World Congress 2026 North America
Practical Threat Modeling for Software Developers
Mudassir Syed
Lead Security Software Engineer
World Congress 2026 North America
World Congress 2026 North America
September 23–25, 2026 · San José, CA
Attend in person
Get ticketsWatch remotely
Pro
Can’t make it to San José? Watch this session live with Pro. You also get:
Threat modeling was created for a time when the intended design closely matched what shipped. That is no longer true. Most teams still model what they plan to build, including user flows, design decisions, and evil user stories, but they rarely re-evaluate the model against what is actually deployed. Pipelines continuously uncover real risks through SAST, SCA, DAST, IaC scans, and cloud configuration checks, yet those signals are not fed back into the threat model. This creates a growing blind spot where decisions are based on assumptions instead of production truth.
This session shows how to extend threat modeling beyond design and incorporate evidence from the built system. You will learn how to treat discovered vulnerabilities as inputs that evolve the model and how to update the model continuously without waiting for new platforms. The approach is practical and can be adopted with tools most teams already have.
World Congress 2026 North America
Mudassir Syed
Lead Security Software Engineer
World Congress 2026 North America
Saloni Garg
Senior ML Engineer at Adobe
World Congress 2026 North America
Desmond Lamptey
Lead Software Engineer @ Capital One
World Congress 2026 North America
Alex Olivier
Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair