Skip to content

Session

Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026

with Farshad Abasi

About This Session

Threat modeling was created for a time when the intended design closely matched what shipped. That is no longer true. Most teams still model what they plan to build, including user flows, design decisions, and evil user stories, but they rarely re-evaluate the model against what is actually deployed. Pipelines continuously uncover real risks through SAST, SCA, DAST, IaC scans, and cloud configuration checks, yet those signals are not fed back into the threat model. This creates a growing blind spot where decisions are based on assumptions instead of production truth. This session shows how to extend threat modeling beyond design and incorporate evidence from the built system. You will learn how to treat discovered vulnerabilities as inputs that evolve the model and how to update the model continuously without waiting for new platforms. The approach is practical and can be adopted with tools most teams already have.

Topics

  • AppSec
  • Security
  • Threat Modelling