10 episodes

Chris Romeo is going on a journey. A journey to understand threat modeling at the deepest levels. He thought he understood threat modeling but realized he could go deeper. Chris shares his findings and talks with some of the best-known experts in the space to experience continuous learning. Join along for the ride -- you will learn something.Chris Romeo is the CEO of Devici (THE Threat Modeling Company) and a General Partner at Kerr Ventures.

The Threat Modeling Podcast Chris Romeo

    • Technology

Chris Romeo is going on a journey. A journey to understand threat modeling at the deepest levels. He thought he understood threat modeling but realized he could go deeper. Chris shares his findings and talks with some of the best-known experts in the space to experience continuous learning. Join along for the ride -- you will learn something.Chris Romeo is the CEO of Devici (THE Threat Modeling Company) and a General Partner at Kerr Ventures.

    Nandita Rao Narla -- Privacy Threat Modeling Wins, Losses, and Tools

    Nandita Rao Narla -- Privacy Threat Modeling Wins, Losses, and Tools

    In this podcast episode, Nandita Rao Narla explores the reasons why privacy threat modeling programs often fail, such as being expensive with a lot of friction in the development lifecycle, misalignment with organizational strategies focused on compliance rather than risk, and difficulty demonstrating a clear return on investment. Nandita highlights some successful strategies, including leveraging existing security threat modeling resources, simplifying the approach for better adoption like A...

    • 7 min
    Nandita Rao Narla -- Privacy Threat Modeling

    Nandita Rao Narla -- Privacy Threat Modeling

    Nandita Rao Narla introduces the basics of privacy in software. She discusses privacy threats, privacy threat modeling, and privacy by design. Suppose you write or handle software that touches user information. In that case, you need to understand privacy, how to assess and mitigate privacy concerns, and know when to implement privacy concerns into a design. This episode of the Threat Modeling Podcast is the perfect primer to raise awareness of the critical role privacy concerns should play i...

    • 8 min
    Akira Brand -- Gaining Experience by Threat Modeling

    Akira Brand -- Gaining Experience by Threat Modeling

    Akira Brand joins Chris to talk about her journey into threat modeling, her early experiences, some lessons learned, and how she knew her threat model was successful. Akira's experiences emphasize the importance of collaboration, understanding the application, and using tools and diagrams to aid the process.Akira is a visual thinker and draws parallels between surgical checklists and the STRIDE model. Akira emphasizes the importance of a comprehensive approach, likening the STRIDE model to a ...

    • 12 min
    Dr. Michael Loadenthal -- Intersectional, Harm Reduction Approach to Threat Modeling

    Dr. Michael Loadenthal -- Intersectional, Harm Reduction Approach to Threat Modeling

    Dr. Michael Loadenthal specializes in threat modeling beyond the conventional realm of technology. Companies today face multifaceted challenges, including political, legal, and technical threats. Solutions to these problems can also be varied. A comprehensive threat model should consider many dimensions, such as political, legal, ethical, and social. Whether advising activist groups or high-profile individuals, Dr. Loadenthal emphasizes a comprehensive understanding of the threat landscape an...

    • 19 min
    A Comprehensive Threat Modeling Strategy

    A Comprehensive Threat Modeling Strategy

    The AppSec community agrees that threat modeling is essential, but many struggle to implement it effectively. Using insight from the LinkedIn community, Chris lays out a comprehensive Threat Modeling strategy to guide AppSec teams to success in this critical discipline.Before starting, consider the organization's culture, tech debt, and current risk posture. Threat modeling will not be successful in an organization that doesn't prioritize security!Tie threat modeling to the success of the bus...

    • 7 min
    Software-Centric Threat Modeling

    Software-Centric Threat Modeling

    Engineering-led, developer-focused, or software-centric threat modeling: they all have software in common. Composing software into functions through the user story's lens is important. Farshad Abasi shares his journey from being a software engineer to forming a global AppSec team at HSBC Bank. Farshad expresses the importance of asset-based threat modeling and the need to keep things simple. He emphasizes the importance of focusing on the user story and considering the "comma, but" scenario t...

    • 8 min

Top Podcasts In Technology

Deep Questions with Cal Newport
Cal Newport
Acquired
Ben Gilbert and David Rosenthal
Lex Fridman Podcast
Lex Fridman
The TED AI Show
TED
Hard Fork
The New York Times
The AI Daily Brief (Formerly The AI Breakdown): Artificial Intelligence News and Analysis
Nathaniel Whittemore

You Might Also Like

The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo
The Application Security Podcast
Chris Romeo and Robert Hurlbut
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
Johannes B. Ullrich
Risky Business
Patrick Gray
CISO Tradecraft®
CISO Tradecraft®
Security Weekly Podcast Network (Audio)
Security Weekly Productions