumption or electromagnetic emissions&lt;/li&gt; 
         &lt;li&gt;Fault injection attacks that use voltage manipulation to bypass security checks&lt;/li&gt; 
         &lt;li&gt;Physical tampering with components or traces&lt;/li&gt; 
        &lt;/ul&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Application and System Software Threats&lt;/strong&gt;&lt;/p&gt; 
        &lt;p&gt;Embedded systems run software that can contain vulnerabilities.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Buffer overflows and memory corruption in firmware&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;&lt;p&gt;Insecure boot processes that allow malicious code to load · Inadequate code signing and verification.&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;&lt;p&gt;Privilege escalation vulnerabilities&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;&lt;p&gt;Insecure update mechanisms that could allow malicious firmware installation&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Network and Communication Threats&lt;/strong&gt;&lt;/p&gt; 
        &lt;p&gt;As embedded devices increasingly connect to networks, they inherit all the network security challenges of traditional systems, often without defenses.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Unencrypted communications exposing sensitive data&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;Weak or default credentials&lt;/li&gt; 
         &lt;li&gt;Vulnerable protocols and services&lt;/li&gt; 
         &lt;li&gt;Interception attacks&lt;/li&gt; 
         &lt;li&gt;Denial of service vulnerabilities&lt;/li&gt; 
        &lt;/ul&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Using EMB3D in Your Threat Modeling Process&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Here is a practical approach to using EMB3D for embedded system threat modeling:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;1. Define Your System Scope&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Document what you are analyzing. Create a system architecture diagram showing all components, interfaces, data flows, and trust boundaries. Identify what assets you are protecting (user data, cryptographic keys, control functionality, safety features) and document any assumptions about the operational environment.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;2. Map to EMB3D Device Properties&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Work through each EMB3D device property systematically. For each component in your architecture, ask which threats from the framework apply. Consider the entire lifecycle from development through decommissioning.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;3. Assess Threat Severity&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Not all threats pose equal risk. Evaluate each identified threat based on the likelihood of exploitation (considering attacker capability requirements, accessibility, and existing controls) and the potential impact on confidentiality, integrity, availability, and safety.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;4. Identify Gaps and Mitigations&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Compare your current security controls against EMB3D’s recommended mitigations. This gap analysis reveals where the embedded system is exposed to security threats and helps prioritize security investments. Document why you accept specific threats if you choose not to mitigate them.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;5. Validate and Test&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Threat models are only valuable if they reflect reality. Conduct penetration testing and security assessments focused on the threats you have identified. Review and update your threat model as the system evolves or new threats emerge.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Getting Started&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get started with MITRE EMB3D today! Here are five practical next steps:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;1. Access the Framework:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Visit the MITRE EMB3D website to explore the complete threat taxonomy and documentation.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;2. Train Your Team:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Ensure your security team, developers, and architects understand both general threat modeling principles and the specifics of embedded system security.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;3. Start Small:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Begin with a pilot project on a single embedded system to learn the framework before rolling it out more broadly.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;4. Integrate with Development:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Make threat modeling a standard part of your secure development lifecycle, not a one-time exercise.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;5. Stay Current:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;MITRE EMB3D continues to be updated with new or updated threats and mitigations.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;MITRE EMB3D Terms of Use&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;One item to be aware of in using MITRE EMB3D is its &lt;a href="https://emb3d.mitre.org/subtabs/terms-of-use.html"&gt;Terms of Use&lt;/a&gt;. The EMB3D framework is free to use for internal business purposes, academic purposes by public or non-profit educational organizations, and for research. It is not to be used for commercial purposes (i.e., turned into or used as a “for-profit” tool). Please consider these requirements when using the framework.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Embedded systems are becoming increasingly critical to our infrastructure. Rigorous threat modeling is no longer optional. One solution is to check out MITRE EMB3D and its comprehensive, structured approach, specifically tailored to the unique challenges of embedded device security. By systematically working through hardware, software, and&lt;/p&gt; 
     &lt;p&gt;network threats, security teams and threat modelers can identify threats and vulnerabilities before attackers do and implement effective mitigations.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to master threat modeling?&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Become a Certified Threat Modeling Practitioner today!&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Robert Hurlbut, a Principal Product Security Architect and Threat Modeling Trainer at Toreon, has over 30 years of experience in secure coding and software architecture. Before joining Toreon, he initiated and led threat modeling programs at Bank of America and Aquia. Robert is passionate about empowering teams to identify, communicate, and understand threats and mitigations, ultimately enhancing the security of workloads through effective threat modeling. He is an ISC2 Certified Secure Software Lifecycle Professional (CSSLP), holds a Master of Science in Cyber Security from Southern New Hampshire University, and is pursuing a Ph.D. in Space Cybersecurity at Capitol Technology University. Additionally, Robert is a co-author of the Threat Modeling Manifesto and the Threat Modeling Capabilities Model, and he co-hosts the Application Security Podcast. Globally recognized as an expert in threat modeling, he regularly contributes thought leadership and delivers workshops and training at industry events.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Connect with Robert Hurlbut&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-embedded-systems" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Blog-preview-CVE-2025-9709-1.webp" alt="Threat Modeling &amp;amp; Embedded Systems" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;By &lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Robert Hurlbut&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In modern society, everywhere we look, we see examples of embedded systems at work: IoT devices in our homes, critical controllers in industrial facilities, medical devices, and all kinds of vehicles. Despite their ubiquity and importance, these systems often lack robust security frameworks comparable to those in traditional IT systems. This is where threat modeling becomes critical, providing a way to think about secure design and focusing on understanding and mitigating embedded system threats.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Embedded Systems Need Special Attention&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Embedded systems present unique security challenges:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Resource Constraints&lt;/strong&gt;: Typically, embedded devices have limited processing power, memory, and storage. This makes it challenging to implement robust security controls such as encryption or complex authentication mechanisms.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Long Lifecycles&lt;/strong&gt;: Unlike other systems that may be replaced every few years (such as your laptop), embedded systems in industrial control systems or medical devices can remain in service for decades, often without regular security updates.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Physical Accessibility&lt;/strong&gt;: Embedded devices are frequently deployed in locations that are easy to access physically, enabling attackers to gain direct access to hardware.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-Time Requirements&lt;/strong&gt;: Many embedded systems utilize strict timing requirements when responding to inputs, which leaves little room for security overhead that might introduce latency.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Diverse Attack Surfaces&lt;/strong&gt;: Embedded systems can be attacked through software vulnerabilities, hardware manipulation, side-channel attacks, supply chain compromises, and more.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Introducing MITRE EMB3D&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The &lt;a href="https://emb3d.mitre.org/"&gt;MITRE Embedded Device Security (EMB3D) Threat Model&lt;/a&gt; is a comprehensive framework specifically designed to address the unique security challenges of embedded systems. Released as an open-source knowledge base in September 2024, EMB3D (most recently updated to v2.0.1 in April 2025) provides a structured approach to identifying and mitigating threats throughout the embedded device lifecycle.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Key Threats in EMB3D&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;EMB3D organizes threats into a hierarchical taxonomy, which makes it easier to analyze embedded systems systematically:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Device Properties&lt;/strong&gt;: High-level groupings of related threats (Hardware, Application Software, System Software, and Network – see Figure 1 below) 
       &lt;ul&gt; 
        &lt;li&gt;&lt;strong&gt;Threats&lt;/strong&gt;: Specific security concerns within each device property (cataloged through Threat Identifications – TIDs) 
         &lt;ul&gt; 
          &lt;li&gt;&lt;strong&gt;Mitigations&lt;/strong&gt;: Countermeasures to reduce or eliminate threat impacts (cataloged through Mitigation Identifications – MIDs)&lt;/li&gt; 
         &lt;/ul&gt;&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This structure allows security teams (and threat modelers) to methodically review potential threats and vulnerabilities rather than relying on ad-hoc analysis.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The EMB3D Framework Structure&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Threat type&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;Examples&lt;/h2&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Hardware Threats&lt;/strong&gt;&lt;/p&gt; 
        &lt;p&gt;Hardware is one of the most challenging attack surfaces for embedded systems, as physical access can bypass many software protections.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;ul&gt; 
         &lt;li&gt;Debug interface exploitation (JTAG, UART)&lt;/li&gt; 
         &lt;li&gt;Side-channel attacks that extract secrets by analyzing power consumption or electromagnetic emissions&lt;/li&gt; 
         &lt;li&gt;Fault injection attacks that use voltage manipulation to bypass security checks&lt;/li&gt; 
         &lt;li&gt;Physical tampering with components or traces&lt;/li&gt; 
        &lt;/ul&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Application and System Software Threats&lt;/strong&gt;&lt;/p&gt; 
        &lt;p&gt;Embedded systems run software that can contain vulnerabilities.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Buffer overflows and memory corruption in firmware&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;&lt;p&gt;Insecure boot processes that allow malicious code to load · Inadequate code signing and verification.&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;&lt;p&gt;Privilege escalation vulnerabilities&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;&lt;p&gt;Insecure update mechanisms that could allow malicious firmware installation&lt;/p&gt;&lt;/li&gt; 
        &lt;/ul&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Network and Communication Threats&lt;/strong&gt;&lt;/p&gt; 
        &lt;p&gt;As embedded devices increasingly connect to networks, they inherit all the network security challenges of traditional systems, often without defenses.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;ul&gt; 
         &lt;li&gt;&lt;p&gt;Unencrypted communications exposing sensitive data&lt;/p&gt;&lt;/li&gt; 
         &lt;li&gt;Weak or default credentials&lt;/li&gt; 
         &lt;li&gt;Vulnerable protocols and services&lt;/li&gt; 
         &lt;li&gt;Interception attacks&lt;/li&gt; 
         &lt;li&gt;Denial of service vulnerabilities&lt;/li&gt; 
        &lt;/ul&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Using EMB3D in Your Threat Modeling Process&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Here is a practical approach to using EMB3D for embedded system threat modeling:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;1. Define Your System Scope&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Document what you are analyzing. Create a system architecture diagram showing all components, interfaces, data flows, and trust boundaries. Identify what assets you are protecting (user data, cryptographic keys, control functionality, safety features) and document any assumptions about the operational environment.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;2. Map to EMB3D Device Properties&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Work through each EMB3D device property systematically. For each component in your architecture, ask which threats from the framework apply. Consider the entire lifecycle from development through decommissioning.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;3. Assess Threat Severity&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Not all threats pose equal risk. Evaluate each identified threat based on the likelihood of exploitation (considering attacker capability requirements, accessibility, and existing controls) and the potential impact on confidentiality, integrity, availability, and safety.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;4. Identify Gaps and Mitigations&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Compare your current security controls against EMB3D’s recommended mitigations. This gap analysis reveals where the embedded system is exposed to security threats and helps prioritize security investments. Document why you accept specific threats if you choose not to mitigate them.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;5. Validate and Test&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Threat models are only valuable if they reflect reality. Conduct penetration testing and security assessments focused on the threats you have identified. Review and update your threat model as the system evolves or new threats emerge.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Getting Started&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Get started with MITRE EMB3D today! Here are five practical next steps:&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;1. Access the Framework:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Visit the MITRE EMB3D website to explore the complete threat taxonomy and documentation.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;2. Train Your Team:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Ensure your security team, developers, and architects understand both general threat modeling principles and the specifics of embedded system security.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;3. Start Small:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Begin with a pilot project on a single embedded system to learn the framework before rolling it out more broadly.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;4. Integrate with Development:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;Make threat modeling a standard part of your secure development lifecycle, not a one-time exercise.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;5. Stay Current:&lt;/strong&gt;&lt;/p&gt; 
     &lt;p&gt;MITRE EMB3D continues to be updated with new or updated threats and mitigations.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;MITRE EMB3D Terms of Use&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;One item to be aware of in using MITRE EMB3D is its &lt;a href="https://emb3d.mitre.org/subtabs/terms-of-use.html"&gt;Terms of Use&lt;/a&gt;. The EMB3D framework is free to use for internal business purposes, academic purposes by public or non-profit educational organizations, and for research. It is not to be used for commercial purposes (i.e., turned into or used as a “for-profit” tool). Please consider these requirements when using the framework.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Embedded systems are becoming increasingly critical to our infrastructure. Rigorous threat modeling is no longer optional. One solution is to check out MITRE EMB3D and its comprehensive, structured approach, specifically tailored to the unique challenges of embedded device security. By systematically working through hardware, software, and&lt;/p&gt; 
     &lt;p&gt;network threats, security teams and threat modelers can identify threats and vulnerabilities before attackers do and implement effective mitigations.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to master threat modeling?&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Become a Certified Threat Modeling Practitioner today!&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Robert Hurlbut, a Principal Product Security Architect and Threat Modeling Trainer at Toreon, has over 30 years of experience in secure coding and software architecture. Before joining Toreon, he initiated and led threat modeling programs at Bank of America and Aquia. Robert is passionate about empowering teams to identify, communicate, and understand threats and mitigations, ultimately enhancing the security of workloads through effective threat modeling. He is an ISC2 Certified Secure Software Lifecycle Professional (CSSLP), holds a Master of Science in Cyber Security from Southern New Hampshire University, and is pursuing a Ph.D. in Space Cybersecurity at Capitol Technology University. Additionally, Robert is a co-author of the Threat Modeling Manifesto and the Threat Modeling Capabilities Model, and he co-hosts the Application Security Podcast. Globally recognized as an expert in threat modeling, he regularly contributes thought leadership and delivers workshops and training at industry events.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Connect with Robert Hurlbut&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthreat-modeling-embedded-systems&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <pubDate>Tue, 16 Dec 2025 23:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-embedded-systems</guid>
      <dc:date>2025-12-16T23:00:00Z</dc:date>
      <dc:creator>Jordan Hardy</dc:creator>
    </item>
    <item>
      <title>Threat Modeling and Threat Intelligence: Distinct and Complementary | Toreon</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-and-threat-intelligence-distinct-and-complementary</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-and-threat-intelligence-distinct-and-complementary" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/TMI-46-Thumbnail-1-1.png" alt="Threat Modeling and Threat Intelligence: Distinct and Complementary | Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;By Robert Hurlbut&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling and threat intelligence are essential practices of a proactive security strategy. Occasionally, these terms can be confusing or mixed up because they sound similar (both start with “threat” – aren’t they the same?). Instead, these terms represent distinct and complementary approaches to understanding and mitigating cybersecurity risks. This blog post will explore their differences, how they complement each other, and how they can be integrated to provide a more secure posture for your organization.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What is Threat Modeling?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling is a proactive approach to understanding, identifying, and addressing potential security threats to a system, application, or organization. It’s a security analysis technique that examines what could go wrong and how to prevent it.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Key Characteristics of Threat Modeling:&lt;/strong&gt;&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Preventive/Forward-Looking&lt;/strong&gt;: Threat modeling is ideally performed during the design phase or ongoing for an existing system as new features are created and before vulnerabilities can be exploited.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;System-Specific&lt;/strong&gt;: The focus areas are on systems, applications, or business processes, analyzing their unique attack surfaces and potential weaknesses.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Structured Frameworks/Methodologies&lt;/strong&gt;: Common frameworks include &lt;a href="https://en.wikipedia.org/wiki/STRIDE_model"&gt;STRIDE&lt;/a&gt; (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) for application/system-centric threats and &lt;a href="https://linddun.org/"&gt;LINDDUN&lt;/a&gt; for privacy threats. &lt;a href="https://www.iriusrisk.com/resources-blog/pasta-threat-modeling-methodologies"&gt;PASTA&lt;/a&gt; (Process for Attack Simulation and Threat Analysis) is a 7-step methodology.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Threat Modeling Process:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Understand the System&lt;/strong&gt;: Create detailed diagrams showing system architectures, data flows, and trust boundaries&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Identify Threats&lt;/strong&gt;: Use structured approaches to enumerate potential threats against each system component&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Assess Risk&lt;/strong&gt;: Evaluate the likelihood and impact of identified threats&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Define Countermeasures&lt;/strong&gt;: Develop specific controls and mitigations for high-priority threats&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Validate and Iterate&lt;/strong&gt;: Continuously update the model as the system evolves&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What is Threat Intelligence?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat intelligence collects, analyzes, and disseminates information about current and emerging security threats. It analyzes raw data about threats and turns them into actionable insights that inform security decisions.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Key Characteristics of Threat Intelligence:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Data-Driven/Reactive&lt;/strong&gt;: Based on observed threat actor behavior, attack patterns, and indicators of compromise from real-world incidents.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Contextual Information&lt;/strong&gt;: Detailed threat actor motivations, capabilities, tactics, techniques, and procedures (TTPs).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Timeliness&lt;/strong&gt;: It focuses on the current threat landscape and emerging trends that could impact the organization.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;External Focus&lt;/strong&gt;: This strategy typically reviews sources outside the organization, including commercial feeds, open-source intelligence, and industry sharing.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Key Differences Between Threat Modeling and Threat Intelligence&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Threat Modeling&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Threat Intelligence&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Orientation&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Future-focused, anticipates potential threats&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Present and past-focused, analyzing current and historical threats&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Scope/Context&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Internal and system-specific&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;External and industry/threat-landscape focused&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Methodology&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Structured analytical process, uses established frameworks&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Data collection, correlation, and analysis from multiple sources&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Output/Application&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Specific countermeasure/security controls&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Contextual information to inform broader security strategy and operations&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Stakeholders&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Primarily used by developers, architects, and security engineers&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Security operations teams, incident responders, and strategic decision-makers&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;How Threat Modeling and Threat Intelligence Complement Each Other&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Threat Identification&lt;/strong&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;Threat intelligence provides real-world context, making threat modeling more realistic and comprehensive by incorporating actual threat actor behaviors and attack patterns observed in the wild.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Prioritization of Threats&lt;br&gt;&lt;/strong&gt;Threat intelligence helps organizations understand the most relevant threats to their industry, geography, or technology stack. This enables threat modelers to focus on credible attack vectors rather than on every conceivable threat equally.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Validation and Updates&lt;br&gt;&lt;/strong&gt;As threat intelligence reveals new attack techniques or threat actor campaigns, existing threat models can be updated to reflect these evolving realities. This, in turn, creates feedback loops that keep threat models current and relevant.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Strategic and Tactical Security&lt;br&gt;&lt;/strong&gt;Threat modeling provides a tactical approach to security, while threat intelligence provides the strategic context about the threat landscape.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Practical Integration Strategies&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Improving Threat Models&lt;br&gt;&lt;/strong&gt;Begin threat modeling exercises by reviewing any relevant threat intelligence reports. Understanding what threat actors target organizations like yours and their known TTPs can improve threat scenarios.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Validating Threat Models&lt;br&gt;&lt;/strong&gt;Use threat intelligence to validate assumptions made during threat modeling. If your threat model assumes specific attack vectors are unlikely, check whether recent intelligence contradicts this assessment.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Updating Threat Models&lt;br&gt;&lt;/strong&gt;Establish processes to update threat models based on new intelligence regularly. When threat intelligence reveals new attack techniques or threat actors targeting your industry, assess whether your existing threat models account for these developments.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Shared Risk Assessment Framework&lt;br&gt;&lt;/strong&gt;Develop risk assessment criteria incorporating threat modeling outputs (system-specific vulnerabilities) and threat intelligence findings (threat actor capabilities and intentions).&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Cross-Functional Collaboration&lt;br&gt;&lt;/strong&gt;Foster collaboration between threat modeling teams and threat intelligence analysts. Use cross-team training so each set of teams understands the techniques and approaches of the other. &amp;nbsp;Regular knowledge-sharing sessions can help each discipline inform and improve the other.&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling and threat intelligence represent distinct but complementary approaches to cybersecurity risk management. Threat modeling provides the systematic analysis needed to understand and secure specific systems, while threat intelligence offers the external context necessary to understand the evolving threat landscape.&lt;/p&gt; 
