

Developing a Threat Modeling Mindset: A Threat Modeling 101 Workshop
This workshop is part of the training for our 2025 Hackathon participants, but we're opening it up to all TMC members! You don’t need to be a hackathon participant to join.
Threat modeling is a way of thinking about what can go wrong and how to prevent it.
Instinctively, we all think this way in regard to our own personal security and safety. When it comes to building or evaluating information systems, we need to develop a similar mindset.
In this workshop, you'll learn practical strategies to develop a Threat Modeling Mindset by: understanding a system, identifying threats and vulnerabilities, determining mitigations, and applying the mitigations through risk management.
Speaker: Robert Hurlbut
Agenda:
What is threat modeling?
Let's walk through the threat modeling process
Step 0 - Assemble the teams
Step 1 - Understand the system *exercise #1
Step 2 - Identify threats *exercise #2
Step 3 - Document threats *exercise #3
Step 4 - Review and follow-up
Wrap-up / Q&A