#threatmodelling
That’s the correct statement of the rule, and the admission of breach, together with a justification through peer conduct. Social proof, in a log file, from a system with no social life.

Have a great week building your AI agents instructions! 💪🧑‍💻👩‍💻😉👍
#AI #agentic #threatmodeling #threatmodelling
September 27, 2026 at 11:20 AM
Burned out development teams and people sleeping during threat modeling sessions.
The realities of doing security is not that pink as we want to portray it, and our tools and processes not that smooth.

#cornucopia #security #awarness #games #threatmodeling #threatmodelling #appsec
OWASP Cornucopia - Gamifying AI Threat Modeling and Security Requirement Analysis
Shift-left doesn't start with scanning the code for security vulnerabilities; it begins with designing for security. Too often, the shif...
media.ccc.de
September 26, 2026 at 8:45 AM
Threat modelling take that annoys people:
Most "threat models" are a diagram nobody updates and a STRIDE table generated to pass an audit.

The useful version is one engineer asking "what happens if this input is hostile" at every trust boundary.

#AppSec #threatmodelling #Infosec
July 6, 2026 at 9:08 PM
Learn how the STRIDE framework helps identify and mitigate security risks in software systems.

watch now: youtu.be/Wdbw2mQCSpE?...

#STRIDEframework #Denialofservice #framework #threatmodelling #cyberthreats #cybersecurity
What is STRIDE ? Understanding The Framework For Threat Modeling
YouTube video by ReconBee
youtu.be
May 7, 2026 at 7:04 AM
LINDDUN is a powerful framework designed to protect your privacy in a digital world.

watch now: youtu.be/kBWga9f5ev8?...

#LINDDUN #threatmodellingframework #threatmodelling #digitalworld #cybersecurity #cyberattack
LINDDUN Framework Explained: A Simple Guide to Privacy Threat Modeling
YouTube video by ReconBee
youtu.be
April 14, 2026 at 12:30 PM
Another day, another threat model. Credit card company wants to know what they should be on the lookout for by way of discovery, lateral movement and c2 and exfiltration from their micro-segmentation solution as easy wins..

#threatmodelling
February 2, 2026 at 7:21 PM
In this video, we explain how LINDDUN works, its privacy threat categories, and how it helps organizations safeguard sensitive data and comply with regulations.

watch now: youtu.be/kBWga9f5ev8?...

#LINDDUN #LINDDUNframework #framework #cybersecurity #threatmodelling
LINDDUN Framework Explained: A Simple Guide to Privacy Threat Modeling
YouTube video by ReconBee
youtu.be
January 29, 2026 at 1:41 PM
Occasionally, I get to do interesting, impactful things. Here's where I built a service and took it GA at Cisco-scale:

https://blogs.cisco.com/customerexperience/cisco-launches-global-threat-modeling-security-assessment-service-for-threat-informed-defense

#threatmodelling
Cisco Launches Global Threat Modeling Security Assessment Service for Threat-Informed Defense
In an era of increasingly sophisticated cyber-attacks, organizations are under pressure to align their security postures with real-world adversary behavior. To meet this growing demand, Cisco has launched a globally available Threat Modeling Security Assessment service, delivered through Customer Experience’s professional services arm. Designed for security-conscious customers seeking a more structured and threat-informed approach to cyber security, the service offers a practical way to understand, priorities, and defend against the threats that matter most to them. ## Threat Modeling, Reimagined for the Real World Cisco’s service is grounded in industry-accepted threat-centric frameworks, including STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege) and MITRE ATT&CK’s TTPs (Tactics, Techniques and Procedures), giving customers a structured and evidence-based lens through which to assess risk. Originally built to support threat-led penetration testing frameworks such as the UK’s CBEST program which takes a threat-led approach to financial resiliency, the service has matured into a comprehensive approach that enables organizations and their security teams to map adversary behavior directly to the systems that impact confidentiality, integrity and availability and which in turn, have the biggest impact on revenue generation and cost management. Whether you are operating critical telecoms infrastructure, managing banking and other financial data, or running transport and industrial services, the assessment identifies how threat actors would target those assets – so you can plan accordingly. **How Threat-Informed Frameworks Are Affecting Critical Sectors Today** ## Threat-Led, Data-Driven, and Expert-Informed One of the core differentiators of Cisco’s offering is how it analyses the threat landscape through both geographic and industry-specific lenses, powered by the MITRE ATT&CK framework. This ensures assessments are relevant, rather than theoretical, considering the common threats seen across similar types of organization and regions. The service also includes custom analytics to predict each asset’s “place in the kill chain”. This analysis is based on a combination of factors including: * The asset’s location within your network * The type of technology and its configuration * Known vulnerabilities (CVE, KEV etc.) and other weaknesses that have historically affected the asset * How the asset is used and administered in your organization By understanding where an asset sits in an attacker’s kill chain and what it protects, processes or stores, organizations can better prioritize defenses and anticipate likely attack paths. ## Consider How the Global Threat Landscape Can Affect Your Organization Perhaps most importantly, customers get access to Cisco experts with deep experience in ATT&CK’s TTPs and vulnerability research. This expertise ensures that the analysis is not only comprehensive but also operationally realistic, supporting meaningful and defensible security decisions. ## From Theory to Practice: Real-World Use Cases Threat modeling is not just an academic exercise – it is a foundational capability that every organization should be using, to inform the decisions they make so as better prepare for the threat landscape they inhabit. Cisco’s Threat Modeling Security Assessment helps organizations turn intelligence into action. Common use cases include: * Defining Threat Intelligence requirements for a service provider: Instead of drowning in data, organizations can define specific intelligence priorities based on adversaries most likely to target their organization. * Enabling defensive practices for a bank: By understanding which techniques adversaries use to exploit software flaws, development and engineering teams can build with specific attack paths in mind – bringing security to the start of the project lifecycle. * Aligning Architectural Reviews to control needs for a retailer: Security architecture reviews are often generic. With threat modeling, reviews become contextual, aligned to the tactics, techniques, and procedures (TTPs) that are most relevant. * Improving Detection Engineering for an airport: By mapping threats to assets and identifying attack paths, detection engineers can create more targeted and effective rules and playbooks. This service acts as a bridging function. Taking abstract vertical-specific components that your organization relies upon and translating them into software and hardware artifacts and associated data that threat actors might seek to target. ## Designed for Resilience, Driven by Organizational Requirements Cisco’s Threat Modeling Security Assessment is more than a technical exercise – it is a strategic capability for organizations that want to align cyber security efforts with organizational objectives and operational resilience needs. Whether you are regulated, security-mature, or just beginning to formalize your threat-informed defense, this service provides the insight and structure to make every part of your security program more effective. In today’s threat landscape, resilience depends on understanding how your adversaries operate as well as understanding your own environment. Cisco’s new service offers that clarity – reducing the gap between intelligence, architecture, and operations. For organizations serious about defending what matters most, Cisco’s Threat Modeling Security Assessment is a powerful step towards a more threat-informed future.
blogs.cisco.com
January 14, 2026 at 10:44 PM
baby's first (and second and third) potatosecurity webinar #threatmodelling www.youtube.com/playlist?lis...
January 12, 2026 at 8:24 AM
baby's first (and second and third) cybersecurity webinar #threatmodelling www.youtube.com/playlist?lis...
CRAcademy - YouTube
www.youtube.com
January 12, 2026 at 8:15 AM
In this video, we explain how LINDDUN works, its privacy threat categories, and how it helps organizations safeguard sensitive data and comply with regulations.