     &lt;p&gt;You don’t have to choose between these approaches to apply—you can leverage both of them! By using threat intelligence to inform and validate threat models and threat modeling insights to guide intelligence collection and analysis, organizations can develop a more comprehensive and practical approach to cybersecurity.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to master threat modeling?&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Become a Certified Threat Modeling Practitioner today!&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Robert is a seasoned software developer, software architect, and recognized leader in application security and threat modeling. He is dedicated to helping developers, architects, project managers, and other stakeholders strengthen their understanding of secure software design and architecture through threat modeling and related security practices. A strong advocate for building and sustaining organizational Threat Modeling Programs and Security Champion Programs, Robert brings extensive experience in guiding teams to successfully launch, scale, and mature these initiatives.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Connect with Robert Hurlbut&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-and-threat-intelligence-distinct-and-complementary" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/TMI-46-Thumbnail-1-1.png" alt="Threat Modeling and Threat Intelligence: Distinct and Complementary | Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;By Robert Hurlbut&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling and threat intelligence are essential practices of a proactive security strategy. Occasionally, these terms can be confusing or mixed up because they sound similar (both start with “threat” – aren’t they the same?). Instead, these terms represent distinct and complementary approaches to understanding and mitigating cybersecurity risks. This blog post will explore their differences, how they complement each other, and how they can be integrated to provide a more secure posture for your organization.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What is Threat Modeling?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling is a proactive approach to understanding, identifying, and addressing potential security threats to a system, application, or organization. It’s a security analysis technique that examines what could go wrong and how to prevent it.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Key Characteristics of Threat Modeling:&lt;/strong&gt;&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Preventive/Forward-Looking&lt;/strong&gt;: Threat modeling is ideally performed during the design phase or ongoing for an existing system as new features are created and before vulnerabilities can be exploited.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;System-Specific&lt;/strong&gt;: The focus areas are on systems, applications, or business processes, analyzing their unique attack surfaces and potential weaknesses.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Structured Frameworks/Methodologies&lt;/strong&gt;: Common frameworks include &lt;a href="https://en.wikipedia.org/wiki/STRIDE_model"&gt;STRIDE&lt;/a&gt; (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) for application/system-centric threats and &lt;a href="https://linddun.org/"&gt;LINDDUN&lt;/a&gt; for privacy threats. &lt;a href="https://www.iriusrisk.com/resources-blog/pasta-threat-modeling-methodologies"&gt;PASTA&lt;/a&gt; (Process for Attack Simulation and Threat Analysis) is a 7-step methodology.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;The Threat Modeling Process:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Understand the System&lt;/strong&gt;: Create detailed diagrams showing system architectures, data flows, and trust boundaries&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Identify Threats&lt;/strong&gt;: Use structured approaches to enumerate potential threats against each system component&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Assess Risk&lt;/strong&gt;: Evaluate the likelihood and impact of identified threats&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Define Countermeasures&lt;/strong&gt;: Develop specific controls and mitigations for high-priority threats&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Validate and Iterate&lt;/strong&gt;: Continuously update the model as the system evolves&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;What is Threat Intelligence?&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat intelligence collects, analyzes, and disseminates information about current and emerging security threats. It analyzes raw data about threats and turns them into actionable insights that inform security decisions.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Key Characteristics of Threat Intelligence:&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Data-Driven/Reactive&lt;/strong&gt;: Based on observed threat actor behavior, attack patterns, and indicators of compromise from real-world incidents.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Contextual Information&lt;/strong&gt;: Detailed threat actor motivations, capabilities, tactics, techniques, and procedures (TTPs).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Timeliness&lt;/strong&gt;: It focuses on the current threat landscape and emerging trends that could impact the organization.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;External Focus&lt;/strong&gt;: This strategy typically reviews sources outside the organization, including commercial feeds, open-source intelligence, and industry sharing.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Key Differences Between Threat Modeling and Threat Intelligence&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Threat Modeling&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Threat Intelligence&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Orientation&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Future-focused, anticipates potential threats&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Present and past-focused, analyzing current and historical threats&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Scope/Context&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Internal and system-specific&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;External and industry/threat-landscape focused&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Methodology&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Structured analytical process, uses established frameworks&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Data collection, correlation, and analysis from multiple sources&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Output/Application&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Specific countermeasure/security controls&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Contextual information to inform broader security strategy and operations&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;p&gt;&lt;strong&gt;Stakeholders&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Primarily used by developers, architects, and security engineers&lt;/p&gt;&lt;/td&gt; 
        &lt;td&gt;&lt;p&gt;Security operations teams, incident responders, and strategic decision-makers&lt;/p&gt;&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;How Threat Modeling and Threat Intelligence Complement Each Other&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Threat Identification&lt;/strong&gt;&lt;strong&gt;&lt;br&gt;&lt;/strong&gt;Threat intelligence provides real-world context, making threat modeling more realistic and comprehensive by incorporating actual threat actor behaviors and attack patterns observed in the wild.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Prioritization of Threats&lt;br&gt;&lt;/strong&gt;Threat intelligence helps organizations understand the most relevant threats to their industry, geography, or technology stack. This enables threat modelers to focus on credible attack vectors rather than on every conceivable threat equally.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Validation and Updates&lt;br&gt;&lt;/strong&gt;As threat intelligence reveals new attack techniques or threat actor campaigns, existing threat models can be updated to reflect these evolving realities. This, in turn, creates feedback loops that keep threat models current and relevant.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Strategic and Tactical Security&lt;br&gt;&lt;/strong&gt;Threat modeling provides a tactical approach to security, while threat intelligence provides the strategic context about the threat landscape.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Practical Integration Strategies&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Improving Threat Models&lt;br&gt;&lt;/strong&gt;Begin threat modeling exercises by reviewing any relevant threat intelligence reports. Understanding what threat actors target organizations like yours and their known TTPs can improve threat scenarios.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Validating Threat Models&lt;br&gt;&lt;/strong&gt;Use threat intelligence to validate assumptions made during threat modeling. If your threat model assumes specific attack vectors are unlikely, check whether recent intelligence contradicts this assessment.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Updating Threat Models&lt;br&gt;&lt;/strong&gt;Establish processes to update threat models based on new intelligence regularly. When threat intelligence reveals new attack techniques or threat actors targeting your industry, assess whether your existing threat models account for these developments.&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Shared Risk Assessment Framework&lt;br&gt;&lt;/strong&gt;Develop risk assessment criteria incorporating threat modeling outputs (system-specific vulnerabilities) and threat intelligence findings (threat actor capabilities and intentions).&lt;/li&gt; 
     &lt;/ol&gt; 
     &lt;ol&gt; 
      &lt;li&gt;&lt;strong&gt;Cross-Functional Collaboration&lt;br&gt;&lt;/strong&gt;Foster collaboration between threat modeling teams and threat intelligence analysts. Use cross-team training so each set of teams understands the techniques and approaches of the other. &amp;nbsp;Regular knowledge-sharing sessions can help each discipline inform and improve the other.&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Threat modeling and threat intelligence represent distinct but complementary approaches to cybersecurity risk management. Threat modeling provides the systematic analysis needed to understand and secure specific systems, while threat intelligence offers the external context necessary to understand the evolving threat landscape.&lt;/p&gt; 
     &lt;p&gt;You don’t have to choose between these approaches to apply—you can leverage both of them! By using threat intelligence to inform and validate threat models and threat modeling insights to guide intelligence collection and analysis, organizations can develop a more comprehensive and practical approach to cybersecurity.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to master threat modeling?&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Become a Certified Threat Modeling Practitioner today!&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Robert is a seasoned software developer, software architect, and recognized leader in application security and threat modeling. He is dedicated to helping developers, architects, project managers, and other stakeholders strengthen their understanding of secure software design and architecture through threat modeling and related security practices. A strong advocate for building and sustaining organizational Threat Modeling Programs and Security Champion Programs, Robert brings extensive experience in guiding teams to successfully launch, scale, and mature these initiatives.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Connect with Robert Hurlbut&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthreat-modeling-and-threat-intelligence-distinct-and-complementary&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <pubDate>Tue, 23 Sep 2025 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-and-threat-intelligence-distinct-and-complementary</guid>
      <dc:date>2025-09-23T22:00:00Z</dc:date>
      <dc:creator>Hans Francken</dc:creator>
    </item>
    <item>
      <title>Threat Modeling Insider - August 2025 - Toreon</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-august-2025</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-august-2025" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/TMI-46-Thumbnail-2.png" alt="Threat Modeling Insider - August 2025 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;46th Edition – August 2025&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, Elevation of MLsec: &lt;strong&gt;bringing threat modeling to machine learning practitioners&lt;/strong&gt;, Elias Botterli Sørensen explores how gamification can make ML security risks tangible, helping cross-functional teams identify threats from data poisoning to model misuse in an engaging and practical way.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Robert Hurlbut explores &lt;strong&gt;Space Cybersecurity and Threat Modeling&lt;/strong&gt;, uncovering the unique risks satellites and space systems face and how frameworks like SPARTA can help protect this critical frontier.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, Elevation of MLsec: &lt;strong&gt;bringing threat modeling to machine learning practitioners&lt;/strong&gt;, Elias Brattli Sørensen explores how gamification can make ML security risks tangible, helping cross-functional teams identify threats from data poisoning to model misuse in an engaging and practical way.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Robert Hurlbut explores &lt;strong&gt;Space Cybersecurity and Threat Modeling&lt;/strong&gt;, uncovering the unique risks satellites and space systems face and how frameworks like SPARTA can help protect this critical frontier.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;On this edition&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest article&lt;br&gt;&lt;/b&gt;Elevation of MLsec: bringing threat modeling to machine learning practitioners, by &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/ebsorensen/"&gt;Elias Botterli Sørensen&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; Space Cybersecurity and Threat Modeling, by &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Robert Hurlbut&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated Content&lt;br&gt;&lt;/b&gt;State of Threat Modeling 2024-2025. Community insights shaping threat modeling’s future.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;MITRE Adds Mitigations to EMB3D Threat Model.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;Threat modeling your generative AI workload to evaluate security risk.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;Get started with our DFD library on draw.io.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Guest article&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;Elevation of MLsec: bringing threat modeling to machine learning practitioners&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In 2024, I created the threat modeling card game Elevation of MLsec (EoML), which is a machine learning security extension of Adam Shostack’s well-known game Elevation of Privilege (EoP). Simply put, the cards in the game describe things that can go wrong during the whole lifecycle from machine learning (ML) training and engineering, to operations where models interact with the world.&lt;/p&gt; 
     &lt;p&gt;I believe the game is highly relevant during a period where adoption of machine learning technology like large language models (LLMs) has taken off. Elevation of MLsec follows the same setup and rules as Elevation of Privilege, and can be combined with the original deck if you threat model holistic view of a system with multiple components.&lt;/p&gt; 
     &lt;p&gt;In this article, I will expand upon a bit of the game’s backstory and technical background, as well as my current experiences with applying the game and sharing it with practitioners.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;The magic of gamification&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;As a security professional reading this, you have probably felt the frustration of not being able to get people in the organization properly interested in threat modeling. By gamifying threat modeling in a card game, we remove many of the barriers of people who would otherwise be intimidated or disinterested in such a technical exercise. I see that we humans have a tendency to forget the play when we grow up. All young mammals play to learn.&lt;/p&gt; 
        &lt;p&gt;However, there is very good reason to want to play, and we have good backing for it in academia. The gamification of work-related or academic topics (which involves designing games for an educational purpose outside entertainment), is known as serious games.&lt;/p&gt; 
        &lt;p&gt;&lt;br&gt; Serious games are an effective teaching tool, and can be a great way to direct the discussion of complex issues. When interacting with a game, more of the participants’ senses are activated. A game’s human-focused design nudges players to want to learn and understand more about the topic [1]. I firmly believe that the sensation we get from pulling out a card deck and having something physical in our hands gives us something of pedagogical value that computers can not.&lt;/p&gt; 
        &lt;p&gt;To learn more about this topic, I can recommend Adam Shostack’s whitepaper about EoP [4]. The lessons learned and game design carry well over to the extension EoML.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://github.com/kantega/elevation-of-mlsec"&gt;Elevation of MLsec on GitHub&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Backstory&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;During the autumn of 2022, I watched a lecture from Gary McGraw about his recent work in security engineering for machine learning. This lecture inspired in me a deep interest for machine learning viewed from a security and safety perspective. The work by Gary and his colleagues has been published through the Berryville Institute of Machine Learning (BIML), whose&amp;nbsp;&lt;a href="https://berryvilleiml.com/"&gt;website&lt;/a&gt;&amp;nbsp;has their reports available under the creative commons.&lt;/p&gt; 
     &lt;p&gt;Then later in 2023, I got familiar with Elevation of Privilege through a presentation from a colleague who had used the game to teach threat modeling to his team. While I was already familiar with STRIDE, this was the first time EoP crossed my path. The presentation of this game gave me an idea; why not take the report from BIML and put it into a game like EoP? I worked on an initial draft of the game where I took some of the notable risks from BIML and got help designing a card surface. During this period, BIML published their 2024 report that targeted risks within LLMs. This influenced the game design, which aside from generic ML risks got a few cards that are specific to LLMs. As a nod to the OWASP crew, I also included a couple items from the OWASP top 10 list for LLMs. After several trials of playtesting, I officially announced the game roughly one year ago, in June of 2024. Since then I have been running several more play tests and workshops, and I am still actively collecting feedback from players.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;p&gt;&lt;b&gt;The technical background from BIML&lt;/b&gt;&lt;/p&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;I like the BIML risk framework [2] because they offer a rigorous and holistic view of the ML lifecycle without hand-waving of fluffy terminology. Rather than talking about AI and using anthropocentric terminology, there is a focus on technical details as well as a critical view on the bigger picture. The game Elevation of MLsec applies the risk framework of BIML, who use nine components to describe a generic machine learning lifecycle. An important emphasis is put on the details of the training process, where seemingly harmless decisions can have subtle but dangerous consequences for security or other quality aspects of the system.&lt;/p&gt; 
     &lt;p&gt;For the game, I used four of the components to get my four card suits. The lifecycle with respect to the card suits is shown in the figure below.&lt;/p&gt; 
     &lt;p&gt;The cards suits come from the four&amp;nbsp;&lt;em&gt;objects&lt;/em&gt;: 3. datasets, 6. inputs, 7. model, and 9. outputs. The the ovals in components 1, 2, 4, 5 and 8 (and the polygon in component 1) are processes or data pools that form&amp;nbsp;&lt;em&gt;interfaces&lt;/em&gt;&amp;nbsp;between the objects. Therefore their risks can be considered risks of the object with which they interface. Risks about the system as a whole can also be isolated to one component in our context as it usually is most present in one of the components.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Considering this lifecycle, let’s have a look a few risks to illustrate the range of things that can go wrong in machine learning (ML):&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Data poisoning&lt;/strong&gt;: Data is integral for the security of an ML system. That’s because an ML system learns to do what it does directly from data, and essentially&amp;nbsp;&lt;em&gt;becomes&lt;/em&gt;&amp;nbsp;the data. If an attacker can intentionally manipulate the data being used by an ML system, the entire system can be compromised. Particularly with natural languagem, it is very hard to distinguish poison from “true” data.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Transfer learning attack&lt;/strong&gt;: Model transfer leads to the possibility that what is being reused may be a Trojaned (or otherwise damaged) version of the model.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Transparency&lt;/strong&gt;: It is easier to perform attacks undetected on a black-box system which is not transparent about how it works.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Error propagation&lt;/strong&gt;: When ML output is input to a larger decision process, errors in the ML subsystem may propagate in unforeseen ways.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Input ambiguity&lt;/strong&gt;: English, the main interface language for LLMs, is an ambiguous interface. Natural language can be misleading, making LLMs susceptible to misinformation.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;These risks range from specific attacks from motivated threat actors, to subtle mistakes in engineering decisions made by the builder of an ML system. Both may have some negative consequence for the system that it might be worthwhile to consider. The risks in BIML are fundamental in nature, and address building blocks that are underlying most deep learning models. The ML lifecycle they published is a great way to organize our thinking about the full process of ML. Because of its generality, the BIML framework can very well be narrowed down and used for a particular machine learning system. For example, BIML took their 2020 work about generic ML[2] and applied it to generic LLMs [3].&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Other ML security framework&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;BIML´s particular emphasis on the engineering part of machine learning contrasts&amp;nbsp;&lt;a href="https://atlas.mitre.org/"&gt;MITRE ATLAS&lt;/a&gt;, which is a framework specifically listing various kinds of attacks. The OWASP top ten lists for&amp;nbsp;&lt;a href="https://mltop10.info/"&gt;machine learning&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/"&gt;LLMs&lt;/a&gt;&amp;nbsp;have a ,ore overlap with BIML. While the OWASP lists aren’t as extensive as BIML given their limitation of ten items, they are regularly maintained to incorporate new developments in the field.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Play testing&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The last year has been spent sharing the game, and testing it with various participants, both university students as well as professionals in the industry. I have been running workshops where cross-functional teams with anything from management to tech have been working together to threat model a fictive system. The play tests suggest that the game is a promising way to start discussions about what can go wrong while building or using machine learning technology. The players reported that they were surprised at how engaging it was. Players with a non-technical background paired with technicals were able to threat model a system, and were able to get into the mindset of a security person.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Using it in practice&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This game is one of many available tools that can enrich a product team’s threat modeling process. I think this game can be a good starting point for AI teams that would like to get starter with threat modeling. Playing will hopefully yield a nice and broad overview of what can go wrong in your system, and get you started thinking about AI more the way the people at BIML do. Because of its compatibility with Elevation of Privilege, I also think Elevation of MLsec is a good choice for teams that are already experienced with threat modeling, but need somewhere to start with all this new AI stuff. With the BIML lifecycle as a foundation for thinking about machine learning security, I think you will have a better time absorbing other frameworks, organizing their contents into the components of the generic ML lifecycle.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Intended audience&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;I have reflected on where such a game might be useful. In my opinion, it is very powerful to tackle design discussions in a cross-functional team with representation from various disciplines outside pure technological roles. Still, the following roles may find use for these cards as a way to get started with security engineering in an organization that is employing machine learning in some way:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Security practitioners can use this game to perform relevant threat modeling coaching with ML engineering teams or teams otherwise adopting AI.&lt;/li&gt; 
