Practical threat modeling workshop

STRIDE gremlins
STRIDE gremlins: six friendly creatures you'll learn to keep in check.

Threat modeling transforms vague security worries into a concrete, risk-prioritized backlog. If you're building software products and security mostly feels like checklists and friction, this workshop is for you.

Why threat modeling beats security checklists

Does your development team align well with security? Or is security just slowing you down with checklists and documentation? And after all that, things still don't feel under control?

Threat modeling connects security threats to business impact and engineering priorities. Instead of monotonous checklists, you get clear, well-scoped, and prioritized backlogs.

When you introduce threat modeling into your development cycle, you start designing for security early on, not at the project finish line.

What you'll learn

  • Use the STRIDE technique and data-flow diagrams (DFDs) to walk through and prioritize your threats one by one.
  • Focus on high-impact threats and spend less effort on lower-risk ones—in a way that still keeps auditors happy.
  • Apply threat modeling to existing products, from simple gap analysis to reusable security patterns and solutions.

Who this workshop is for

  • Developers and engineers who own services in production
  • Security champions embedded in product teams
  • Architects and tech leads responsible for system design

Lecturers

Michal Svoboda: 25+ years in cybersecurity—from engineer to leader; helping beginners in the security industry and product security mentor for individuals and teams.

Hung Ngo: involved in automotive cybersec; organizer of BSides Prague, product security community ambassador and cybersecurity lecturer.

Bring this workshop to your team

Want to run this workshop in-house or adapt it to your product and stack? Ready to grow a full SSDLC rooted in threat modeling? Get in touch.