watch now: youtu.be/kBWga9f5ev8?...

#linddun #lindunnframework #Framework #threatmodelling #cybersecurity
LINDDUN Framework Explained: A Simple Guide to Privacy Threat Modeling
YouTube video by ReconBee
youtu.be
December 11, 2025 at 2:45 PM
#Threatmodelling is identifying and analysing potential security threats and vulnerabilities in a system, application, or network.

To mitigate potential security risks with a balanced budget, security threat modelling is critical.
Use the (free) SAST for #Python nocomplexity.com/codeaudit/

#owasp
November 25, 2025 at 5:44 PM
In this article, we will explore the STRIDE methodology, going through each component and its advantages

read more: reconbee.com/stride-threa...

#STRIDE #stridemethodology #strideframework #threatmodelling #framework #CyberSecurity
STRIDE Threat Modeling Framework - A Complete Guide
the STRIDE Threat Modeling Framework - A Complete Guide provides a robust, systematic approach for identifying, analyzing, and addressing
reconbee.com
November 14, 2025 at 11:53 AM
Bruce Schneier has a few words about Digital Threat Modeling Under Authoritarianism.

https://www.schneier.com/blog/archives/2025/09/digital-threat-modeling-under-authoritarianism.html

#threatmodelling #uspol
www.schneier.com
September 27, 2025 at 4:14 AM
QA folks: you already have the tools to shine in Threat Modelling.
Giancarlo’s workshop will help you connect quality & security where it matters most.

Real cases. Real outcomes. Real fun. 🛡️
tinyurl.com/bdh2uh5a ◀️

#QA #ThreatModelling #AgileTestingDays
July 7, 2025 at 5:53 PM
Running threat-crank to update https://github.com/timb-machine/attack-ti with v16 and v17 data.

#threatmodelling
GitHub - timb-machine/attack-ti: Vertical and geographic extracts from MITRE ATT&CK
Vertical and geographic extracts from MITRE ATT&CK; - timb-machine/attack-ti
github.com
April 23, 2025 at 8:04 PM
Car thought: Isn't AD a browse up architecture? Also, does the team even make real sense given that both the client and server can be both victim and attacker in most scenarios...

#threatmodelling
March 14, 2025 at 11:33 AM
A threat model that includes only PROTECT (apply a secure SDLC, patch regularly, harden etc) is incomplete. More needs to be done by way of DETECT, RESPOND and RECOVER functionality because bugs are going to bug, password2025 is still a thing etc.

#threatmodelling
January 15, 2025 at 4:31 PM
Tony Blair calls for roll out of digital ID | “…put all your eggs in one basket, it makes it easier to lose them all and for the government to surveil you…”
https://alecmuffett.com/article/110762
#IdCards #ThreatModelling #TonyBlair
Tony Blair calls for roll out of digital ID | “…put all your eggs in one basket, it makes it easier to lose them all and for the government to surveil you…”
Imagine that all your health information was in one place: easy, with your permission, for anyone anywhere in the health service to see. That your passport, driving licence, anything you need to pr…
alecmuffett.com
December 16, 2024 at 8:10 AM
Today's awkward question: "So that key management server is for the mainframe backups, where is *it* backed up?", "Well..."

#threatmodelling, #ransomwareondemand
December 12, 2024 at 2:11 PM