      &lt;li&gt;ML practitioners and engineers may use this deck as part of their thread modeling process.&lt;/li&gt; 
      &lt;li&gt;Software professionals integrating their “traditional software system” with an ML component can use these cards to get familiar with potential risks that come from integrating the ML component.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;After using the game, it would be natural to explore the richer details of the BIML frameworks for ML in general [2], and for LLMs in particular [3].&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;The way forward&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Moving forward, I am excited to see whether I can bring the game all the way into the heart of data science projects to get the developers started with threat modeling so they can reduce risk while building great things! I am also currently working on a second edition of the game that covers more ground, embeds some more modern developments, and fixes mistakes in the 1.0 version. I warmly welcome any feedback from people who have tried playing the game.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://github.com/kantega/elevation-of-mlsec"&gt;Elevation of MLsec on GitHub&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;References&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;Kowalski, S. J., Von Seth, E., &amp;amp; Zoto, E. (2023). Cs technopoly: A megagame for teaching and learning cybersecurity. Accelerating Open Access Science in Human Factors Engineering and Human-Centered Computing.&lt;/li&gt; 
      &lt;li&gt;McGraw, G., Figueroa, H., Shepardson, V., &amp;amp; Bonett, R. (2020). An architectural risk analysis of machine learning systems: Toward more secure machine learning. Berryville Institute of Machine Learning, Clarke County, VA.&lt;/li&gt; 
      &lt;li&gt;McGraw, G., Figueroa, H., McMahon, K., &amp;amp; Bonett, R. (2024). An architectural risk analysis of large language models: Applied machine learning security. Berryville Inst. Mach. Learn.(BIML), Berryville, VA, USA, Tech. Rep.&lt;/li&gt; 
      &lt;li&gt;Shostack, A. (2014). Elevation of privilege: Drawing developers into threat modeling. In 2014 USENIX Summit on Gaming, Games, and Gamification in Security Education (3GSE 14).&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;CURATED CONTENT&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Toreon Blog: Space Cybersecurity and Threat Modeling&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;State of Threat Modeling 2024-2025&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Outer space is no longer just a realm of exploration. It has become critical infrastructure powering navigation, communications, weather forecasting and national defense. Yet the same systems that connect and protect us are increasingly exposed to cybersecurity risks. From GPS spoofing and satellite jamming to compromised supply chains and solar storms, threats to space assets can ripple across Earth.&lt;/p&gt; 
         &lt;p&gt;In this article Robert Hurlbut examines the growing attack surface in orbit, the unique challenges of space system security and how frameworks like SPARTA and threat modeling can help safeguard our shared space future.&lt;/p&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/space-cybersecurity-and-threat-modeling/"&gt;Read the blog&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;p&gt;Threat modeling is steadily moving from a niche practice to an essential part of secure development. The first-ever &lt;em&gt;State of Threat Modeling 2024–2025&lt;/em&gt; report, based on insights from more than 60 organizations, highlights how teams are applying frameworks, tools, and collaboration to make it work in practice.&lt;/p&gt; 
          &lt;p&gt;While STRIDE remains a cornerstone, most blend multiple approaches, and system diagrams have become a critical enabler. The report also uncovers where adoption stalls, how AI is beginning to play a role, and what maturity looks like for organizations leading the way.&lt;/p&gt; 
          &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.threatmodelingconnect.com/state-of-threat-modeling-2024-25"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;MITRE Adds Mitigations to EMB3D Threat Model&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;MITRE announced the full release of the &lt;strong&gt;EMB3D Threat Model&lt;/strong&gt;, which now includes essential mitigations mapped to security controls specified in the Industrial Automation and Control Systems standard.&lt;/p&gt; 
           &lt;p&gt;Initially announced in December 2023 and&amp;nbsp;&lt;a href="https://www.securityweek.com/mitre-emb3d-threat-model-officially-released/"&gt;officially released&lt;/a&gt;&amp;nbsp;in May 2024,&amp;nbsp;&lt;a href="https://emb3d.mitre.org/"&gt;EMB3D&lt;/a&gt;&amp;nbsp;is a framework offering information on the cyber threats targeting embedded devices used in critical infrastructure and other industries.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.securityweek.com/mitre-adds-mitigations-to-emb3d-threat-model/"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Threat modeling your generative AI workload to evaluate security risk&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt;
          As generative AI models become increasingly integrated into business applications, it’s crucial to evaluate the potential security risks they introduce. A four-step threat modeling process: 
         &lt;strong&gt;defining architecture&lt;/strong&gt;, 
         &lt;strong&gt;identifying threats&lt;/strong&gt;, 
         &lt;strong&gt;articulating them&lt;/strong&gt; clearly, and 
         &lt;strong&gt;assessing risks&lt;/strong&gt; with mitigations, helps organizations systematically strengthen security. By following this approach, organizations can better equip themselves to maintain a high security bar as they adopt generative AI technologies. 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://aws.amazon.com/blogs/security/threat-modeling-your-generative-ai-workload-to-evaluate-security-risk/"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;You can now download our new, free DFD (Data Flow Diagram) template library for draw.io&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;We’ve created a ready-to-use library of Data Flow Diagram templates for draw.io to help you kickstart your threat modeling exercises. Whether you are mapping simple applications or complex architectures, these templates save time, ensure consistency, and make it easier to communicate security insights across your teams. And the best part: it’s &lt;strong&gt;completely free to download and use&lt;/strong&gt;.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Once you start drawio, you can open the library through: 
       &lt;ul&gt; 
        &lt;li&gt;File =&amp;gt;&amp;nbsp;&lt;strong&gt;Open Library from&lt;/strong&gt;&amp;nbsp;=&amp;gt; Device … and select the downloaded library file.&lt;/li&gt; 
        &lt;li&gt;You should then see the DFD elements available in the left pane of the tool:&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://staging.toreon.com/hubfs/Toreon%20DFD%20Library%20-%20Threat%20Modeling.drawio"&gt;Download template&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Our trainings &amp;amp; events for 2025&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4 -5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking, aka Hands-On 1-Day Threat Modeling Workshop, in-person, CyberSecurity Intersection, Orlanda, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;10 October 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://cybersecurityintersection.com/?gad_campaignid=22698645100&amp;amp;gbraid=0AAAAADJS6fbymD19RCnaAHoP_ijakCnvb#!/workshop/AI%20Whiteboard%20Hacking,%20aka%20Hands-On%201-Day%20Threat%20Modeling%20Workshop/8055"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4 -5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking, aka Hands-On 1-Day Threat Modeling Workshop, in-person, CyberSecurity Intersection, Orlanda, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;10 October 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://cybersecurityintersection.com/?gad_campaignid=22698645100&amp;amp;gbraid=0AAAAADJS6fbymD19RCnaAHoP_ijakCnvb#!/workshop/AI%20Whiteboard%20Hacking,%20aka%20Hands-On%201-Day%20Threat%20Modeling%20Workshop/8055"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, NDC Security Manchester, UK&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;1-2 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://ndcsecurity.co.uk/workshops/agile-whiteboard-hacking-aka-hands-on-threat-modeling/2174f00ded6a"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, NDC Security Manchester, UK&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;1-2 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://ndcsecurity.co.uk/workshops/agile-whiteboard-hacking-aka-hands-on-threat-modeling/2174f00ded6a"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Threat Modeling Insider Newsletter&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Delivering the latest Threat Modeling articles and tips straight to your mailbox.&lt;br&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://share-eu1.hsforms.com/1Dc_cA3R9QrCXr6KqluOcQw2b3pne"&gt;Sign up now&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-august-2025" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/TMI-46-Thumbnail-2.png" alt="Threat Modeling Insider - August 2025 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;46th Edition – August 2025&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, Elevation of MLsec: &lt;strong&gt;bringing threat modeling to machine learning practitioners&lt;/strong&gt;, Elias Botterli Sørensen explores how gamification can make ML security risks tangible, helping cross-functional teams identify threats from data poisoning to model misuse in an engaging and practical way.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Robert Hurlbut explores &lt;strong&gt;Space Cybersecurity and Threat Modeling&lt;/strong&gt;, uncovering the unique risks satellites and space systems face and how frameworks like SPARTA can help protect this critical frontier.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, Elevation of MLsec: &lt;strong&gt;bringing threat modeling to machine learning practitioners&lt;/strong&gt;, Elias Brattli Sørensen explores how gamification can make ML security risks tangible, helping cross-functional teams identify threats from data poisoning to model misuse in an engaging and practical way.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Robert Hurlbut explores &lt;strong&gt;Space Cybersecurity and Threat Modeling&lt;/strong&gt;, uncovering the unique risks satellites and space systems face and how frameworks like SPARTA can help protect this critical frontier.&lt;/p&gt; 
     &lt;p&gt;There’s plenty of other actionable insight ahead, so settle in and let’s get started!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;On this edition&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest article&lt;br&gt;&lt;/b&gt;Elevation of MLsec: bringing threat modeling to machine learning practitioners, by &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/ebsorensen/"&gt;Elias Botterli Sørensen&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; Space Cybersecurity and Threat Modeling, by &lt;strong&gt;&lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Robert Hurlbut&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated Content&lt;br&gt;&lt;/b&gt;State of Threat Modeling 2024-2025. Community insights shaping threat modeling’s future.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;MITRE Adds Mitigations to EMB3D Threat Model.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;Threat modeling your generative AI workload to evaluate security risk.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;Get started with our DFD library on draw.io.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Guest article&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;Elevation of MLsec: bringing threat modeling to machine learning practitioners&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In 2024, I created the threat modeling card game Elevation of MLsec (EoML), which is a machine learning security extension of Adam Shostack’s well-known game Elevation of Privilege (EoP). Simply put, the cards in the game describe things that can go wrong during the whole lifecycle from machine learning (ML) training and engineering, to operations where models interact with the world.&lt;/p&gt; 
     &lt;p&gt;I believe the game is highly relevant during a period where adoption of machine learning technology like large language models (LLMs) has taken off. Elevation of MLsec follows the same setup and rules as Elevation of Privilege, and can be combined with the original deck if you threat model holistic view of a system with multiple components.&lt;/p&gt; 
     &lt;p&gt;In this article, I will expand upon a bit of the game’s backstory and technical background, as well as my current experiences with applying the game and sharing it with practitioners.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;The magic of gamification&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;As a security professional reading this, you have probably felt the frustration of not being able to get people in the organization properly interested in threat modeling. By gamifying threat modeling in a card game, we remove many of the barriers of people who would otherwise be intimidated or disinterested in such a technical exercise. I see that we humans have a tendency to forget the play when we grow up. All young mammals play to learn.&lt;/p&gt; 
        &lt;p&gt;However, there is very good reason to want to play, and we have good backing for it in academia. The gamification of work-related or academic topics (which involves designing games for an educational purpose outside entertainment), is known as serious games.&lt;/p&gt; 
        &lt;p&gt;&lt;br&gt; Serious games are an effective teaching tool, and can be a great way to direct the discussion of complex issues. When interacting with a game, more of the participants’ senses are activated. A game’s human-focused design nudges players to want to learn and understand more about the topic [1]. I firmly believe that the sensation we get from pulling out a card deck and having something physical in our hands gives us something of pedagogical value that computers can not.&lt;/p&gt; 
        &lt;p&gt;To learn more about this topic, I can recommend Adam Shostack’s whitepaper about EoP [4]. The lessons learned and game design carry well over to the extension EoML.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://github.com/kantega/elevation-of-mlsec"&gt;Elevation of MLsec on GitHub&lt;/a&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Backstory&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;During the autumn of 2022, I watched a lecture from Gary McGraw about his recent work in security engineering for machine learning. This lecture inspired in me a deep interest for machine learning viewed from a security and safety perspective. The work by Gary and his colleagues has been published through the Berryville Institute of Machine Learning (BIML), whose&amp;nbsp;&lt;a href="https://berryvilleiml.com/"&gt;website&lt;/a&gt;&amp;nbsp;has their reports available under the creative commons.&lt;/p&gt; 
     &lt;p&gt;Then later in 2023, I got familiar with Elevation of Privilege through a presentation from a colleague who had used the game to teach threat modeling to his team. While I was already familiar with STRIDE, this was the first time EoP crossed my path. The presentation of this game gave me an idea; why not take the report from BIML and put it into a game like EoP? I worked on an initial draft of the game where I took some of the notable risks from BIML and got help designing a card surface. During this period, BIML published their 2024 report that targeted risks within LLMs. This influenced the game design, which aside from generic ML risks got a few cards that are specific to LLMs. As a nod to the OWASP crew, I also included a couple items from the OWASP top 10 list for LLMs. After several trials of playtesting, I officially announced the game roughly one year ago, in June of 2024. Since then I have been running several more play tests and workshops, and I am still actively collecting feedback from players.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;p&gt;&lt;b&gt;The technical background from BIML&lt;/b&gt;&lt;/p&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;I like the BIML risk framework [2] because they offer a rigorous and holistic view of the ML lifecycle without hand-waving of fluffy terminology. Rather than talking about AI and using anthropocentric terminology, there is a focus on technical details as well as a critical view on the bigger picture. The game Elevation of MLsec applies the risk framework of BIML, who use nine components to describe a generic machine learning lifecycle. An important emphasis is put on the details of the training process, where seemingly harmless decisions can have subtle but dangerous consequences for security or other quality aspects of the system.&lt;/p&gt; 
     &lt;p&gt;For the game, I used four of the components to get my four card suits. The lifecycle with respect to the card suits is shown in the figure below.&lt;/p&gt; 
     &lt;p&gt;The cards suits come from the four&amp;nbsp;&lt;em&gt;objects&lt;/em&gt;: 3. datasets, 6. inputs, 7. model, and 9. outputs. The the ovals in components 1, 2, 4, 5 and 8 (and the polygon in component 1) are processes or data pools that form&amp;nbsp;&lt;em&gt;interfaces&lt;/em&gt;&amp;nbsp;between the objects. Therefore their risks can be considered risks of the object with which they interface. Risks about the system as a whole can also be isolated to one component in our context as it usually is most present in one of the components.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Considering this lifecycle, let’s have a look a few risks to illustrate the range of things that can go wrong in machine learning (ML):&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Data poisoning&lt;/strong&gt;: Data is integral for the security of an ML system. That’s because an ML system learns to do what it does directly from data, and essentially&amp;nbsp;&lt;em&gt;becomes&lt;/em&gt;&amp;nbsp;the data. If an attacker can intentionally manipulate the data being used by an ML system, the entire system can be compromised. Particularly with natural languagem, it is very hard to distinguish poison from “true” data.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Transfer learning attack&lt;/strong&gt;: Model transfer leads to the possibility that what is being reused may be a Trojaned (or otherwise damaged) version of the model.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Transparency&lt;/strong&gt;: It is easier to perform attacks undetected on a black-box system which is not transparent about how it works.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Error propagation&lt;/strong&gt;: When ML output is input to a larger decision process, errors in the ML subsystem may propagate in unforeseen ways.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Input ambiguity&lt;/strong&gt;: English, the main interface language for LLMs, is an ambiguous interface. Natural language can be misleading, making LLMs susceptible to misinformation.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;These risks range from specific attacks from motivated threat actors, to subtle mistakes in engineering decisions made by the builder of an ML system. Both may have some negative consequence for the system that it might be worthwhile to consider. The risks in BIML are fundamental in nature, and address building blocks that are underlying most deep learning models. The ML lifecycle they published is a great way to organize our thinking about the full process of ML. Because of its generality, the BIML framework can very well be narrowed down and used for a particular machine learning system. For example, BIML took their 2020 work about generic ML[2] and applied it to generic LLMs [3].&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Other ML security framework&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;BIML´s particular emphasis on the engineering part of machine learning contrasts&amp;nbsp;&lt;a href="https://atlas.mitre.org/"&gt;MITRE ATLAS&lt;/a&gt;, which is a framework specifically listing various kinds of attacks. The OWASP top ten lists for&amp;nbsp;&lt;a href="https://mltop10.info/"&gt;machine learning&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/"&gt;LLMs&lt;/a&gt;&amp;nbsp;have a ,ore overlap with BIML. While the OWASP lists aren’t as extensive as BIML given their limitation of ten items, they are regularly maintained to incorporate new developments in the field.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Play testing&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The last year has been spent sharing the game, and testing it with various participants, both university students as well as professionals in the industry. I have been running workshops where cross-functional teams with anything from management to tech have been working together to threat model a fictive system. The play tests suggest that the game is a promising way to start discussions about what can go wrong while building or using machine learning technology. The players reported that they were surprised at how engaging it was. Players with a non-technical background paired with technicals were able to threat model a system, and were able to get into the mindset of a security person.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Using it in practice&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This game is one of many available tools that can enrich a product team’s threat modeling process. I think this game can be a good starting point for AI teams that would like to get starter with threat modeling. Playing will hopefully yield a nice and broad overview of what can go wrong in your system, and get you started thinking about AI more the way the people at BIML do. Because of its compatibility with Elevation of Privilege, I also think Elevation of MLsec is a good choice for teams that are already experienced with threat modeling, but need somewhere to start with all this new AI stuff. With the BIML lifecycle as a foundation for thinking about machine learning security, I think you will have a better time absorbing other frameworks, organizing their contents into the components of the generic ML lifecycle.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;Intended audience&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;I have reflected on where such a game might be useful. In my opinion, it is very powerful to tackle design discussions in a cross-functional team with representation from various disciplines outside pure technological roles. Still, the following roles may find use for these cards as a way to get started with security engineering in an organization that is employing machine learning in some way:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Security practitioners can use this game to perform relevant threat modeling coaching with ML engineering teams or teams otherwise adopting AI.&lt;/li&gt; 
      &lt;li&gt;ML practitioners and engineers may use this deck as part of their thread modeling process.&lt;/li&gt; 
      &lt;li&gt;Software professionals integrating their “traditional software system” with an ML component can use these cards to get familiar with potential risks that come from integrating the ML component.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;After using the game, it would be natural to explore the richer details of the BIML frameworks for ML in general [2], and for LLMs in particular [3].&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;&lt;b&gt;The way forward&lt;/b&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Moving forward, I am excited to see whether I can bring the game all the way into the heart of data science projects to get the developers started with threat modeling so they can reduce risk while building great things! I am also currently working on a second edition of the game that covers more ground, embeds some more modern developments, and fixes mistakes in the 1.0 version. I warmly welcome any feedback from people who have tried playing the game.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://github.com/kantega/elevation-of-mlsec"&gt;Elevation of MLsec on GitHub&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;References&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ol&gt; 
      &lt;li&gt;Kowalski, S. J., Von Seth, E., &amp;amp; Zoto, E. (2023). Cs technopoly: A megagame for teaching and learning cybersecurity. Accelerating Open Access Science in Human Factors Engineering and Human-Centered Computing.&lt;/li&gt; 
      &lt;li&gt;McGraw, G., Figueroa, H., Shepardson, V., &amp;amp; Bonett, R. (2020). An architectural risk analysis of machine learning systems: Toward more secure machine learning. Berryville Institute of Machine Learning, Clarke County, VA.&lt;/li&gt; 
      &lt;li&gt;McGraw, G., Figueroa, H., McMahon, K., &amp;amp; Bonett, R. (2024). An architectural risk analysis of large language models: Applied machine learning security. Berryville Inst. Mach. Learn.(BIML), Berryville, VA, USA, Tech. Rep.&lt;/li&gt; 
      &lt;li&gt;Shostack, A. (2014). Elevation of privilege: Drawing developers into threat modeling. In 2014 USENIX Summit on Gaming, Games, and Gamification in Security Education (3GSE 14).&lt;/li&gt; 
     &lt;/ol&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;CURATED CONTENT&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Toreon Blog: Space Cybersecurity and Threat Modeling&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;State of Threat Modeling 2024-2025&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;p&gt;Outer space is no longer just a realm of exploration. It has become critical infrastructure powering navigation, communications, weather forecasting and national defense. Yet the same systems that connect and protect us are increasingly exposed to cybersecurity risks. From GPS spoofing and satellite jamming to compromised supply chains and solar storms, threats to space assets can ripple across Earth.&lt;/p&gt; 
         &lt;p&gt;In this article Robert Hurlbut examines the growing attack surface in orbit, the unique challenges of space system security and how frameworks like SPARTA and threat modeling can help safeguard our shared space future.&lt;/p&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/space-cybersecurity-and-threat-modeling/"&gt;Read the blog&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;p&gt;Threat modeling is steadily moving from a niche practice to an essential part of secure development. The first-ever &lt;em&gt;State of Threat Modeling 2024–2025&lt;/em&gt; report, based on insights from more than 60 organizations, highlights how teams are applying frameworks, tools, and collaboration to make it work in practice.&lt;/p&gt; 
          &lt;p&gt;While STRIDE remains a cornerstone, most blend multiple approaches, and system diagrams have become a critical enabler. The report also uncovers where adoption stalls, how AI is beginning to play a role, and what maturity looks like for organizations leading the way.&lt;/p&gt; 
          &lt;p&gt;&lt;br&gt;&lt;/p&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.threatmodelingconnect.com/state-of-threat-modeling-2024-25"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;MITRE Adds Mitigations to EMB3D Threat Model&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;MITRE announced the full release of the &lt;strong&gt;EMB3D Threat Model&lt;/strong&gt;, which now includes essential mitigations mapped to security controls specified in the Industrial Automation and Control Systems standard.&lt;/p&gt; 
           &lt;p&gt;Initially announced in December 2023 and&amp;nbsp;&lt;a href="https://www.securityweek.com/mitre-emb3d-threat-model-officially-released/"&gt;officially released&lt;/a&gt;&amp;nbsp;in May 2024,&amp;nbsp;&lt;a href="https://emb3d.mitre.org/"&gt;EMB3D&lt;/a&gt;&amp;nbsp;is a framework offering information on the cyber threats targeting embedded devices used in critical infrastructure and other industries.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.securityweek.com/mitre-adds-mitigations-to-emb3d-threat-model/"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Threat modeling your generative AI workload to evaluate security risk&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt;
          As generative AI models become increasingly integrated into business applications, it’s crucial to evaluate the potential security risks they introduce. A four-step threat modeling process: 
         &lt;strong&gt;defining architecture&lt;/strong&gt;, 
         &lt;strong&gt;identifying threats&lt;/strong&gt;, 
         &lt;strong&gt;articulating them&lt;/strong&gt; clearly, and 
         &lt;strong&gt;assessing risks&lt;/strong&gt; with mitigations, helps organizations systematically strengthen security. By following this approach, organizations can better equip themselves to maintain a high security bar as they adopt generative AI technologies. 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://aws.amazon.com/blogs/security/threat-modeling-your-generative-ai-workload-to-evaluate-security-risk/"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;You can now download our new, free DFD (Data Flow Diagram) template library for draw.io&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;We’ve created a ready-to-use library of Data Flow Diagram templates for draw.io to help you kickstart your threat modeling exercises. Whether you are mapping simple applications or complex architectures, these templates save time, ensure consistency, and make it easier to communicate security insights across your teams. And the best part: it’s &lt;strong&gt;completely free to download and use&lt;/strong&gt;.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;Once you start drawio, you can open the library through: 
       &lt;ul&gt; 
        &lt;li&gt;File =&amp;gt;&amp;nbsp;&lt;strong&gt;Open Library from&lt;/strong&gt;&amp;nbsp;=&amp;gt; Device … and select the downloaded library file.&lt;/li&gt; 
        &lt;li&gt;You should then see the DFD elements available in the left pane of the tool:&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://staging.toreon.com/hubfs/Toreon%20DFD%20Library%20-%20Threat%20Modeling.drawio"&gt;Download template&lt;/a&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Our trainings &amp;amp; events for 2025&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4 -5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking, aka Hands-On 1-Day Threat Modeling Workshop, in-person, CyberSecurity Intersection, Orlanda, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;10 October 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://cybersecurityintersection.com/?gad_campaignid=22698645100&amp;amp;gbraid=0AAAAADJS6fbymD19RCnaAHoP_ijakCnvb#!/workshop/AI%20Whiteboard%20Hacking,%20aka%20Hands-On%201-Day%20Threat%20Modeling%20Workshop/8055"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4 -5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;AI Whiteboard Hacking, aka Hands-On 1-Day Threat Modeling Workshop, in-person, CyberSecurity Intersection, Orlanda, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;10 October 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://cybersecurityintersection.com/?gad_campaignid=22698645100&amp;amp;gbraid=0AAAAADJS6fbymD19RCnaAHoP_ijakCnvb#!/workshop/AI%20Whiteboard%20Hacking,%20aka%20Hands-On%201-Day%20Threat%20Modeling%20Workshop/8055"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, NDC Security Manchester, UK&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;1-2 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://ndcsecurity.co.uk/workshops/agile-whiteboard-hacking-aka-hands-on-threat-modeling/2174f00ded6a"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, NDC Security Manchester, UK&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;1-2 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://ndcsecurity.co.uk/workshops/agile-whiteboard-hacking-aka-hands-on-threat-modeling/2174f00ded6a"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Threat Modeling Insider Newsletter&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Delivering the latest Threat Modeling articles and tips straight to your mailbox.&lt;br&gt;&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://share-eu1.hsforms.com/1Dc_cA3R9QrCXr6KqluOcQw2b3pne"&gt;Sign up now&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthreat-modeling-insider-august-2025&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <pubDate>Wed, 27 Aug 2025 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-august-2025</guid>
      <dc:date>2025-08-27T22:00:00Z</dc:date>
      <dc:creator>Hans Francken</dc:creator>
    </item>
    <item>
      <title>Threat Modeling Insider - June 2025 - Toreon</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-2025</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-2025" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Maestro-1.png" alt="Threat Modeling Insider - June 2025 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;45th Edition – June 2025&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, &lt;i&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk&lt;/i&gt;, Michael Novack explores AI agent threats, relevant mitigations, and strategies to focus your security efforts.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Sebastien Deleersnyder presents STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
     &lt;p&gt;But that’s not everything, so let’s dive in!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, &lt;i&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk&lt;/i&gt;, Michael Novack explores AI agent threats, relevant mitigations, and strategies to focus your security efforts.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Sebastien Deleersnyder presents STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
     &lt;p&gt;But that’s not everything, so let’s dive in!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;On this edition&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest article&lt;br&gt;&lt;/b&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk, by &lt;a href="https://www.linkedin.com/in/michael-novack/"&gt;&lt;strong&gt;Michael Novack&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; Mind the Gap: STRIDE-AI, by &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;&lt;strong&gt;Sebastien Deleersnyder&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;Threat Modeling as Code: Implementing STRIDE in DevSecOps&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;Threat Modeling Guide for Software Teams&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;Securing HTTP based APIs&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Guest article&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In the evolving landscape of cybersecurity, AI agents present both opportunities and unique challenges. It’s crucial to understand the gaps in your cybersecurity program to effectively protect these advanced systems. This presentation will explore AI agent threats, relevant mitigations, and strategies to focus your security efforts.&lt;/p&gt; 
     &lt;p&gt;The threats are novel enough according to the Cloud Security Alliance they made a new threat modeling framework called MAESTRO just for AI agents. We discuss if this is really needed.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What are AI Agents?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;AI agents are advanced systems that utilize artificial intelligence to perform actions or make decisions, often with some degree of autonomy. They are designed to perceive their environment, process information, and take actions to achieve specific goals.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Understanding AI Agent Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The perspectives on the threat landscape for AI agents vary widely. Some believe existing cybersecurity programs are sufficient, while others express alarm about the inadequacy of current controls in an AI-driven world.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;To highlight this disparity we will compare the AI agent threat modeling framework MAESTRO from the Cloud Security Alliance to a modified version of STRIDE.&lt;/p&gt; 
     &lt;p&gt;We want to be clear that the point of this article is NOT to say MAESTRO is not needed. We acknowledge there are gaps with STRIDE which is why we have to modify it for an AI agent use case. We are using the widely-adopted STRIDE framework to illustrate how much of a gap MAESTRO is actually filling. Use what works best for your needs.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What is MAESTRO?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;MAESTRO (Multi-Agentic System Threat Model) is a 7-layer reference architecture for agentic AI developed by the Cloud Security Alliance. This framework is designed to provide a structured approach to threat modeling for AI agents, addressing the limitations of traditional methods like STRIDE.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Why Does MAESTRO Exist?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Current threat modeling frameworks, like STRIDE, are not well-suited for AI agents. STRIDE, while a good starting point, doesn’t fully address the unique challenges posed by AI agents, such as adversarial attacks and risks associated with unpredictable learning and decision-making. MAESTRO provides a more tailored approach to threat modeling in this context.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A Modified STRIDE + ML&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;To better understand the gaps that AI creates in a cybersecurity program, let’s modify STRIDE so it can handle the unique challenges of AI agents. This is done by incorporating two new threat categories “Misunderstanding” and “Lack of Accountability” (ML), which can be employed.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Misunderstanding:&lt;/strong&gt; This refers to models having undesirable assessments due to a lack of context or malicious intervention, leading to unexpected emerging behaviors.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Lack of Accountability:&lt;/strong&gt; This occurs when actions are performed without clear governance or ownership, making it difficult to determine responsibility when issues arise.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Applying STRIDE + ML to AI Agents&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Frameworks such as the OWASP Multi Agentic Threat Modeling Guide and the Cloud Security Alliance Agentic Threat Modeling Guide can be mapped into STRIDE + ML to provide a clearer view of AI agent threats. This mapping reveals that a significant portion of AI agent threats can be categorized using traditional STRIDE, but a notable percentage require the additional ML categories.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Source documentation:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro"&gt;Cloud Security Alliance – MAESTRO framework and threats&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/"&gt;OWASP Multi Agentic system Threat Modeling Guide&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/"&gt;OWASP AI Agent Threats and Mitigation&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;AI Agent Threats and Mitigations&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;AI agent threats can be categorized, and mitigations can be mapped to these categories. Some threats can be mitigated using existing cybersecurity measures, while others require extending capabilities or implementing new mitigations.&lt;/p&gt; 
     &lt;p&gt;We use the OWASP AI Agent threat taxonomy as it is more concise compared to the Cloud Security Alliance taxonomy. Almost all of the threats in the Cloud Security Alliance threat taxonomy can be categorized into the OWASP taxonomy.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Threats with Existing Mitigations:&lt;/strong&gt; 
       &lt;ul&gt; 
        &lt;li&gt;Spoofing (T9 – Identity Spoofing)&lt;/li&gt; 
        &lt;li&gt;Repudiation (T8 – Repudiation and Untraceability)&lt;/li&gt; 
        &lt;li&gt;Information Disclosure (T12 – Agent Communication Poisoning)&lt;/li&gt; 
        &lt;li&gt;Denial of Service (T4 – Resource Overload)&lt;/li&gt; 
        &lt;li&gt;Elevation of Privilege (T3 – Privilege Compromise)&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Threats Requiring Expanded Mitigations:&lt;/strong&gt; This category includes 
       &lt;ul&gt; 
        &lt;li&gt;Spoofing (T13 – Rogue Agents)&lt;/li&gt; 
        &lt;li&gt;Tampering (T11 – Unexpected RCE and Code Attacks, T1 – Memory Poisoning)&lt;/li&gt; 
        &lt;li&gt;Denial of Service (T10 – Overwhelming HITL)&lt;/li&gt; 
        &lt;li&gt;Elevation of Privilege (T14 – Human attacks on MAS)&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Threats Requiring New Mitigations:&lt;/strong&gt; These are unique to AI agents 
       &lt;ul&gt; 
        &lt;li&gt;Misunderstanding (T2 – Tool Misuse, T5 – Cascading Hallucinations, T6 – Intent Breaking &amp;amp; Goal Manipulation)&lt;/li&gt; 
        &lt;li&gt;Lack of Accountability (T7 – Misaligned &amp;amp; Deceptive Behaviour, T15 – Human Trust Manipulation)&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Mitigation Options and AI-Specific Considerations&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The cloud security alliance provides a good list of mitigations to focus on. Many of the mitigations should be part of any robust cybersecurity program regardless if AI is used or not. Below are the additional mitigations required specifically for AI systems.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Mitigation&lt;/td&gt; 
        &lt;td&gt;Description&lt;/td&gt; 
        &lt;td&gt;Example&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Review internal governance and control frameworks&lt;/td&gt; 
        &lt;td&gt;Train agents to be robust against adversarial examples.&lt;/td&gt; 
        &lt;td&gt;During the model training process add in an example of prompts trying to get toxic responses about ageism. These should be labeled so the model knows that this type of prompt should not be answered.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Formal Verification&lt;/td&gt; 
        &lt;td&gt;Use formal methods to verify agent behavior and ensure goal alignment.&lt;/td&gt; 
        &lt;td&gt;Given the intent of an agent is only to provide information and analysis about a customer's bank account. Regularly audit that an agent is not attempting to do unexpected activity like transfer funds.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Explainable AI (XAI)&lt;/td&gt; 
        &lt;td&gt;Improve transparency in agent decision-making to facilitate auditing.&lt;/td&gt; 
        &lt;td&gt;Be able to explain why an insurance claim agent denied a specific customer's claim.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Red Teaming&lt;/td&gt; 
        &lt;td&gt;Simulate attacks to identify vulnerabilities.&lt;/td&gt; 
        &lt;td&gt;Researching the latest prompt injection techniques and seeing if they are successful or not on your system.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Safety Monitoring&lt;/td&gt; 
        &lt;td&gt;Implement runtime monitoring to detect unsafe agent behaviors.&lt;/td&gt; 
        &lt;td&gt;With a platform independent of the agent, verifying incoming prompts are not attempts of jailbreaking or trying to get the agent to do unethical actions like illegal or discriminatory behavior.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Focusing Your Efforts&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The AI agent space is not as unique as many portray it to be, but we also cannot pretend that our existing cybersecurity control strategy is sufficient.&lt;/p&gt; 
     &lt;p&gt;To effectively improve the ROI of your AI agent security efforts, focus on:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;First look at your current capabilities to see how you can address ~⅔ of the AI threat space.&lt;/li&gt; 
      &lt;li&gt;Look at the market for the emergent ~⅓ of AI threats, as these mitigations are being built now, so unlikely to exist with your current capabilities.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;By understanding the nuances of AI agent threats and applying targeted mitigations, organizations can better protect these systems and maximize their return on investment in AI technologies.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;CSA threats related to OWASP threats&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The table below is a mapping of the threats defined in the OWASP AI Agent Threat and Mitigation Guide to the threats in the Cloud Security Alliance MAESTRO documentation. As most of the analysis of this blog is done using the OWASP threat taxonomy, I wanted to make sure you see how it relates to the CSA documentation, as it is the source of the MAESTRO threat modeling framework, and OWASP Mult-Agent Threat Modeling Guide references the CSA documentation.&lt;/p&gt; 
     &lt;p&gt;OWASP AI Agent Mitigation Guide tries to only call out threats that are unique to AI Agents. (Section &lt;em&gt;Reference Threat Model&lt;/em&gt; in OWASP AI Agent Threat and Mitigation Guide). It builds upon the existing OWASP documentation to reduce redundancy. Some of the CSA threats correspond to threats called out in other OWASP documentation.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;API## = &lt;a href="https://owasp.org/API-Security/editions/2023/en/0x11-t10/"&gt;OWASP Top 10 API&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;A## = &lt;a href="https://owasp.org/Top10/"&gt;OWASP Top 10 2021&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;LMM## = &lt;a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/"&gt;OWASP Top 10 LLM&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;STRIDE + ML&lt;/td&gt; 
        &lt;td&gt;OWASP&lt;/td&gt; 
        &lt;td&gt;CSA&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;S&lt;/b&gt;poofing&lt;/td&gt; 
        &lt;td&gt;T9 – Identity Spoofing&lt;/td&gt; 
        &lt;td&gt;Agent Impersonation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T13 – Rogue Agents&lt;/td&gt; 
        &lt;td&gt;Compromised Security AI Agents &lt;br&gt; Compromised Agents&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;T&lt;/b&gt;ampering&lt;/td&gt; 
        &lt;td&gt;T1 – Memory Poisoning&lt;/td&gt; 
        &lt;td&gt;Data Poisoning &lt;br&gt; Data Tampering &lt;br&gt; Security Agent Data Poisoning&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T11 - Unexpected RCE and Code Attacks&lt;/td&gt; 
        &lt;td&gt;Input Validation Attacks&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;LLM03:2025 Supply Chain &lt;br&gt; A06:2021-Vulnerable and Outdated Components&lt;br&gt; API9:2023 - Improper Inventory Management&lt;/td&gt; 
        &lt;td&gt;Supply Chain Attacks&lt;br&gt; Compromised Framework Components&lt;br&gt; Compromised Observability Tools&lt;br&gt; Marketplace Manipulation&lt;br&gt; Integration Risks&lt;br&gt; Compromised Agent Registry&lt;br&gt; Malicious Agent Discovery&lt;br&gt; Agent Pricing Model Manipulation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;A08:2021-Software and Data Integrity Failures&lt;/td&gt; 
        &lt;td&gt;Compromised Container Images&lt;br&gt; Infrastructure-as-Code (IaC) Manipulation&lt;br&gt; Compromised RAG Pipelines&lt;br&gt; Manipulation of Evaluation Metrics&lt;br&gt; Poisoning Observability Data&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;R&lt;/b&gt;epudiation&lt;/td&gt; 
        &lt;td&gt;T8 – Repudiation and Untraceability&lt;/td&gt; 
        &lt;td&gt;Repudiation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;I&lt;/b&gt;nformation&lt;br&gt; &lt;b&gt;D&lt;/b&gt;isclosure&lt;/td&gt; 
        &lt;td&gt;T12 – Agent Communication Poisoning&lt;/td&gt; 
        &lt;td&gt;Not called out as a unique threat, but in mitigations&lt;br&gt; Secure Inter-Layer Communication&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;LLM02:2025 Sensitive Information Disclosure&lt;/td&gt; 
        &lt;td&gt;Data Leakage&lt;br&gt; Data Exfiltration&lt;br&gt; Data Leakage through Observability&lt;br&gt; Model Stealing&lt;br&gt; Model Inversion/Extraction&lt;br&gt; Model Extraction of AI Security Agents&lt;br&gt; Membership Inference Attacks&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;D&lt;/b&gt;enial of Service&lt;/td&gt; 
        &lt;td&gt;T4 – Resource Overload&lt;/td&gt; 
        &lt;td&gt;Denial of Service on Data Infrastructure&lt;br&gt; Denial of Service on Framework APIs&lt;br&gt; Denial of Service (DoS) Attacks&lt;br&gt; Resource Hijacking&lt;br&gt; Denial of Service on Evaluation Infrastructure&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T10 – Overwhelming HITL&lt;/td&gt; 
        &lt;td&gt;No clear equivalent in CSA&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;E&lt;/b&gt;levation of Privilege&lt;/td&gt; 
        &lt;td&gt;T3 – Privilege Compromise&lt;/td&gt; 
        &lt;td&gt;Lateral Movement&lt;br&gt; Privilege Escalation&lt;br&gt; Backdoor Attacks&lt;br&gt; Orchestration Attacks&lt;br&gt; Agent Identity Attack&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T14 – Human attacks on MAS&lt;/td&gt; 
        &lt;td&gt;No clear equivalent in CSA&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;M&lt;/b&gt;isunderstanding&lt;/td&gt; 
        &lt;td&gt;T2 – Tool Misuse&lt;/td&gt; 
        &lt;td&gt;Agent Tool Misuse&lt;br&gt; Inaccurate Agent Capability Description&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T5 - Cascading Hallucinations&lt;/td&gt; 
        &lt;td&gt;Goal Misalignment Cascades&lt;br&gt; Horizontal/Vertical Solution Vulnerabilities&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T6 – Intent Breaking &amp;amp; Goal Manipulation&lt;/td&gt; 
        &lt;td&gt;Agent Goal Manipulation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T7 – Misaligned &amp;amp; Deceptive Behaviour&lt;/td&gt; 
        &lt;td&gt;Reprogramming Attacks&lt;br&gt; Adversarial Examples&lt;br&gt; Framework Evasion&lt;br&gt; Evasion of Detection&lt;br&gt; Evasion of Security AI Agents&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;L&lt;/b&gt;ack of Accountability&lt;/td&gt; 
        &lt;td&gt;T15 – Human Trust Manipulation&lt;/td&gt; 
        &lt;td&gt;Regulatory Non-Compliance by AI Security Agents&lt;br&gt; Bias in Security AI Agents&lt;br&gt; Lack of Explainability in Security AI Agents&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;OWASP threats justification for each STRIDE + ML category&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;STRIDE + ML&lt;/td&gt; 
        &lt;td&gt;OWASP&lt;/td&gt; 
        &lt;td&gt;Justification&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;S&lt;/b&gt;poofing&lt;/td&gt; 
        &lt;td&gt;T9 – Identity Spoofing&lt;/td&gt; 
        &lt;td&gt;Attackers exploiting authentication mechanisms to impersonate AI agents or human users. By assuming a false identity, the attacker can then execute unauthorized actions under that guise.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T13 – Rogue Agents&lt;/td&gt; 
        &lt;td&gt;An attacker might leverage identity spoofing techniques to impersonate a legitimate AI agent. By successfully authenticating as an existing agent or creating a new agent that masquerades as legitimate, the attacker can introduce a "rogue" agent into the system under a false identity. This rogue agent can then carry out malicious activities.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;T&lt;/b&gt;ampering&lt;/td&gt; 
        &lt;td&gt;T1 – Memory Poisoning&lt;/td&gt; 
        &lt;td&gt;An attacker injecting malicious data or code into the memory space of an AI agent or the underlying system. This directly constitutes unauthorized modification, which is the core of the Tampering threat category.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T11 - Unexpected RCE and Code Attacks&lt;/td&gt; 
        &lt;td&gt;The ultimate aim of an attacker exploiting an RCE vulnerability is to tamper with the system's intended state and behavior. By injecting and executing their own code, they are directly modifying how the AI agent operates, the data it processes, or the system it runs on.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;R&lt;/b&gt;epudiation&lt;/td&gt; 
        &lt;td&gt;T8 – Repudiation and Untraceability&lt;/td&gt; 
        &lt;td&gt;This category deals with the ability of an attacker (or even a legitimate user) to deny having performed an action or transaction. Untraceability directly supports repudiation by making it difficult or impossible to link an action back to a specific individual or entity.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;I&lt;/b&gt;nformation&lt;br&gt; &lt;b&gt;D&lt;/b&gt;isclosure&lt;/td&gt; 
        &lt;td&gt;T12 – Agent Communication Poisoning&lt;/td&gt; 
        &lt;td&gt;This category deals with the threat of an attacker gaining unauthorized access to sensitive information and potentially altering. You could make the case for this to be in Tampering as well. If communication between AI agents is not properly secured, an attacker eavesdropping on the network can gain valuable insights.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;D&lt;/b&gt;enial of Service&lt;/td&gt; 
        &lt;td&gt;T4 – Resource Overload&lt;/td&gt; 
        &lt;td&gt;This category focuses on attacks that aim to make a system or service unavailable to legitimate users or processes. Resource overload, by its very nature, achieves this by consuming excessive system resources (CPU, memory, network bandwidth, storage) to the point where the AI agent or the underlying system can no longer function correctly or respond to legitimate requests.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T10 – Overwhelming HITL&lt;/td&gt; 
        &lt;td&gt;The core of "Overwhelming HITL" is to flood the human operator with an excessive number of requests, alerts, or decisions, rendering them unable to effectively process and respond in a timely manner. This effectively makes the HITL component unavailable or significantly degrades its performance, leading to a denial of the intended service or oversight.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;E&lt;/b&gt;levation of Privilege&lt;/td&gt; 
        &lt;td&gt;T3 – Privilege Compromise&lt;/td&gt; 
        &lt;td&gt;This category focuses on the threat of an attacker gaining higher levels of access or permissions than they were originally intended to have. Privilege compromise is precisely the act of an attacker successfully obtaining these elevated privileges within the AI agent system or its underlying infrastructure.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T14 – Human attacks on MAS&lt;/td&gt; 
        &lt;td&gt;In many scenarios, human attackers might not be exploiting technical vulnerabilities to gain new privileges. Instead, they might be leveraging their existing authorized access and the inherent trust the system places in human operators to perform actions that go beyond the expected or safe scope of their intended use.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;M&lt;/b&gt;isunderstanding&lt;/td&gt; 
        &lt;td&gt;T2 – Tool Misuse&lt;/td&gt; 
        &lt;td&gt;An AI agent or user lacks sufficient context about a tool's function or is misled by malicious input, leading to a flawed assessment of its proper application. This flawed assessment results in the tool being used in unintended ways, causing unexpected and undesirable emerging behaviors in the AI system due to this fundamental misunderstanding of the tool's role or implications.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T5 - Cascading Hallucinations&lt;/td&gt; 
        &lt;td&gt;An initial lack of context or a maliciously introduced falsehood leads an AI model to make an incorrect assessment, which then compounds in subsequent reasoning steps, generating further inaccurate outputs and unexpected behaviors. Each hallucination builds upon a prior flawed assessment, demonstrating a cascading "Misunderstanding" of the underlying information or task.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T6 – Intent Breaking &amp;amp; Goal Manipulation&lt;/td&gt; 
