> Markdown version of [/videos/100396-your-threat-model-is-lying-to-you-why-modeling-the-design-isn-t-enough-in-2026](https://www.wearedevelopers.com/videos/100396-your-threat-model-is-lying-to-you-why-modeling-the-design-isn-t-enough-in-2026). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026 Your fifteen declared dependencies just ballooned into hundreds of hidden vulnerabilities. Discover why design-phase threat modeling fails today and how continuous feedback loops expose your true production risks. - **Speakers:** [Farshad Abasi](https://www.wearedevelopers.com/@farshad-abasi) - **Event:** World Congress 2026 North America - **Published:** September 25, 2026 - **Duration:** 30:06 - **URL:** https://www.wearedevelopers.com/videos/100396-your-threat-model-is-lying-to-you-why-modeling-the-design-isn-t-enough-in-2026 ## Access Playback and chapters for this video are available with a Free account. ## Related Moments - [Automating threat modeling directly within developer pull requests](https://www.wearedevelopers.com/videos/100120-your-ai-ships-code-faster-than-anyone-can-review-it) (from "Your AI Ships Code Faster Than Anyone Can Review It") - [Adopting an iterative threat modeling workflow](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) (from "Real-world Threat Modeling") - [Introducing collaborative threat modeling workshops in engineering teams](https://www.wearedevelopers.com/videos/485-we-adopted-devops-and-are-cloud-native-now-what) (from "We adopted DevOps and are Cloud-native, Now What?") - [Integrating security across the application development lifecycle](https://www.wearedevelopers.com/videos/468-securing-your-application-software-supply-chain) (from "Securing your application software supply-chain") - [Recommended resources for continuous threat modeling education](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) (from "Real-world Threat Modeling") - [Defining threat modeling in secure design](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) (from "Real-world Threat Modeling") ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) ## Related Jobs - [Senior Product Security Architect](https://www.wearedevelopers.com/jobs/48532-senior-product-security-architect) at **Expedia** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/2628442-staff-developer-advocate-github-security-lab) at **GitHub** - [Model Implementation Engineer](https://www.wearedevelopers.com/jobs/48421-model-implementation-engineer) at **Sciforium** - [Senior Threat Intelligence Analyst](https://www.wearedevelopers.com/jobs/ext/2000909-senior-threat-intelligence-analyst) at **ZEISS Group** - [Senior Principal Software Engineer, Docker and Ecosystem](https://www.wearedevelopers.com/jobs/48456-senior-principal-software-engineer-docker-and-ecosystem) at **Docker, Inc.** - [SoC Offensive Security Staff Engineer](https://www.wearedevelopers.com/jobs/48479-soc-offensive-security-staff-engineer) at **Arm**