        &lt;td&gt;A model's assessment of the user's intended goal is incorrect due to a lack of proper context or malicious prompting designed to mislead it. This "Misunderstanding" of the desired outcome results in the model exhibiting unexpected behaviors that deviate from or actively subvert the user's actual objective.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;L&lt;/b&gt;ack of Accountability&lt;/td&gt; 
        &lt;td&gt;T7 – Misaligned &amp;amp; Deceptive Behaviour&lt;/td&gt; 
        &lt;td&gt;A model's assessment of appropriate action is flawed due to insufficient context regarding ethical guidelines or malicious prompting that manipulates its understanding of desirable behavior. This "Lack of Accountability" leads to unexpected emerging behaviors that are either not aligned with intended values or actively deceptive.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T15 – Human Trust ManipulationS&lt;/td&gt; 
        &lt;td&gt;When a model's output, influenced by insufficient context or malicious prompting, leads a human to form an inaccurate assessment of the model's reliability or the situation it presents. This "Lack of Accountability" of the model's trustworthiness can result in unexpected and potentially harmful human behaviors based on that flawed assessment.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;OWASP justify level of mitigations in the industry justification&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Mitigation Availability&lt;/td&gt; 
        &lt;td&gt;OWASP Threat&lt;/td&gt; 
        &lt;td&gt;Justification&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Existing&lt;/td&gt; 
        &lt;td&gt;T9 – Identity Spoofing&lt;/td&gt; 
        &lt;td&gt;Standard Identity Access Management (IAM) should be used&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T8 - Repudiation and Untraceability&lt;/td&gt; 
        &lt;td&gt;Standard logging methods will suffice.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T12 - Agent Communication Poising&lt;/td&gt; 
        &lt;td&gt;There are established protocols to perform secure communication. If using new protocols they should have similar levels of cryptographic and authentication capabilities.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T4 - Resource Overload&lt;/td&gt; 
        &lt;td&gt;There are robust mechanisms to throttle rate limits on a frequency and payload level. This just needs to be applied to APIs that utilize LLM capabilities.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T3 - Privilege Compromise&lt;/td&gt; 
        &lt;td&gt;This calls out standard least privilege controls with strong authN/authZ systems and only granting the permission that is needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Expand&lt;/td&gt; 
        &lt;td&gt;T13-Rougue Agents&lt;/td&gt; 
        &lt;td&gt;We have ways to detect if infrastructure has been compromised. Now the activities a rogue agent would perform are more subtle, so these detection mechanisms should be improved.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T11 - Unexpected RCE and Code Attacks&lt;/td&gt; 
        &lt;td&gt;Your infrastructure should already be limited to not execute arbitrary code. There are also some detection mechanisms for detecting and understanding code, but these capabilities will need to get better to comfortably full allow agents to generate and utilize code on the fly.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T1 - Memory Poisoning&lt;/td&gt; 
        &lt;td&gt;The core mitigations are: &lt;br&gt; - Session management to separate users memory and regularly clearing. &lt;br&gt; - This in the expand category as normally memory management is more about performance than security.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T10 - Overwhelming HITL&lt;/td&gt; 
        &lt;td&gt;We do have ways to mitigate DDoS attacks, but these are normally in the context of protecting technology workloads not people. That being said we can adopt some of those principles when routing traffic to people to resolve.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T14 - Human attacks on MAS&lt;/td&gt; 
        &lt;td&gt;Apply a zero-trust mentality between agents. All actions should be fully validated if authorized and appropriate when communication between agents happen. As it might be hard to know what are valid actions we can apply a zero-trust mentality to get part of the way there.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;New&lt;/td&gt; 
        &lt;td&gt;T2 - Tool Misuse&lt;/td&gt; 
        &lt;td&gt;The ecosystem of tools are actively evolving and the industry standards are being established. Things like MCP auto-discovery of tools is a new type of 3rd party risk. In theory an agent could use a new tool without anyone's knowledge. This a level of dynamic 3rd party management the industry has not done before.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T5 - Cascading Hallucionations&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T6 - Intent Breaking &amp;amp; Goal Manipulationg&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T7 - Misaligned &amp;amp; Deceptive Behavior&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T15 - Human Trust Manipulation&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;CURATED CONTENT&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Toreon Blog: Mind the Gap: STRIDE-AI&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Threat Modeling as Code: Implementing STRIDE in DevSecOps&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The security landscape is changing rapidly as AI integrates into every part of our lives – from smart assistants and recommendation systems to autonomous vehicles and vision technology. While traditional cybersecurity practices remain essential, AI-enabled systems introduce new types of threats that require a specialized approach. At Toreon, we’ve experienced this firsthand. That’s why we’re excited to launch STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/stride-ai-your-clear-path-to-understanding-ai-vulnerabilities/"&gt;Read the blog&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;In the DevSecOps era, security is built into the development lifecycle, not bolted on after the fact. While traditional methods can slow delivery, Threat Modeling as Code (TMAC) enables automated, scalable, and continuous security assessments.&lt;/p&gt; 
           &lt;p&gt;This article explores how to implement STRIDE, a Microsoft-developed threat classification framework, within DevSecOps. Learn how to automate threat modeling, integrate it into your CI/CD pipelines, and catch vulnerabilities early, before they reach production.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://medium.com/@urshilaravindran/threat-modeling-as-code-implementing-stride-in-devsecops-0dd9f9ff06c1"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Threat Modeling Guide for Software Teams&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt;
          Threat modeling helps teams understand how data moves through systems and spot risks that automated tools often miss. Instead of treating it as a one-time or standalone activity, teams should embed threat modeling into their development workflow through small, ongoing efforts. This article offers practical ways to get started, whether you’re focused on application development, infrastructure, or both. With rising cybersecurity threats and growing accountability, making threat modeling a regular habit is more important than ever. 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://martinfowler.com/articles/agile-threat-modelling.html"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Securing HTTP-based APIs&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This UK NCSC guidance offers practical advice for securing HTTP-based APIs and is intended for technical teams involved in designing or building applications with API endpoints. Keep in mind that full security depends on performing threat modelling tailored to your specific architecture and use cases.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.ncsc.gov.uk/collection/securing-http-based-apis"&gt;Learn more&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Our Black Hat "Whiteboard Hacking" (hands-on threat modeling) training is going virtual!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While we’ll miss the in-person experience, this opens up the opportunity for more participants worldwide who might not be able to travel to Las Vegas. &lt;br&gt; Our training stands out due to its hands-on nature, small group work, collaboration, and exercises based on real-world situations.&lt;/p&gt; 
     &lt;p&gt;This year, we’re covering hot topics including:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;AI threat modeling, with exercises related to chatbots&lt;/li&gt; 
      &lt;li&gt;Cloud, including storage and CI/CD pipelines&lt;/li&gt; 
      &lt;li&gt;IoT, embedded devices, and systems&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Robert Hurlbut&lt;/a&gt; will be delivering the training, so we’re looking forward to seeing you there!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.blackhat.com/us-25/training/schedule/index.html#advanced-whiteboard-hacking---aka-hands-on-threat-modeling-online-44481"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Our trainings &amp;amp; events for 2025&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, virtual, hosted by Black Hat USA, Las Vegas&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;2-5 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 18 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.blackhat.com/us-25/training/schedule/index.html#advanced-whiteboard-hacking---aka-hands-on-threat-modeling-44481"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, virtual, hosted by Black Hat USA, Las Vegas&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;2-5 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.blackhat.com/us-25/training/schedule/index.html#advanced-whiteboard-hacking---aka-hands-on-threat-modeling-44481"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 18 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Hands-on Threat Modeling AI, in-person, hosted by BruCON, Belgium&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;22-24 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.brucon.org/training"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Hands-on Threat Modeling AI, in-person, hosted by BruCON, Belgium&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;22-24 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.brucon.org/training"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, NDC Security Manchester, UK&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;1-2 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://ndcsecurity.co.uk/workshops/agile-whiteboard-hacking-aka-hands-on-threat-modeling/2174f00ded6a"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Stay updated with high quality educational material every month.&lt;br&gt; No ads, no spam. Just pure learning.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Join 2000+ companies who learn about threat modeling every month!&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-2025" title="" class="hs-featured-image-link"&gt; &lt;img src="https://staging.toreon.com/hubfs/Imported_Blog_Media/Maestro-1.png" alt="Threat Modeling Insider - June 2025 - Toreon" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;45th Edition – June 2025&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, &lt;i&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk&lt;/i&gt;, Michael Novack explores AI agent threats, relevant mitigations, and strategies to focus your security efforts.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Sebastien Deleersnyder presents STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
     &lt;p&gt;But that’s not everything, so let’s dive in!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Welcome!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Welcome to this month’s edition of &lt;strong&gt;Threat Modeling Insider&lt;/strong&gt;! In our featured guest article, &lt;i&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk&lt;/i&gt;, Michael Novack explores AI agent threats, relevant mitigations, and strategies to focus your security efforts.&lt;/p&gt; 
     &lt;p&gt;Meanwhile, on the Toreon blog, Sebastien Deleersnyder presents STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
     &lt;p&gt;But that’s not everything, so let’s dive in!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/tmi-threat-modeling/"&gt;Read our previous newsletters&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;On this edition&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Guest article&lt;br&gt;&lt;/b&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk, by &lt;a href="https://www.linkedin.com/in/michael-novack/"&gt;&lt;strong&gt;Michael Novack&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Toreon Blog&lt;/b&gt;&lt;br&gt; Mind the Gap: STRIDE-AI, by &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;&lt;strong&gt;Sebastien Deleersnyder&lt;/strong&gt;&lt;/a&gt;&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;Threat Modeling as Code: Implementing STRIDE in DevSecOps&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Curated content&lt;br&gt;&lt;/b&gt;Threat Modeling Guide for Software Teams&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;b&gt;Tips &amp;amp; tricks&lt;br&gt;&lt;/b&gt;Securing HTTP based APIs&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;&lt;strong&gt;Training update&lt;br&gt;&lt;/strong&gt;An update on our training sessions.&lt;/p&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Guest article&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;&lt;b&gt;Securing AI Agents: A Framework to Maximize ROI, Minimize Risk&lt;/b&gt;&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;In the evolving landscape of cybersecurity, AI agents present both opportunities and unique challenges. It’s crucial to understand the gaps in your cybersecurity program to effectively protect these advanced systems. This presentation will explore AI agent threats, relevant mitigations, and strategies to focus your security efforts.&lt;/p&gt; 
     &lt;p&gt;The threats are novel enough according to the Cloud Security Alliance they made a new threat modeling framework called MAESTRO just for AI agents. We discuss if this is really needed.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What are AI Agents?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;p&gt;AI agents are advanced systems that utilize artificial intelligence to perform actions or make decisions, often with some degree of autonomy. They are designed to perceive their environment, process information, and take actions to achieve specific goals.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;h3&gt;Understanding AI Agent Threat Modeling&lt;/h3&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The perspectives on the threat landscape for AI agents vary widely. Some believe existing cybersecurity programs are sufficient, while others express alarm about the inadequacy of current controls in an AI-driven world.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;To highlight this disparity we will compare the AI agent threat modeling framework MAESTRO from the Cloud Security Alliance to a modified version of STRIDE.&lt;/p&gt; 
     &lt;p&gt;We want to be clear that the point of this article is NOT to say MAESTRO is not needed. We acknowledge there are gaps with STRIDE which is why we have to modify it for an AI agent use case. We are using the widely-adopted STRIDE framework to illustrate how much of a gap MAESTRO is actually filling. Use what works best for your needs.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;What is MAESTRO?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;MAESTRO (Multi-Agentic System Threat Model) is a 7-layer reference architecture for agentic AI developed by the Cloud Security Alliance. This framework is designed to provide a structured approach to threat modeling for AI agents, addressing the limitations of traditional methods like STRIDE.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Why Does MAESTRO Exist?&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Current threat modeling frameworks, like STRIDE, are not well-suited for AI agents. STRIDE, while a good starting point, doesn’t fully address the unique challenges posed by AI agents, such as adversarial attacks and risks associated with unpredictable learning and decision-making. MAESTRO provides a more tailored approach to threat modeling in this context.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;A Modified STRIDE + ML&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;To better understand the gaps that AI creates in a cybersecurity program, let’s modify STRIDE so it can handle the unique challenges of AI agents. This is done by incorporating two new threat categories “Misunderstanding” and “Lack of Accountability” (ML), which can be employed.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Misunderstanding:&lt;/strong&gt; This refers to models having undesirable assessments due to a lack of context or malicious intervention, leading to unexpected emerging behaviors.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Lack of Accountability:&lt;/strong&gt; This occurs when actions are performed without clear governance or ownership, making it difficult to determine responsibility when issues arise.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Applying STRIDE + ML to AI Agents&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Frameworks such as the OWASP Multi Agentic Threat Modeling Guide and the Cloud Security Alliance Agentic Threat Modeling Guide can be mapped into STRIDE + ML to provide a clearer view of AI agent threats. This mapping reveals that a significant portion of AI agent threats can be categorized using traditional STRIDE, but a notable percentage require the additional ML categories.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Source documentation:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;a href="https://cloudsecurityalliance.org/blog/2025/02/06/agentic-ai-threat-modeling-framework-maestro"&gt;Cloud Security Alliance – MAESTRO framework and threats&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/"&gt;OWASP Multi Agentic system Threat Modeling Guide&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;a href="https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/"&gt;OWASP AI Agent Threats and Mitigation&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;AI Agent Threats and Mitigations&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;AI agent threats can be categorized, and mitigations can be mapped to these categories. Some threats can be mitigated using existing cybersecurity measures, while others require extending capabilities or implementing new mitigations.&lt;/p&gt; 
     &lt;p&gt;We use the OWASP AI Agent threat taxonomy as it is more concise compared to the Cloud Security Alliance taxonomy. Almost all of the threats in the Cloud Security Alliance threat taxonomy can be categorized into the OWASP taxonomy.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Threats with Existing Mitigations:&lt;/strong&gt; 
       &lt;ul&gt; 
        &lt;li&gt;Spoofing (T9 – Identity Spoofing)&lt;/li&gt; 
        &lt;li&gt;Repudiation (T8 – Repudiation and Untraceability)&lt;/li&gt; 
        &lt;li&gt;Information Disclosure (T12 – Agent Communication Poisoning)&lt;/li&gt; 
        &lt;li&gt;Denial of Service (T4 – Resource Overload)&lt;/li&gt; 
        &lt;li&gt;Elevation of Privilege (T3 – Privilege Compromise)&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Threats Requiring Expanded Mitigations:&lt;/strong&gt; This category includes 
       &lt;ul&gt; 
        &lt;li&gt;Spoofing (T13 – Rogue Agents)&lt;/li&gt; 
        &lt;li&gt;Tampering (T11 – Unexpected RCE and Code Attacks, T1 – Memory Poisoning)&lt;/li&gt; 
        &lt;li&gt;Denial of Service (T10 – Overwhelming HITL)&lt;/li&gt; 
        &lt;li&gt;Elevation of Privilege (T14 – Human attacks on MAS)&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Threats Requiring New Mitigations:&lt;/strong&gt; These are unique to AI agents 
       &lt;ul&gt; 
        &lt;li&gt;Misunderstanding (T2 – Tool Misuse, T5 – Cascading Hallucinations, T6 – Intent Breaking &amp;amp; Goal Manipulation)&lt;/li&gt; 
        &lt;li&gt;Lack of Accountability (T7 – Misaligned &amp;amp; Deceptive Behaviour, T15 – Human Trust Manipulation)&lt;/li&gt; 
       &lt;/ul&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Mitigation Options and AI-Specific Considerations&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The cloud security alliance provides a good list of mitigations to focus on. Many of the mitigations should be part of any robust cybersecurity program regardless if AI is used or not. Below are the additional mitigations required specifically for AI systems.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Mitigation&lt;/td&gt; 
        &lt;td&gt;Description&lt;/td&gt; 
        &lt;td&gt;Example&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Review internal governance and control frameworks&lt;/td&gt; 
        &lt;td&gt;Train agents to be robust against adversarial examples.&lt;/td&gt; 
        &lt;td&gt;During the model training process add in an example of prompts trying to get toxic responses about ageism. These should be labeled so the model knows that this type of prompt should not be answered.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Formal Verification&lt;/td&gt; 
        &lt;td&gt;Use formal methods to verify agent behavior and ensure goal alignment.&lt;/td&gt; 
        &lt;td&gt;Given the intent of an agent is only to provide information and analysis about a customer's bank account. Regularly audit that an agent is not attempting to do unexpected activity like transfer funds.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Explainable AI (XAI)&lt;/td&gt; 
        &lt;td&gt;Improve transparency in agent decision-making to facilitate auditing.&lt;/td&gt; 
        &lt;td&gt;Be able to explain why an insurance claim agent denied a specific customer's claim.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Red Teaming&lt;/td&gt; 
        &lt;td&gt;Simulate attacks to identify vulnerabilities.&lt;/td&gt; 
        &lt;td&gt;Researching the latest prompt injection techniques and seeing if they are successful or not on your system.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Safety Monitoring&lt;/td&gt; 
        &lt;td&gt;Implement runtime monitoring to detect unsafe agent behaviors.&lt;/td&gt; 
        &lt;td&gt;With a platform independent of the agent, verifying incoming prompts are not attempts of jailbreaking or trying to get the agent to do unethical actions like illegal or discriminatory behavior.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Focusing Your Efforts&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The AI agent space is not as unique as many portray it to be, but we also cannot pretend that our existing cybersecurity control strategy is sufficient.&lt;/p&gt; 
     &lt;p&gt;To effectively improve the ROI of your AI agent security efforts, focus on:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;First look at your current capabilities to see how you can address ~⅔ of the AI threat space.&lt;/li&gt; 
      &lt;li&gt;Look at the market for the emergent ~⅓ of AI threats, as these mitigations are being built now, so unlikely to exist with your current capabilities.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;By understanding the nuances of AI agent threats and applying targeted mitigations, organizations can better protect these systems and maximize their return on investment in AI technologies.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;CSA threats related to OWASP threats&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The table below is a mapping of the threats defined in the OWASP AI Agent Threat and Mitigation Guide to the threats in the Cloud Security Alliance MAESTRO documentation. As most of the analysis of this blog is done using the OWASP threat taxonomy, I wanted to make sure you see how it relates to the CSA documentation, as it is the source of the MAESTRO threat modeling framework, and OWASP Mult-Agent Threat Modeling Guide references the CSA documentation.&lt;/p&gt; 
     &lt;p&gt;OWASP AI Agent Mitigation Guide tries to only call out threats that are unique to AI Agents. (Section &lt;em&gt;Reference Threat Model&lt;/em&gt; in OWASP AI Agent Threat and Mitigation Guide). It builds upon the existing OWASP documentation to reduce redundancy. Some of the CSA threats correspond to threats called out in other OWASP documentation.&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;API## = &lt;a href="https://owasp.org/API-Security/editions/2023/en/0x11-t10/"&gt;OWASP Top 10 API&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;A## = &lt;a href="https://owasp.org/Top10/"&gt;OWASP Top 10 2021&lt;/a&gt;&lt;/li&gt; 
      &lt;li&gt;LMM## = &lt;a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/"&gt;OWASP Top 10 LLM&lt;/a&gt;&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;STRIDE + ML&lt;/td&gt; 
        &lt;td&gt;OWASP&lt;/td&gt; 
        &lt;td&gt;CSA&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;S&lt;/b&gt;poofing&lt;/td&gt; 
        &lt;td&gt;T9 – Identity Spoofing&lt;/td&gt; 
        &lt;td&gt;Agent Impersonation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T13 – Rogue Agents&lt;/td&gt; 
        &lt;td&gt;Compromised Security AI Agents &lt;br&gt; Compromised Agents&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;T&lt;/b&gt;ampering&lt;/td&gt; 
        &lt;td&gt;T1 – Memory Poisoning&lt;/td&gt; 
        &lt;td&gt;Data Poisoning &lt;br&gt; Data Tampering &lt;br&gt; Security Agent Data Poisoning&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T11 - Unexpected RCE and Code Attacks&lt;/td&gt; 
        &lt;td&gt;Input Validation Attacks&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;LLM03:2025 Supply Chain &lt;br&gt; A06:2021-Vulnerable and Outdated Components&lt;br&gt; API9:2023 - Improper Inventory Management&lt;/td&gt; 
        &lt;td&gt;Supply Chain Attacks&lt;br&gt; Compromised Framework Components&lt;br&gt; Compromised Observability Tools&lt;br&gt; Marketplace Manipulation&lt;br&gt; Integration Risks&lt;br&gt; Compromised Agent Registry&lt;br&gt; Malicious Agent Discovery&lt;br&gt; Agent Pricing Model Manipulation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;A08:2021-Software and Data Integrity Failures&lt;/td&gt; 
        &lt;td&gt;Compromised Container Images&lt;br&gt; Infrastructure-as-Code (IaC) Manipulation&lt;br&gt; Compromised RAG Pipelines&lt;br&gt; Manipulation of Evaluation Metrics&lt;br&gt; Poisoning Observability Data&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;R&lt;/b&gt;epudiation&lt;/td&gt; 
        &lt;td&gt;T8 – Repudiation and Untraceability&lt;/td&gt; 
        &lt;td&gt;Repudiation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;I&lt;/b&gt;nformation&lt;br&gt; &lt;b&gt;D&lt;/b&gt;isclosure&lt;/td&gt; 
        &lt;td&gt;T12 – Agent Communication Poisoning&lt;/td&gt; 
        &lt;td&gt;Not called out as a unique threat, but in mitigations&lt;br&gt; Secure Inter-Layer Communication&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;LLM02:2025 Sensitive Information Disclosure&lt;/td&gt; 
        &lt;td&gt;Data Leakage&lt;br&gt; Data Exfiltration&lt;br&gt; Data Leakage through Observability&lt;br&gt; Model Stealing&lt;br&gt; Model Inversion/Extraction&lt;br&gt; Model Extraction of AI Security Agents&lt;br&gt; Membership Inference Attacks&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;D&lt;/b&gt;enial of Service&lt;/td&gt; 
        &lt;td&gt;T4 – Resource Overload&lt;/td&gt; 
        &lt;td&gt;Denial of Service on Data Infrastructure&lt;br&gt; Denial of Service on Framework APIs&lt;br&gt; Denial of Service (DoS) Attacks&lt;br&gt; Resource Hijacking&lt;br&gt; Denial of Service on Evaluation Infrastructure&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T10 – Overwhelming HITL&lt;/td&gt; 
        &lt;td&gt;No clear equivalent in CSA&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;E&lt;/b&gt;levation of Privilege&lt;/td&gt; 
        &lt;td&gt;T3 – Privilege Compromise&lt;/td&gt; 
        &lt;td&gt;Lateral Movement&lt;br&gt; Privilege Escalation&lt;br&gt; Backdoor Attacks&lt;br&gt; Orchestration Attacks&lt;br&gt; Agent Identity Attack&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T14 – Human attacks on MAS&lt;/td&gt; 
        &lt;td&gt;No clear equivalent in CSA&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;M&lt;/b&gt;isunderstanding&lt;/td&gt; 
        &lt;td&gt;T2 – Tool Misuse&lt;/td&gt; 
        &lt;td&gt;Agent Tool Misuse&lt;br&gt; Inaccurate Agent Capability Description&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T5 - Cascading Hallucinations&lt;/td&gt; 
        &lt;td&gt;Goal Misalignment Cascades&lt;br&gt; Horizontal/Vertical Solution Vulnerabilities&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T6 – Intent Breaking &amp;amp; Goal Manipulation&lt;/td&gt; 
        &lt;td&gt;Agent Goal Manipulation&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T7 – Misaligned &amp;amp; Deceptive Behaviour&lt;/td&gt; 
        &lt;td&gt;Reprogramming Attacks&lt;br&gt; Adversarial Examples&lt;br&gt; Framework Evasion&lt;br&gt; Evasion of Detection&lt;br&gt; Evasion of Security AI Agents&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;L&lt;/b&gt;ack of Accountability&lt;/td&gt; 
        &lt;td&gt;T15 – Human Trust Manipulation&lt;/td&gt; 
        &lt;td&gt;Regulatory Non-Compliance by AI Security Agents&lt;br&gt; Bias in Security AI Agents&lt;br&gt; Lack of Explainability in Security AI Agents&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;OWASP threats justification for each STRIDE + ML category&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;STRIDE + ML&lt;/td&gt; 
        &lt;td&gt;OWASP&lt;/td&gt; 
        &lt;td&gt;Justification&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;S&lt;/b&gt;poofing&lt;/td&gt; 
        &lt;td&gt;T9 – Identity Spoofing&lt;/td&gt; 
        &lt;td&gt;Attackers exploiting authentication mechanisms to impersonate AI agents or human users. By assuming a false identity, the attacker can then execute unauthorized actions under that guise.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T13 – Rogue Agents&lt;/td&gt; 
        &lt;td&gt;An attacker might leverage identity spoofing techniques to impersonate a legitimate AI agent. By successfully authenticating as an existing agent or creating a new agent that masquerades as legitimate, the attacker can introduce a "rogue" agent into the system under a false identity. This rogue agent can then carry out malicious activities.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;T&lt;/b&gt;ampering&lt;/td&gt; 
        &lt;td&gt;T1 – Memory Poisoning&lt;/td&gt; 
        &lt;td&gt;An attacker injecting malicious data or code into the memory space of an AI agent or the underlying system. This directly constitutes unauthorized modification, which is the core of the Tampering threat category.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T11 - Unexpected RCE and Code Attacks&lt;/td&gt; 
        &lt;td&gt;The ultimate aim of an attacker exploiting an RCE vulnerability is to tamper with the system's intended state and behavior. By injecting and executing their own code, they are directly modifying how the AI agent operates, the data it processes, or the system it runs on.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;R&lt;/b&gt;epudiation&lt;/td&gt; 
        &lt;td&gt;T8 – Repudiation and Untraceability&lt;/td&gt; 
        &lt;td&gt;This category deals with the ability of an attacker (or even a legitimate user) to deny having performed an action or transaction. Untraceability directly supports repudiation by making it difficult or impossible to link an action back to a specific individual or entity.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;I&lt;/b&gt;nformation&lt;br&gt; &lt;b&gt;D&lt;/b&gt;isclosure&lt;/td&gt; 
        &lt;td&gt;T12 – Agent Communication Poisoning&lt;/td&gt; 
        &lt;td&gt;This category deals with the threat of an attacker gaining unauthorized access to sensitive information and potentially altering. You could make the case for this to be in Tampering as well. If communication between AI agents is not properly secured, an attacker eavesdropping on the network can gain valuable insights.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;D&lt;/b&gt;enial of Service&lt;/td&gt; 
        &lt;td&gt;T4 – Resource Overload&lt;/td&gt; 
        &lt;td&gt;This category focuses on attacks that aim to make a system or service unavailable to legitimate users or processes. Resource overload, by its very nature, achieves this by consuming excessive system resources (CPU, memory, network bandwidth, storage) to the point where the AI agent or the underlying system can no longer function correctly or respond to legitimate requests.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T10 – Overwhelming HITL&lt;/td&gt; 
        &lt;td&gt;The core of "Overwhelming HITL" is to flood the human operator with an excessive number of requests, alerts, or decisions, rendering them unable to effectively process and respond in a timely manner. This effectively makes the HITL component unavailable or significantly degrades its performance, leading to a denial of the intended service or oversight.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;E&lt;/b&gt;levation of Privilege&lt;/td&gt; 
        &lt;td&gt;T3 – Privilege Compromise&lt;/td&gt; 
        &lt;td&gt;This category focuses on the threat of an attacker gaining higher levels of access or permissions than they were originally intended to have. Privilege compromise is precisely the act of an attacker successfully obtaining these elevated privileges within the AI agent system or its underlying infrastructure.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T14 – Human attacks on MAS&lt;/td&gt; 
        &lt;td&gt;In many scenarios, human attackers might not be exploiting technical vulnerabilities to gain new privileges. Instead, they might be leveraging their existing authorized access and the inherent trust the system places in human operators to perform actions that go beyond the expected or safe scope of their intended use.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;M&lt;/b&gt;isunderstanding&lt;/td&gt; 
        &lt;td&gt;T2 – Tool Misuse&lt;/td&gt; 
        &lt;td&gt;An AI agent or user lacks sufficient context about a tool's function or is misled by malicious input, leading to a flawed assessment of its proper application. This flawed assessment results in the tool being used in unintended ways, causing unexpected and undesirable emerging behaviors in the AI system due to this fundamental misunderstanding of the tool's role or implications.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T5 - Cascading Hallucinations&lt;/td&gt; 
        &lt;td&gt;An initial lack of context or a maliciously introduced falsehood leads an AI model to make an incorrect assessment, which then compounds in subsequent reasoning steps, generating further inaccurate outputs and unexpected behaviors. Each hallucination builds upon a prior flawed assessment, demonstrating a cascading "Misunderstanding" of the underlying information or task.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T6 – Intent Breaking &amp;amp; Goal Manipulation&lt;/td&gt; 
        &lt;td&gt;A model's assessment of the user's intended goal is incorrect due to a lack of proper context or malicious prompting designed to mislead it. This "Misunderstanding" of the desired outcome results in the model exhibiting unexpected behaviors that deviate from or actively subvert the user's actual objective.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;&lt;b&gt;L&lt;/b&gt;ack of Accountability&lt;/td&gt; 
        &lt;td&gt;T7 – Misaligned &amp;amp; Deceptive Behaviour&lt;/td&gt; 
        &lt;td&gt;A model's assessment of appropriate action is flawed due to insufficient context regarding ethical guidelines or malicious prompting that manipulates its understanding of desirable behavior. This "Lack of Accountability" leads to unexpected emerging behaviors that are either not aligned with intended values or actively deceptive.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T15 – Human Trust ManipulationS&lt;/td&gt; 
        &lt;td&gt;When a model's output, influenced by insufficient context or malicious prompting, leads a human to form an inaccurate assessment of the model's reliability or the situation it presents. This "Lack of Accountability" of the model's trustworthiness can result in unexpected and potentially harmful human behaviors based on that flawed assessment.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;OWASP justify level of mitigations in the industry justification&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;table&gt; 
      &lt;tbody&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Mitigation Availability&lt;/td&gt; 
        &lt;td&gt;OWASP Threat&lt;/td&gt; 
        &lt;td&gt;Justification&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Existing&lt;/td&gt; 
        &lt;td&gt;T9 – Identity Spoofing&lt;/td&gt; 
        &lt;td&gt;Standard Identity Access Management (IAM) should be used&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T8 - Repudiation and Untraceability&lt;/td&gt; 
        &lt;td&gt;Standard logging methods will suffice.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T12 - Agent Communication Poising&lt;/td&gt; 
        &lt;td&gt;There are established protocols to perform secure communication. If using new protocols they should have similar levels of cryptographic and authentication capabilities.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T4 - Resource Overload&lt;/td&gt; 
        &lt;td&gt;There are robust mechanisms to throttle rate limits on a frequency and payload level. This just needs to be applied to APIs that utilize LLM capabilities.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T3 - Privilege Compromise&lt;/td&gt; 
        &lt;td&gt;This calls out standard least privilege controls with strong authN/authZ systems and only granting the permission that is needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;Expand&lt;/td&gt; 
        &lt;td&gt;T13-Rougue Agents&lt;/td&gt; 
        &lt;td&gt;We have ways to detect if infrastructure has been compromised. Now the activities a rogue agent would perform are more subtle, so these detection mechanisms should be improved.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T11 - Unexpected RCE and Code Attacks&lt;/td&gt; 
        &lt;td&gt;Your infrastructure should already be limited to not execute arbitrary code. There are also some detection mechanisms for detecting and understanding code, but these capabilities will need to get better to comfortably full allow agents to generate and utilize code on the fly.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T1 - Memory Poisoning&lt;/td&gt; 
        &lt;td&gt;The core mitigations are: &lt;br&gt; - Session management to separate users memory and regularly clearing. &lt;br&gt; - This in the expand category as normally memory management is more about performance than security.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T10 - Overwhelming HITL&lt;/td&gt; 
        &lt;td&gt;We do have ways to mitigate DDoS attacks, but these are normally in the context of protecting technology workloads not people. That being said we can adopt some of those principles when routing traffic to people to resolve.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T14 - Human attacks on MAS&lt;/td&gt; 
        &lt;td&gt;Apply a zero-trust mentality between agents. All actions should be fully validated if authorized and appropriate when communication between agents happen. As it might be hard to know what are valid actions we can apply a zero-trust mentality to get part of the way there.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;New&lt;/td&gt; 
        &lt;td&gt;T2 - Tool Misuse&lt;/td&gt; 
        &lt;td&gt;The ecosystem of tools are actively evolving and the industry standards are being established. Things like MCP auto-discovery of tools is a new type of 3rd party risk. In theory an agent could use a new tool without anyone's knowledge. This a level of dynamic 3rd party management the industry has not done before.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T5 - Cascading Hallucionations&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T6 - Intent Breaking &amp;amp; Goal Manipulationg&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T7 - Misaligned &amp;amp; Deceptive Behavior&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
       &lt;tr&gt; 
        &lt;td&gt;T15 - Human Trust Manipulation&lt;/td&gt; 
        &lt;td&gt;It will be hard to validate what is appropriate behavior for the agent as the potential scope output is too large. A new way of output validation and monitoring will be needed.&lt;/td&gt; 
       &lt;/tr&gt; 
      &lt;/tbody&gt; 
     &lt;/table&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;CURATED CONTENT&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Handpicked for you&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Toreon Blog: Mind the Gap: STRIDE-AI&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Threat Modeling as Code: Implementing STRIDE in DevSecOps&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The security landscape is changing rapidly as AI integrates into every part of our lives – from smart assistants and recommendation systems to autonomous vehicles and vision technology. While traditional cybersecurity practices remain essential, AI-enabled systems introduce new types of threats that require a specialized approach. At Toreon, we’ve experienced this firsthand. That’s why we’re excited to launch STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/stride-ai-your-clear-path-to-understanding-ai-vulnerabilities/"&gt;Read the blog&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt; 
         &lt;div&gt; 
          &lt;div&gt; 
           &lt;p&gt;In the DevSecOps era, security is built into the development lifecycle, not bolted on after the fact. While traditional methods can slow delivery, Threat Modeling as Code (TMAC) enables automated, scalable, and continuous security assessments.&lt;/p&gt; 
           &lt;p&gt;This article explores how to implement STRIDE, a Microsoft-developed threat classification framework, within DevSecOps. Learn how to automate threat modeling, integrate it into your CI/CD pipelines, and catch vulnerabilities early, before they reach production.&lt;/p&gt; 
          &lt;/div&gt; 
         &lt;/div&gt; 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://medium.com/@urshilaravindran/threat-modeling-as-code-implementing-stride-in-devsecops-0dd9f9ff06c1"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Threat Modeling Guide for Software Teams&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;div&gt;
          Threat modeling helps teams understand how data moves through systems and spot risks that automated tools often miss. Instead of treating it as a one-time or standalone activity, teams should embed threat modeling into their development workflow through small, ongoing efforts. This article offers practical ways to get started, whether you’re focused on application development, infrastructure, or both. With rising cybersecurity threats and growing accountability, making threat modeling a regular habit is more important than ever. 
        &lt;/div&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://martinfowler.com/articles/agile-threat-modelling.html"&gt;Read More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;TIPS &amp;amp; TRICKS&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Securing HTTP-based APIs&lt;/h3&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;This UK NCSC guidance offers practical advice for securing HTTP-based APIs and is intended for technical teams involved in designing or building applications with API endpoints. Keep in mind that full security depends on performing threat modelling tailored to your specific architecture and use cases.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.ncsc.gov.uk/collection/securing-http-based-apis"&gt;Learn more&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Our Black Hat "Whiteboard Hacking" (hands-on threat modeling) training is going virtual!&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While we’ll miss the in-person experience, this opens up the opportunity for more participants worldwide who might not be able to travel to Las Vegas. &lt;br&gt; Our training stands out due to its hands-on nature, small group work, collaboration, and exercises based on real-world situations.&lt;/p&gt; 
     &lt;p&gt;This year, we’re covering hot topics including:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;AI threat modeling, with exercises related to chatbots&lt;/li&gt; 
      &lt;li&gt;Cloud, including storage and CI/CD pipelines&lt;/li&gt; 
      &lt;li&gt;IoT, embedded devices, and systems&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;a href="https://www.linkedin.com/in/roberthurlbut/"&gt;Robert Hurlbut&lt;/a&gt; will be delivering the training, so we’re looking forward to seeing you there!&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.blackhat.com/us-25/training/schedule/index.html#advanced-whiteboard-hacking---aka-hands-on-threat-modeling-online-44481"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Our trainings &amp;amp; events for 2025&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Book a seat in our upcoming trainings &amp;amp; events&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, virtual, hosted by Black Hat USA, Las Vegas&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;2-5 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 18 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.blackhat.com/us-25/training/schedule/index.html#advanced-whiteboard-hacking---aka-hands-on-threat-modeling-44481"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, virtual, hosted by Black Hat USA, Las Vegas&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;2-5 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.blackhat.com/us-25/training/schedule/index.html#advanced-whiteboard-hacking---aka-hands-on-threat-modeling-44481"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 18 August 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, Blue Team Con, Chicago, USA&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://blueteamcon.com/directory/whiteboard-hacking-aka-hands-on-threat-modeling/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Hands-on Threat Modeling AI, in-person, hosted by BruCON, Belgium&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;22-24 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.brucon.org/training"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Hands-on Threat Modeling AI, in-person, hosted by BruCON, Belgium&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;22-24 September 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.brucon.org/training"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, OWASP Global AppSec, Washington DC&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;4-5 November 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://owasp.glueup.com/event/owasp-2025-global-appsec-usa-washington-dc-131624/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Threat Modeling Practitioner training, hybrid online, hosted by DPI&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;Cohort starting on 1 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.dp-institute.eu/en/courses/threat-modeling-practitioner-training/"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Advanced Whiteboard Hacking a.k.a. Hands-on Threat Modeling, in-person, NDC Security Manchester, UK&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;em&gt;1-2 December 2025&lt;/em&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;a href="https://ndcsecurity.co.uk/workshops/agile-whiteboard-hacking-aka-hands-on-threat-modeling/2174f00ded6a"&gt;Book your spot&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Stay updated with high quality educational material every month.&lt;br&gt; No ads, no spam. Just pure learning.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h3&gt;Join 2000+ companies who learn about threat modeling every month!&lt;/h3&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthreat-modeling-insider-june-2025&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <category>Toreon All</category>
      <pubDate>Wed, 25 Jun 2025 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-insider-june-2025</guid>
      <dc:date>2025-06-25T22:00:00Z</dc:date>
      <dc:creator>Laurent Dupont</dc:creator>
    </item>
    <item>
      <title>Mind the Gap: STRIDE-AI - Your Clear Path to Understanding AI Vulnerabilities</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/stride-ai-your-clear-path-to-understanding-ai-vulnerabilities</link>
      <description>&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Your Clear Path to Understanding AI Vulnerabilities&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The security landscape is changing rapidly as AI integrates into every part of our lives – from smart assistants and recommendation systems to autonomous vehicles and vision technology. While traditional cybersecurity practices remain essential, AI-enabled systems introduce new types of threats that require a specialized approach. At Toreon, we’ve experienced this firsthand. That’s why we’re excited to launch STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Why Traditional STRIDE Isn't Enough for AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The STRIDE threat modeling framework, originally created by Microsoft, has been fundamental to application security for many years. It classifies threats into six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. These categories remain relevant for AI systems. However, how these threats appear in an AI setting is significantly different, requiring a deeper understanding and customized countermeasures. AI systems aren’t just code; they learn, infer, and adapt, making them susceptible to unique attack vectors like data poisoning, adversarial examples, and prompt injection. This is where STRIDE-AI comes in, extending the classic framework to address the complexities of AI-specific risks.&lt;/p&gt; 
     &lt;p&gt;Let’s examine how each STRIDE category applies, using real-world examples to highlight the urgency of this specialized approach.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;STRIDE-AI: A Deep Dive into AI-Specific Threats&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;1. Spoofing: Impersonation in the Age of AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Attackers impersonate users, AI services, or data sources to fool an AI system. Think deepfakes bypassing biometric authentication or forged sensor feeds misleading an autonomous system.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; The infamous case of criminals using AI to clone a CEO’s voice, authorizing fraudulent transactions worth hundreds of thousands of dollars. Another chilling example: a small piece of tape on a speed-limit sign caused Tesla’s image recognition to misread “35” as “85,” leading the car to accelerate dangerously. These are stark illustrations of AI spoofing – forged inputs accepted as genuine.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We emphasize strong authentication and validation. This goes beyond simple passwords, advocating for multi-factor authentication, cross-modal checks (like liveness tests for biometrics), and cryptographic authentication of AI model endpoints and data sources. Deepfake detection and anomaly detection are also crucial.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;2. Tampering: Corrupting AI's Integrity&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Unauthorized alteration of data or models in the AI pipeline. This includes data poisoning (injecting malicious data into training sets), model poisoning/backdooring (altering model weights), or adversarial input attacks (subtly manipulating inputs to cause incorrect outputs).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; In 2016, Microsoft’s Tay Twitter bot was quickly “poisoned” by users feeding it hateful inputs, forcing its shutdown. Similarly, placing tape on a road sign (tampering with the physical input) fooled a Tesla’s vision system. These incidents underscore how even subtle malicious modifications can compromise an AI’s integrity.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We focus on robust data and model integrity controls. This involves securing the entire AI training pipeline with trusted data sources, versioning, and validation (e.g., outlier detection for poisoned data). We also cover robust and adversarial training techniques and protect model files with encryption and digital signatures. Continuous monitoring of model performance is key to detecting tampering.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;3. Repudiation: The Challenge of Accountability in AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; The lack of accountability or traceability in AI operations allows parties to deny actions. This occurs when insufficient logs or audit trails exist for model training, data access, or decision outputs.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; A deepfake audio clip used in a UK court to falsely incriminate someone, forcing the person to repudiate it – a clear demonstration of how AI can complicate accountability. Without proper logging, an autonomous agent making an unauthorized transaction could be easily denied, with “the AI” taking the blame.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We emphasize comprehensive AI audit logs that are tamper-evident, ensuring an immutable record. Digital signatures or watermarks on critical model outputs can prove authenticity, and clear accountability for AI actions is established by associating them with user or process IDs&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;4. Information Disclosure: AI as a Data Leakage Vector&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Unauthorized access or exposure of sensitive data through AI systems (privacy leakage). &lt;strong&gt;Model reverse engineering&lt;/strong&gt;contributes significantly here, enabling attackers to reconstruct sensitive training data or infer confidential insights from an AI model, essentially turning the AI into an&lt;strong&gt;unintentional data leakage vector.&lt;/strong&gt; Attackers can exploit models to extract training data (model inversion, membership inference), or an AI system might inadvertently reveal confidential information in its responses.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; Researchers demonstrated how simple prompts could trick ChatGPT into revealing over 10,000 pieces of verbatim training data, including names, phone numbers, and addresses. Another instance involved attackers using membership inference to determine if a specific user’s data was part of a model’s training set, despite it being private.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We champion privacy-preserving AI techniques like differential privacy during training to reduce memorization. Strict access controls, output filters to redact sensitive data, and secure handling of trained models (treating them as sensitive assets) are also crucial to prevent information leakage.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;5. Denial of Service (DoS): Crippling AI Availability&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Disrupting an AI system or reducing its performance by overwhelming resources or exploiting worst-case behaviors. This can involve flooding an AI service with requests, creating expensive inputs, or even data poisoning aimed at availability.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt;Sending prompts to Large Language Models (LLMs) that trigger extremely large outputs or infinite loops, leading to service slowdowns or crashes. The OWASP Top 10 for LLMs notes that overloading LLMs with resource-intensive tasks can disrupt service and significantly increase costs. For example, a single carefully crafted query to an LLM application has been shown to potentially result in a bill exceeding $1000 due to excessive token generation and processing.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We advocate for robust measures like rate limiting and input throttling on AI service endpoints. Input validation to reject unusually large or complex inputs, performance monitoring, and graceful degradation strategies are key to maintaining availability under attack.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;6. Elevation of Privilege: Gaining Unintended Control via AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Gaining higher privileges or capabilities via the AI system than intended. This can involve exploiting vulnerabilities in AI plugins to execute code on the host, or “jailbreaking” an AI’s safeguards to make it perform restricted actions.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; The “DAN” (Do Anything Now) exploit in ChatGPT, where users crafted prompts to bypass the model’s safety rules and generate disallowed content. Another example is an insecure AI plugin that allows malicious prompts to inject commands for execution on the server, leading to remote code execution (RCE).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We emphasize strict policy enforcement, segmentation, and sandboxing for AI systems. AI agents and plugins should operate with the least privileges possible within isolated environments. Robust input validation and prompt filtering are essential to neutralize malicious patterns and prevent the AI from becoming an attack vector for higher system access.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Beyond STRIDE-AI: A Holistic View&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While STRIDE-AI forms the core of our methodology, we also integrate insights from other crucial frameworks:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;NIST AI Risk Management Framework (AI RMF 1.0)&lt;/strong&gt; provides comprehensive guidance for managing AI system risks throughout their lifecycle.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;MITRE ATLAS (Adversarial Threat Landscape for AI):&lt;/strong&gt; A knowledge base of adversary tactics and techniques specifically targeting AI systems.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;OWASP Machine Learning Security Top 10 (2023) &amp;amp; OWASP Top 10 for LLM Applications (2024):&lt;/strong&gt; Industry-focused checklists outlining common vulnerabilities and attack vectors in ML and LLM systems.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;AI Incident Database (AIID):&lt;/strong&gt; A valuable resource for understanding real-world AI failures and incidents, grounding our threat modeling in practical examples.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;It’s crucial to remember that &lt;strong&gt;AI integration doesn’t negate the need for traditional application security (appsec)&lt;/strong&gt;. Since AI systems are often embedded within larger technological infrastructures, robust conventional security measures remain vital to protect the entire ecosystem.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Strengthen Your AI Security with Toreon's Expertise&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Understanding these AI-specific threats is now essential. As organizations increasingly adopt AI, proactive and specialized security measures become crucial. At Toreon, we’ve created a 3-day AI Threat Modeling Training that provides security and engineering professionals with practical skills and a structured approach to identify, assess, and mitigate threats in AI applications.&lt;/p&gt; 
     &lt;p&gt;Using our enhanced STRIDE-AI methodology, you’ll learn to systematically build robust security into your AI systems from the ground up. The training culminates in an engaging Red Team/Blue Team wargame, allowing you to put your newfound skills to the test in a realistic scenario.&lt;/p&gt; 
     &lt;p&gt;Don’t let AI’s unique risks catch you off guard. Invest in your organization’s security in the future.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to master AI threat modeling?&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/ai-whiteboard-hacking-training/"&gt;Explore our 3-day AI Threat Modeling Training today!&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Seba Deleersnyder is the editor of the Threat Modeling Insider newsletter and a passionate advocate for practical security solutions. With years of experience in the field, he continues to curate insights and build communities that make threat modeling more accessible to everyone.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Connect with Sebastien Deleersnyder&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;img class="blogimage" src="https://staging.toreon.com/hs-fs/hubfs/Imported_Blog_Media/20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg?width=2560&amp;amp;height=1707&amp;amp;name=20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg" alt="Sebastien" width="2560" height="1707"&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Your Clear Path to Understanding AI Vulnerabilities&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The security landscape is changing rapidly as AI integrates into every part of our lives – from smart assistants and recommendation systems to autonomous vehicles and vision technology. While traditional cybersecurity practices remain essential, AI-enabled systems introduce new types of threats that require a specialized approach. At Toreon, we’ve experienced this firsthand. That’s why we’re excited to launch STRIDE-AI, our enhanced methodology for comprehensive AI threat modeling, along with our new 3-day AI threat modeling training.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Why Traditional STRIDE Isn't Enough for AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;The STRIDE threat modeling framework, originally created by Microsoft, has been fundamental to application security for many years. It classifies threats into six categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege. These categories remain relevant for AI systems. However, how these threats appear in an AI setting is significantly different, requiring a deeper understanding and customized countermeasures. AI systems aren’t just code; they learn, infer, and adapt, making them susceptible to unique attack vectors like data poisoning, adversarial examples, and prompt injection. This is where STRIDE-AI comes in, extending the classic framework to address the complexities of AI-specific risks.&lt;/p&gt; 
     &lt;p&gt;Let’s examine how each STRIDE category applies, using real-world examples to highlight the urgency of this specialized approach.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;STRIDE-AI: A Deep Dive into AI-Specific Threats&lt;/h2&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;1. Spoofing: Impersonation in the Age of AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Attackers impersonate users, AI services, or data sources to fool an AI system. Think deepfakes bypassing biometric authentication or forged sensor feeds misleading an autonomous system.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; The infamous case of criminals using AI to clone a CEO’s voice, authorizing fraudulent transactions worth hundreds of thousands of dollars. Another chilling example: a small piece of tape on a speed-limit sign caused Tesla’s image recognition to misread “35” as “85,” leading the car to accelerate dangerously. These are stark illustrations of AI spoofing – forged inputs accepted as genuine.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We emphasize strong authentication and validation. This goes beyond simple passwords, advocating for multi-factor authentication, cross-modal checks (like liveness tests for biometrics), and cryptographic authentication of AI model endpoints and data sources. Deepfake detection and anomaly detection are also crucial.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;2. Tampering: Corrupting AI's Integrity&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Unauthorized alteration of data or models in the AI pipeline. This includes data poisoning (injecting malicious data into training sets), model poisoning/backdooring (altering model weights), or adversarial input attacks (subtly manipulating inputs to cause incorrect outputs).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; In 2016, Microsoft’s Tay Twitter bot was quickly “poisoned” by users feeding it hateful inputs, forcing its shutdown. Similarly, placing tape on a road sign (tampering with the physical input) fooled a Tesla’s vision system. These incidents underscore how even subtle malicious modifications can compromise an AI’s integrity.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We focus on robust data and model integrity controls. This involves securing the entire AI training pipeline with trusted data sources, versioning, and validation (e.g., outlier detection for poisoned data). We also cover robust and adversarial training techniques and protect model files with encryption and digital signatures. Continuous monitoring of model performance is key to detecting tampering.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;3. Repudiation: The Challenge of Accountability in AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; The lack of accountability or traceability in AI operations allows parties to deny actions. This occurs when insufficient logs or audit trails exist for model training, data access, or decision outputs.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; A deepfake audio clip used in a UK court to falsely incriminate someone, forcing the person to repudiate it – a clear demonstration of how AI can complicate accountability. Without proper logging, an autonomous agent making an unauthorized transaction could be easily denied, with “the AI” taking the blame.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We emphasize comprehensive AI audit logs that are tamper-evident, ensuring an immutable record. Digital signatures or watermarks on critical model outputs can prove authenticity, and clear accountability for AI actions is established by associating them with user or process IDs&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;4. Information Disclosure: AI as a Data Leakage Vector&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Unauthorized access or exposure of sensitive data through AI systems (privacy leakage). &lt;strong&gt;Model reverse engineering&lt;/strong&gt;contributes significantly here, enabling attackers to reconstruct sensitive training data or infer confidential insights from an AI model, essentially turning the AI into an&lt;strong&gt;unintentional data leakage vector.&lt;/strong&gt; Attackers can exploit models to extract training data (model inversion, membership inference), or an AI system might inadvertently reveal confidential information in its responses.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; Researchers demonstrated how simple prompts could trick ChatGPT into revealing over 10,000 pieces of verbatim training data, including names, phone numbers, and addresses. Another instance involved attackers using membership inference to determine if a specific user’s data was part of a model’s training set, despite it being private.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We champion privacy-preserving AI techniques like differential privacy during training to reduce memorization. Strict access controls, output filters to redact sensitive data, and secure handling of trained models (treating them as sensitive assets) are also crucial to prevent information leakage.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;5. Denial of Service (DoS): Crippling AI Availability&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Disrupting an AI system or reducing its performance by overwhelming resources or exploiting worst-case behaviors. This can involve flooding an AI service with requests, creating expensive inputs, or even data poisoning aimed at availability.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt;Sending prompts to Large Language Models (LLMs) that trigger extremely large outputs or infinite loops, leading to service slowdowns or crashes. The OWASP Top 10 for LLMs notes that overloading LLMs with resource-intensive tasks can disrupt service and significantly increase costs. For example, a single carefully crafted query to an LLM application has been shown to potentially result in a bill exceeding $1000 due to excessive token generation and processing.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We advocate for robust measures like rate limiting and input throttling on AI service endpoints. Input validation to reject unusually large or complex inputs, performance monitoring, and graceful degradation strategies are key to maintaining availability under attack.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;6. Elevation of Privilege: Gaining Unintended Control via AI&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Manifestation:&lt;/strong&gt; Gaining higher privileges or capabilities via the AI system than intended. This can involve exploiting vulnerabilities in AI plugins to execute code on the host, or “jailbreaking” an AI’s safeguards to make it perform restricted actions.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Real-World Example:&lt;/strong&gt; The “DAN” (Do Anything Now) exploit in ChatGPT, where users crafted prompts to bypass the model’s safety rules and generate disallowed content. Another example is an insecure AI plugin that allows malicious prompts to inject commands for execution on the server, leading to remote code execution (RCE).&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Our Approach:&lt;/strong&gt; We emphasize strict policy enforcement, segmentation, and sandboxing for AI systems. AI agents and plugins should operate with the least privileges possible within isolated environments. Robust input validation and prompt filtering are essential to neutralize malicious patterns and prevent the AI from becoming an attack vector for higher system access.&lt;/li&gt; 
     &lt;/ul&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Beyond STRIDE-AI: A Holistic View&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;While STRIDE-AI forms the core of our methodology, we also integrate insights from other crucial frameworks:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;NIST AI Risk Management Framework (AI RMF 1.0)&lt;/strong&gt; provides comprehensive guidance for managing AI system risks throughout their lifecycle.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;MITRE ATLAS (Adversarial Threat Landscape for AI):&lt;/strong&gt; A knowledge base of adversary tactics and techniques specifically targeting AI systems.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;OWASP Machine Learning Security Top 10 (2023) &amp;amp; OWASP Top 10 for LLM Applications (2024):&lt;/strong&gt; Industry-focused checklists outlining common vulnerabilities and attack vectors in ML and LLM systems.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;AI Incident Database (AIID):&lt;/strong&gt; A valuable resource for understanding real-world AI failures and incidents, grounding our threat modeling in practical examples.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;It’s crucial to remember that &lt;strong&gt;AI integration doesn’t negate the need for traditional application security (appsec)&lt;/strong&gt;. Since AI systems are often embedded within larger technological infrastructures, robust conventional security measures remain vital to protect the entire ecosystem.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Strengthen Your AI Security with Toreon's Expertise&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Understanding these AI-specific threats is now essential. As organizations increasingly adopt AI, proactive and specialized security measures become crucial. At Toreon, we’ve created a 3-day AI Threat Modeling Training that provides security and engineering professionals with practical skills and a structured approach to identify, assess, and mitigate threats in AI applications.&lt;/p&gt; 
     &lt;p&gt;Using our enhanced STRIDE-AI methodology, you’ll learn to systematically build robust security into your AI systems from the ground up. The training culminates in an engaging Red Team/Blue Team wargame, allowing you to put your newfound skills to the test in a realistic scenario.&lt;/p&gt; 
     &lt;p&gt;Don’t let AI’s unique risks catch you off guard. Invest in your organization’s security in the future.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to master AI threat modeling?&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/ai-whiteboard-hacking-training/"&gt;Explore our 3-day AI Threat Modeling Training today!&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Seba Deleersnyder is the editor of the Threat Modeling Insider newsletter and a passionate advocate for practical security solutions. With years of experience in the field, he continues to curate insights and build communities that make threat modeling more accessible to everyone.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Connect with Sebastien Deleersnyder&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;img class="blogimage" src="https://staging.toreon.com/hs-fs/hubfs/Imported_Blog_Media/20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg?width=2560&amp;amp;height=1707&amp;amp;name=20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg" alt="Sebastien" width="2560" height="1707"&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fstride-ai-your-clear-path-to-understanding-ai-vulnerabilities&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Toreon News</category>
      <pubDate>Wed, 25 Jun 2025 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/stride-ai-your-clear-path-to-understanding-ai-vulnerabilities</guid>
      <dc:date>2025-06-25T22:00:00Z</dc:date>
      <dc:creator>Laurent Dupont</dc:creator>
    </item>
    <item>
      <title>Threat Modeling: 5 Strategies to Sell Leadership on Security</title>
      <link>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-5-strategies-to-sell-leadership-on-security</link>
      <description>&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Picture this: your security team catches a major flaw &lt;strong&gt;before&lt;/strong&gt; a product launch, saving $$$ and a PR nightmare. Still, many security leaders struggle with getting upper management to invest in threat modeling. In fact, a 2021 study found that &lt;strong&gt;79% of security pros see threat modeling as a top priority, yet only 25% do it early in development&lt;/strong&gt;. The gap is &lt;strong&gt;frustrating&lt;/strong&gt; – leadership craves secure software but often balks at the upfront time or cost of threat modeling.&lt;/p&gt; 
     &lt;p&gt;Sound familiar? You know threat modeling &lt;em&gt;reduces costly late fixes&lt;/em&gt;, ticks compliance boxes, and ups customer trust – but how do you get the &lt;strong&gt;C-suite&lt;/strong&gt; to see it? Maybe you’ve tried the usual slide decks and scare tactics, only to get lukewarm buy-in. &lt;strong&gt;What’s missing is influence&lt;/strong&gt; – the psychology of persuasion, the art of speaking leadership’s language.&lt;/p&gt; 
     &lt;p&gt;This post lays out &lt;strong&gt;5 battle-tested strategies&lt;/strong&gt; to influence leadership and get them on board with threat modeling. We’ll apply established influence techniques to threat modeling, drawing on a five-step framework for guiding leadership through change.By the end, you’ll have a conversational, no-fluff playbook to &lt;strong&gt;flip the script&lt;/strong&gt; – from pleading for budget to &lt;strong&gt;inspiring&lt;/strong&gt; action. Along the way, look for &lt;strong&gt;clear calls-to-action (CTAs)&lt;/strong&gt; linking to resources like our Threat Modeling Training. Let’s dive in and unlock how to make threat modeling a &lt;em&gt;no-brainer&lt;/em&gt; for upper management.&lt;/p&gt; 
     &lt;p&gt;Ready to jumpstart change? Check out our &lt;strong&gt;Threat Modeling Training&lt;/strong&gt; for actionable workshops and quick wins you can show leadership.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Learn More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;1. Find Your Internal Champions (Identify Influential Leaders)&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Every company has its &lt;strong&gt;movers and shakers&lt;/strong&gt; – not just by title, but by who colleagues listen to. Our first tip: &lt;em&gt;“Identify the influential leadership”&lt;/em&gt;. Start by mapping out formal decision-makers (CIO, CISO, Head of Development), &lt;strong&gt;and&lt;/strong&gt; the informal influencers (that product manager everyone respects, the veteran architect with sway). These allies can become your &lt;strong&gt;internal champions&lt;/strong&gt; for threat modeling.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Why It Works:&lt;/strong&gt; Leadership is more likely to listen when the pitch comes from a trusted peer. If you can get, say, a &lt;strong&gt;DevOps manager&lt;/strong&gt; excited about threat modeling’s efficiency boost, they’ll help sell it upstairs. It’s &lt;em&gt;social proof&lt;/em&gt; in action – people follow the crowd, especially when the “crowd” includes respected voices.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; At one fintech company, a principal developer became &lt;em&gt;the&lt;/em&gt; threat modeling advocate after seeing how it caught design flaws early. When she spoke up about saved development time and &lt;strong&gt;preventing a costly bug fix (640x cheaper to fix early!)&lt;/strong&gt; at the next department sync, leadership took note.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Set up a casual brown-bag session to talk about a recent security win (or scare) and how threat modeling played a role. Invite a mix of roles – QA, Dev, Ops, Compliance. See who leans in with interest or questions. Follow up with them 1:1 to ask if they’d help champion a threat modeling initiative. This relationship-building mirrors “building relationships with those people” – a principle that emphasizes trust before influence.&lt;/p&gt; 
     &lt;p&gt;Want to empower an internal champion fast? Our &lt;strong&gt;Threat Modeling Training&lt;/strong&gt; isn’t just tech skills – we offer leadership-ready talking points to help you and your allies make the case.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Explore our Training Options&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;2. Speak Their Language: Align with Strategic Objectives&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;You might &lt;em&gt;live and breathe&lt;/em&gt; security, but top executives juggle &lt;strong&gt;business goals&lt;/strong&gt;, &lt;strong&gt;market competition&lt;/strong&gt;, and &lt;strong&gt;compliance&lt;/strong&gt; on top of security. To grab their attention, frame threat modeling as a &lt;strong&gt;solution to their problems&lt;/strong&gt;. This aligns with the idea of connecting your approach to broader organizational goals—in our case, &lt;strong&gt;linking threat modeling to the key concerns and priorities that matter most to leadership&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Start with Why:&lt;/strong&gt; Does your CEO obsess over market trust? Talk about how threat modeling prevents the next breach headline, protecting brand reputation. CFO worried about costs? Show data that &lt;strong&gt;fixing a vuln in production costs 30x more&lt;/strong&gt; than fixing it in design – threat modeling is essentially a cost-saver. For compliance-focused leaders (think GDPR, ISO, or the new &lt;a href="https://www.toreon.com/threat-modeling-as-a-strategic-path-to-cra-compliance/"&gt;EU Cyber Resilience Act&lt;/a&gt;), emphasize threat modeling as a &lt;strong&gt;built-in way to meet regulations&lt;/strong&gt; while &lt;strong&gt;simplifying audits&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; A healthcare startup’s CTO was lukewarm on threat modeling until the security lead reframed it: “This isn’t a security tax, it’s how we speed up HIPAA compliance checks &lt;em&gt;and&lt;/em&gt; avoid reworking code later.” By linking threat modeling to avoiding regulatory fines and development churn, the CTO saw it as &lt;strong&gt;efficiency and risk management&lt;/strong&gt;, not a hurdle.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Before your next pitch, list 3 top business objectives in your org (e.g., “Scale to new markets,” “Increase customer trust,” “Cut operational costs by X%”). For each, jot a note on how threat modeling supports it. Even better, gather any existing metrics or case studies: “After adopting threat modeling, Company X saw 15% faster security approvals, contributing to quicker market launches” (hypothetical example, but you get the idea!). Armed with this, your conversation shifts from technical jargon to &lt;strong&gt;business value&lt;/strong&gt; – exactly what leaders want to hear.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;3. Make It Personal: Align with Leaders’ Personal Goals&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Beyond organizational goals, remember that leaders are individuals with personal drivers. It’s important to align change efforts with what matters to them personally. In practice, this means understanding what motivates your executives. Do they want to be seen as champions of innovation? Cost-saving leaders? Culture shapers?&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Find the Hook:&lt;/strong&gt; If a VP is eyeing a promotion, frame threat modeling as their chance to &lt;strong&gt;shine as a forward-thinking leader&lt;/strong&gt; who introduced a practice that saved the company millions (yes, security can be a kingmaker!). If another leader is a &lt;strong&gt;tech enthusiast&lt;/strong&gt;, pitch threat modeling as the “next cool thing” – it’s cutting-edge, it’s what top companies do (nobody wants to be left behind, and “everyone’s doing it” is a psychological nudge via social proof).&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; Consider a CISO who deeply values mentorship and team development. By highlighting that threat modeling training will &lt;strong&gt;empower teams&lt;/strong&gt;, making them less reliant on outside consultants (a common pain point) and more autonomous in decision-making, you appeal to that personal passion for team growth. Suddenly, threat modeling isn’t just a process – it’s part of their leadership legacy in building a stronger team.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Do a bit of homework on your execs. You likely know their professional KPIs, but what anecdotes have you heard in meetings? Did your CEO mention “customer trust” in the last town hall? Does your CIO talk about “sleeping better at night knowing X is handled”? Jot those down. In your proposal or chat, weave those exact phrases in: “I know keeping customer trust is huge for you – threat modeling directly feeds into that by preventing the kind of breach that loses users.” This isn’t flattery; it’s &lt;em&gt;framing&lt;/em&gt; your ask in terms of what they already care about.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;4. Use the Power of Story and Social Proof&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Numbers are great, but &lt;strong&gt;stories&lt;/strong&gt; seal the deal. Psychologically, humans are wired to remember and connect with stories more than spreadsheets. When persuading leadership, come prepared with relatable &lt;strong&gt;anecdotes and social proof&lt;/strong&gt;from peers or industry leaders. This approach draws on a simple truth: influence is stronger when it taps into how people naturally think, feel, and make decisions.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Tell a “What If” Story:&lt;/strong&gt; Paint a picture. What if we hadn’t threat-modeled our new app and missed a flaw? Imagine a &lt;strong&gt;critical vuln found days before launch&lt;/strong&gt;, causing a month delay – and now picture the opposite: a smooth launch because threat modeling &lt;strong&gt;saved the day&lt;/strong&gt;. Or recount a high-profile breach in your industry with a twist: “If only they’d threat modeled the system design, they might have caught that glaring hole.” These narratives create an emotional &lt;em&gt;urgency&lt;/em&gt; beyond the cold facts.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Social Proof Matters:&lt;/strong&gt; Highlight how &lt;strong&gt;industry leaders&lt;/strong&gt; or competitors are already on the threat modeling train. “BigBank Corp just credited threat modeling for cutting security incidents by 40% this year” or “In our sector, companies that do threat modeling have a 20% faster compliance audit pass rate.” If you lack public examples, leverage quotes from respected sources: For instance, the CTO of Toreon emphasized that threat modeling “ensures vulnerabilities are recognized and remediated before they become a problem”. Knowing peers value something makes leadership more inclined to follow suit (nobody wants FOMO in business).&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Craft a short case study or find a relevant one. Even a fictitious but realistic scenario works: “Last year, Team X spent 6 weeks fixing a late-discovered security flaw, costing €100K in dev time. Threat modeling those features upfront would have prevented that – saving time, money, and some grey hairs.” Share this story in an all-hands or a leadership 1:1. Also, look up industry reports or surveys to sprinkle in stats that back your story with evidence.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;5. Lower the Barrier: Start Small and Show Quick Wins&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;One reason leadership hesitates on threat modeling? It &lt;strong&gt;sounds big&lt;/strong&gt; – like an overhaul, expensive tools, training every dev, possibly slowing releases. So, make it &lt;em&gt;small&lt;/em&gt;. Propose a pilot or a time-boxed trial where you can snag a &lt;strong&gt;quick win&lt;/strong&gt;. This tactic is about reducing fear of change by proving it on a manageable scale.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;The Foot-in-the-Door Technique:&lt;/strong&gt; Psychologists note that getting someone to agree to a small step makes them likelier to agree to bigger steps later. So instead of “Let’s implement threat modeling everywhere forever,” try “How about a 2-week spike where one team threat models their next feature, and we see what value comes out?” When leadership sees a tangible result with minimal investment, it’s much easier for them to say, “Okay, let’s do more.”&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;What Does a Quick Win Look Like?&lt;/strong&gt; It could be finding and fixing a significant security issue &lt;strong&gt;before code is written&lt;/strong&gt;, preventing a costly fix later. Or achieving an “all clear” in a security review because threat modeling guided devs to build it right the first time. Or even just a dev team saying, “This actually helped us think deeper; we saved time in code review because we caught stuff earlier.” Those wins, however small, create positive momentum.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; A security architect in a SaaS company convinced leadership to let her run a one-day threat modeling workshop (with pizza – bribery by food works!). One product team identified &lt;strong&gt;3 potential vulnerabilities&lt;/strong&gt; in a planned feature and adjusted design on the spot. It barely impacted their timeline. That story was shared in the next exec meeting, and the CTO’s immediate response: “How do we roll this out more broadly?”&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Identify a friendly team or a low-risk project to pilot threat modeling. Keep it informal and fun, if you can (gamify it, use sticky notes, whatever fits your culture). Document the outcome: what was found, how long it took, and any a-ha moments. Then package that into a one-page “success brief” and deliver it to leadership. It’s hard to argue with real, recent success &lt;strong&gt;inside your own company&lt;/strong&gt;. It shows &lt;em&gt;pragmatism&lt;/em&gt; (you’re not asking for the moon, just incremental improvement) and &lt;em&gt;proof&lt;/em&gt; that threat modeling works for you.&lt;/p&gt; 
     &lt;p&gt;To help you craft that pilot and rack up quick wins, consider our &lt;strong&gt;Threat Modeling Training&lt;/strong&gt; – it’s designed to get teams hands-on experience fast, building confidence and results you can show off.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Get Started&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Adopting threat modeling at scale can feel like pushing a boulder uphill – at first. But with these influence strategies, you’re not shoving alone; you’re enrolling others to help that boulder roll &lt;em&gt;downhill&lt;/em&gt;. Let’s recap the game plan:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Find Allies:&lt;/strong&gt; Don’t go it solo. Tap respected voices to champion threat modeling.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Frame Strategically:&lt;/strong&gt; Map threat modeling to business goals (ROI, compliance, speed) so it’s a solution, not a cost.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Make It Personal:&lt;/strong&gt; Speak to what individual leaders care about – their legacy, their fears, their aspirations.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Use Story &amp;amp; Proof:&lt;/strong&gt; Facts tell, stories sell. Share powerful anecdotes and peer examples to make threat modeling real.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Start Small:&lt;/strong&gt; Diminish the risk in leaders’ eyes by piloting and delivering a quick win, then scale up.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;strong&gt;Overcoming Objections:&lt;/strong&gt; You might still hear, “We don’t have time,” or “Won’t this slow us down?” Remind them that &lt;strong&gt;not&lt;/strong&gt; doing threat modeling means risking far bigger delays and costs later. Show the stat about a prod vuln costing 640x more to fix – that usually raises eyebrows. If budget is a concern, emphasize that threat modeling isn’t about buying pricey tools; it’s about a mindset and practice that saves money. And if they worry about developer time, point out that &lt;strong&gt;integrating security early prevents fire-fighting later&lt;/strong&gt;, freeing teams to innovate.&lt;/p&gt; 
     &lt;p&gt;By now, you’re armed to turn skeptics into supporters. The key is a casual, confident conversation – you’re &lt;strong&gt;on their side&lt;/strong&gt;, helping them win in their roles while making the company safer. Threat modeling isn’t a hard sell when it clicks that it’s really about smarter, smoother business.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to make threat modeling a reality?&lt;/strong&gt; Remember, you don’t have to do it alone. Bring in reinforcements, whether it’s data from this post, peers with success stories, or experts like us. We’ve helped many organizations break through the buy-in barrier.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Take the Next Step:&lt;/strong&gt; If you’re looking for a structured way to get started and &lt;em&gt;impress&lt;/em&gt; your leadership with immediate progress, check out our &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Threat Modeling Training&lt;/a&gt;. It’s designed to equip you (and your team) with the skills embed threat modeling into your culture. Let’s turn that uphill battle into a downhill roll – with you leading the charge!&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Now go forth and influence – you’ve got this, and the benefits (secure, on-time projects; happy auditors; proud leadership) are totally worth it.&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Seba Deleersnyder is the editor of the Threat Modeling Insider newsletter and a passionate advocate for practical security solutions. With years of experience in the field, he continues to curate insights and build communities that make threat modeling more accessible to everyone.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Connect with Sebastien Deleersnyder&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;img class="blogimage" src="https://staging.toreon.com/hs-fs/hubfs/Imported_Blog_Media/20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg?width=2560&amp;amp;height=1707&amp;amp;name=20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg" alt="Sebastien" width="2560" height="1707"&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Picture this: your security team catches a major flaw &lt;strong&gt;before&lt;/strong&gt; a product launch, saving $$$ and a PR nightmare. Still, many security leaders struggle with getting upper management to invest in threat modeling. In fact, a 2021 study found that &lt;strong&gt;79% of security pros see threat modeling as a top priority, yet only 25% do it early in development&lt;/strong&gt;. The gap is &lt;strong&gt;frustrating&lt;/strong&gt; – leadership craves secure software but often balks at the upfront time or cost of threat modeling.&lt;/p&gt; 
     &lt;p&gt;Sound familiar? You know threat modeling &lt;em&gt;reduces costly late fixes&lt;/em&gt;, ticks compliance boxes, and ups customer trust – but how do you get the &lt;strong&gt;C-suite&lt;/strong&gt; to see it? Maybe you’ve tried the usual slide decks and scare tactics, only to get lukewarm buy-in. &lt;strong&gt;What’s missing is influence&lt;/strong&gt; – the psychology of persuasion, the art of speaking leadership’s language.&lt;/p&gt; 
     &lt;p&gt;This post lays out &lt;strong&gt;5 battle-tested strategies&lt;/strong&gt; to influence leadership and get them on board with threat modeling. We’ll apply established influence techniques to threat modeling, drawing on a five-step framework for guiding leadership through change.By the end, you’ll have a conversational, no-fluff playbook to &lt;strong&gt;flip the script&lt;/strong&gt; – from pleading for budget to &lt;strong&gt;inspiring&lt;/strong&gt; action. Along the way, look for &lt;strong&gt;clear calls-to-action (CTAs)&lt;/strong&gt; linking to resources like our Threat Modeling Training. Let’s dive in and unlock how to make threat modeling a &lt;em&gt;no-brainer&lt;/em&gt; for upper management.&lt;/p&gt; 
     &lt;p&gt;Ready to jumpstart change? Check out our &lt;strong&gt;Threat Modeling Training&lt;/strong&gt; for actionable workshops and quick wins you can show leadership.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Learn More&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;1. Find Your Internal Champions (Identify Influential Leaders)&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Every company has its &lt;strong&gt;movers and shakers&lt;/strong&gt; – not just by title, but by who colleagues listen to. Our first tip: &lt;em&gt;“Identify the influential leadership”&lt;/em&gt;. Start by mapping out formal decision-makers (CIO, CISO, Head of Development), &lt;strong&gt;and&lt;/strong&gt; the informal influencers (that product manager everyone respects, the veteran architect with sway). These allies can become your &lt;strong&gt;internal champions&lt;/strong&gt; for threat modeling.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Why It Works:&lt;/strong&gt; Leadership is more likely to listen when the pitch comes from a trusted peer. If you can get, say, a &lt;strong&gt;DevOps manager&lt;/strong&gt; excited about threat modeling’s efficiency boost, they’ll help sell it upstairs. It’s &lt;em&gt;social proof&lt;/em&gt; in action – people follow the crowd, especially when the “crowd” includes respected voices.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; At one fintech company, a principal developer became &lt;em&gt;the&lt;/em&gt; threat modeling advocate after seeing how it caught design flaws early. When she spoke up about saved development time and &lt;strong&gt;preventing a costly bug fix (640x cheaper to fix early!)&lt;/strong&gt; at the next department sync, leadership took note.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Set up a casual brown-bag session to talk about a recent security win (or scare) and how threat modeling played a role. Invite a mix of roles – QA, Dev, Ops, Compliance. See who leans in with interest or questions. Follow up with them 1:1 to ask if they’d help champion a threat modeling initiative. This relationship-building mirrors “building relationships with those people” – a principle that emphasizes trust before influence.&lt;/p&gt; 
     &lt;p&gt;Want to empower an internal champion fast? Our &lt;strong&gt;Threat Modeling Training&lt;/strong&gt; isn’t just tech skills – we offer leadership-ready talking points to help you and your allies make the case.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Explore our Training Options&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;2. Speak Their Language: Align with Strategic Objectives&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;You might &lt;em&gt;live and breathe&lt;/em&gt; security, but top executives juggle &lt;strong&gt;business goals&lt;/strong&gt;, &lt;strong&gt;market competition&lt;/strong&gt;, and &lt;strong&gt;compliance&lt;/strong&gt; on top of security. To grab their attention, frame threat modeling as a &lt;strong&gt;solution to their problems&lt;/strong&gt;. This aligns with the idea of connecting your approach to broader organizational goals—in our case, &lt;strong&gt;linking threat modeling to the key concerns and priorities that matter most to leadership&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Start with Why:&lt;/strong&gt; Does your CEO obsess over market trust? Talk about how threat modeling prevents the next breach headline, protecting brand reputation. CFO worried about costs? Show data that &lt;strong&gt;fixing a vuln in production costs 30x more&lt;/strong&gt; than fixing it in design – threat modeling is essentially a cost-saver. For compliance-focused leaders (think GDPR, ISO, or the new &lt;a href="https://www.toreon.com/threat-modeling-as-a-strategic-path-to-cra-compliance/"&gt;EU Cyber Resilience Act&lt;/a&gt;), emphasize threat modeling as a &lt;strong&gt;built-in way to meet regulations&lt;/strong&gt; while &lt;strong&gt;simplifying audits&lt;/strong&gt;.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; A healthcare startup’s CTO was lukewarm on threat modeling until the security lead reframed it: “This isn’t a security tax, it’s how we speed up HIPAA compliance checks &lt;em&gt;and&lt;/em&gt; avoid reworking code later.” By linking threat modeling to avoiding regulatory fines and development churn, the CTO saw it as &lt;strong&gt;efficiency and risk management&lt;/strong&gt;, not a hurdle.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Before your next pitch, list 3 top business objectives in your org (e.g., “Scale to new markets,” “Increase customer trust,” “Cut operational costs by X%”). For each, jot a note on how threat modeling supports it. Even better, gather any existing metrics or case studies: “After adopting threat modeling, Company X saw 15% faster security approvals, contributing to quicker market launches” (hypothetical example, but you get the idea!). Armed with this, your conversation shifts from technical jargon to &lt;strong&gt;business value&lt;/strong&gt; – exactly what leaders want to hear.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;3. Make It Personal: Align with Leaders’ Personal Goals&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Beyond organizational goals, remember that leaders are individuals with personal drivers. It’s important to align change efforts with what matters to them personally. In practice, this means understanding what motivates your executives. Do they want to be seen as champions of innovation? Cost-saving leaders? Culture shapers?&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Find the Hook:&lt;/strong&gt; If a VP is eyeing a promotion, frame threat modeling as their chance to &lt;strong&gt;shine as a forward-thinking leader&lt;/strong&gt; who introduced a practice that saved the company millions (yes, security can be a kingmaker!). If another leader is a &lt;strong&gt;tech enthusiast&lt;/strong&gt;, pitch threat modeling as the “next cool thing” – it’s cutting-edge, it’s what top companies do (nobody wants to be left behind, and “everyone’s doing it” is a psychological nudge via social proof).&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; Consider a CISO who deeply values mentorship and team development. By highlighting that threat modeling training will &lt;strong&gt;empower teams&lt;/strong&gt;, making them less reliant on outside consultants (a common pain point) and more autonomous in decision-making, you appeal to that personal passion for team growth. Suddenly, threat modeling isn’t just a process – it’s part of their leadership legacy in building a stronger team.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Do a bit of homework on your execs. You likely know their professional KPIs, but what anecdotes have you heard in meetings? Did your CEO mention “customer trust” in the last town hall? Does your CIO talk about “sleeping better at night knowing X is handled”? Jot those down. In your proposal or chat, weave those exact phrases in: “I know keeping customer trust is huge for you – threat modeling directly feeds into that by preventing the kind of breach that loses users.” This isn’t flattery; it’s &lt;em&gt;framing&lt;/em&gt; your ask in terms of what they already care about.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;4. Use the Power of Story and Social Proof&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Numbers are great, but &lt;strong&gt;stories&lt;/strong&gt; seal the deal. Psychologically, humans are wired to remember and connect with stories more than spreadsheets. When persuading leadership, come prepared with relatable &lt;strong&gt;anecdotes and social proof&lt;/strong&gt;from peers or industry leaders. This approach draws on a simple truth: influence is stronger when it taps into how people naturally think, feel, and make decisions.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Tell a “What If” Story:&lt;/strong&gt; Paint a picture. What if we hadn’t threat-modeled our new app and missed a flaw? Imagine a &lt;strong&gt;critical vuln found days before launch&lt;/strong&gt;, causing a month delay – and now picture the opposite: a smooth launch because threat modeling &lt;strong&gt;saved the day&lt;/strong&gt;. Or recount a high-profile breach in your industry with a twist: “If only they’d threat modeled the system design, they might have caught that glaring hole.” These narratives create an emotional &lt;em&gt;urgency&lt;/em&gt; beyond the cold facts.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Social Proof Matters:&lt;/strong&gt; Highlight how &lt;strong&gt;industry leaders&lt;/strong&gt; or competitors are already on the threat modeling train. “BigBank Corp just credited threat modeling for cutting security incidents by 40% this year” or “In our sector, companies that do threat modeling have a 20% faster compliance audit pass rate.” If you lack public examples, leverage quotes from respected sources: For instance, the CTO of Toreon emphasized that threat modeling “ensures vulnerabilities are recognized and remediated before they become a problem”. Knowing peers value something makes leadership more inclined to follow suit (nobody wants FOMO in business).&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Craft a short case study or find a relevant one. Even a fictitious but realistic scenario works: “Last year, Team X spent 6 weeks fixing a late-discovered security flaw, costing €100K in dev time. Threat modeling those features upfront would have prevented that – saving time, money, and some grey hairs.” Share this story in an all-hands or a leadership 1:1. Also, look up industry reports or surveys to sprinkle in stats that back your story with evidence.&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;5. Lower the Barrier: Start Small and Show Quick Wins&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;One reason leadership hesitates on threat modeling? It &lt;strong&gt;sounds big&lt;/strong&gt; – like an overhaul, expensive tools, training every dev, possibly slowing releases. So, make it &lt;em&gt;small&lt;/em&gt;. Propose a pilot or a time-boxed trial where you can snag a &lt;strong&gt;quick win&lt;/strong&gt;. This tactic is about reducing fear of change by proving it on a manageable scale.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;The Foot-in-the-Door Technique:&lt;/strong&gt; Psychologists note that getting someone to agree to a small step makes them likelier to agree to bigger steps later. So instead of “Let’s implement threat modeling everywhere forever,” try “How about a 2-week spike where one team threat models their next feature, and we see what value comes out?” When leadership sees a tangible result with minimal investment, it’s much easier for them to say, “Okay, let’s do more.”&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;What Does a Quick Win Look Like?&lt;/strong&gt; It could be finding and fixing a significant security issue &lt;strong&gt;before code is written&lt;/strong&gt;, preventing a costly fix later. Or achieving an “all clear” in a security review because threat modeling guided devs to build it right the first time. Or even just a dev team saying, “This actually helped us think deeper; we saved time in code review because we caught stuff earlier.” Those wins, however small, create positive momentum.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Example:&lt;/strong&gt; A security architect in a SaaS company convinced leadership to let her run a one-day threat modeling workshop (with pizza – bribery by food works!). One product team identified &lt;strong&gt;3 potential vulnerabilities&lt;/strong&gt; in a planned feature and adjusted design on the spot. It barely impacted their timeline. That story was shared in the next exec meeting, and the CTO’s immediate response: “How do we roll this out more broadly?”&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Actionable Tip:&lt;/strong&gt; Identify a friendly team or a low-risk project to pilot threat modeling. Keep it informal and fun, if you can (gamify it, use sticky notes, whatever fits your culture). Document the outcome: what was found, how long it took, and any a-ha moments. Then package that into a one-page “success brief” and deliver it to leadership. It’s hard to argue with real, recent success &lt;strong&gt;inside your own company&lt;/strong&gt;. It shows &lt;em&gt;pragmatism&lt;/em&gt; (you’re not asking for the moon, just incremental improvement) and &lt;em&gt;proof&lt;/em&gt; that threat modeling works for you.&lt;/p&gt; 
     &lt;p&gt;To help you craft that pilot and rack up quick wins, consider our &lt;strong&gt;Threat Modeling Training&lt;/strong&gt; – it’s designed to get teams hands-on experience fast, building confidence and results you can show off.&lt;/p&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Get Started&lt;/a&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;h2&gt;Conclusion&lt;/h2&gt; 
    &lt;/div&gt; 
    &lt;div&gt; 
     &lt;p&gt;Adopting threat modeling at scale can feel like pushing a boulder uphill – at first. But with these influence strategies, you’re not shoving alone; you’re enrolling others to help that boulder roll &lt;em&gt;downhill&lt;/em&gt;. Let’s recap the game plan:&lt;/p&gt; 
     &lt;ul&gt; 
      &lt;li&gt;&lt;strong&gt;Find Allies:&lt;/strong&gt; Don’t go it solo. Tap respected voices to champion threat modeling.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Frame Strategically:&lt;/strong&gt; Map threat modeling to business goals (ROI, compliance, speed) so it’s a solution, not a cost.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Make It Personal:&lt;/strong&gt; Speak to what individual leaders care about – their legacy, their fears, their aspirations.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Use Story &amp;amp; Proof:&lt;/strong&gt; Facts tell, stories sell. Share powerful anecdotes and peer examples to make threat modeling real.&lt;/li&gt; 
      &lt;li&gt;&lt;strong&gt;Start Small:&lt;/strong&gt; Diminish the risk in leaders’ eyes by piloting and delivering a quick win, then scale up.&lt;/li&gt; 
     &lt;/ul&gt; 
     &lt;p&gt;&lt;strong&gt;Overcoming Objections:&lt;/strong&gt; You might still hear, “We don’t have time,” or “Won’t this slow us down?” Remind them that &lt;strong&gt;not&lt;/strong&gt; doing threat modeling means risking far bigger delays and costs later. Show the stat about a prod vuln costing 640x more to fix – that usually raises eyebrows. If budget is a concern, emphasize that threat modeling isn’t about buying pricey tools; it’s about a mindset and practice that saves money. And if they worry about developer time, point out that &lt;strong&gt;integrating security early prevents fire-fighting later&lt;/strong&gt;, freeing teams to innovate.&lt;/p&gt; 
     &lt;p&gt;By now, you’re armed to turn skeptics into supporters. The key is a casual, confident conversation – you’re &lt;strong&gt;on their side&lt;/strong&gt;, helping them win in their roles while making the company safer. Threat modeling isn’t a hard sell when it clicks that it’s really about smarter, smoother business.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Ready to make threat modeling a reality?&lt;/strong&gt; Remember, you don’t have to do it alone. Bring in reinforcements, whether it’s data from this post, peers with success stories, or experts like us. We’ve helped many organizations break through the buy-in barrier.&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Take the Next Step:&lt;/strong&gt; If you’re looking for a structured way to get started and &lt;em&gt;impress&lt;/em&gt; your leadership with immediate progress, check out our &lt;a href="https://www.toreon.com/threat-modeling-training/"&gt;Threat Modeling Training&lt;/a&gt;. It’s designed to equip you (and your team) with the skills embed threat modeling into your culture. Let’s turn that uphill battle into a downhill roll – with you leading the charge!&lt;/p&gt; 
     &lt;p&gt;&lt;strong&gt;Now go forth and influence – you’ve got this, and the benefits (secure, on-time projects; happy auditors; proud leadership) are totally worth it.&lt;/strong&gt;&lt;/p&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
 &lt;div&gt; 
  &lt;div&gt; 
   &lt;div&gt; 
    &lt;div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;h2&gt;About the Author&lt;/h2&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;p&gt;Seba Deleersnyder is the editor of the Threat Modeling Insider newsletter and a passionate advocate for practical security solutions. With years of experience in the field, he continues to curate insights and build communities that make threat modeling more accessible to everyone.&lt;/p&gt; 
       &lt;/div&gt; 
       &lt;div&gt; 
        &lt;a href="https://www.linkedin.com/in/sebadele/"&gt;Connect with Sebastien Deleersnyder&lt;/a&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
     &lt;div&gt; 
      &lt;div&gt; 
       &lt;div&gt; 
        &lt;img class="blogimage" src="https://staging.toreon.com/hs-fs/hubfs/Imported_Blog_Media/20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg?width=2560&amp;amp;height=1707&amp;amp;name=20241019-10-jaar-Toreon-c-Martin-Corlazzoli-COR02817-scaled-3.jpg" alt="Sebastien" width="2560" height="1707"&gt; 
       &lt;/div&gt; 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;img src="https://track-eu1.hubspot.com/__ptq.gif?a=139581338&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fstaging.toreon.com%2Fen%2Finsights%2Fthreat-modeling-insider%2Fthreat-modeling-5-strategies-to-sell-leadership-on-security&amp;amp;bu=https%253A%252F%252Fstaging.toreon.com%252Fen%252Finsights%252Fthreat-modeling-insider&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Threat Modeling</category>
      <category>Application Security coaching</category>
      <category>Toreon News</category>
      <pubDate>Thu, 08 May 2025 22:00:00 GMT</pubDate>
      <guid>https://staging.toreon.com/en/insights/threat-modeling-insider/threat-modeling-5-strategies-to-sell-leadership-on-security</guid>
      <dc:date>2025-05-08T22:00:00Z</dc:date>
      <dc:creator>Laurent Dupont</dc:creator>
    </item>
  </channel>
</rss>
