# How do you get your dev team to shift security left?

**URL:** https://threatmodelingconnect.discourse.group/t/how-do-you-get-your-dev-team-to-shift-security-left/1182
**Category:** General
**Created:** [October 3, 2025, 8:16am UTC](https://threatmodelingconnect.discourse.group/t/how-do-you-get-your-dev-team-to-shift-security-left/1182 "2025-10-03T08:16:57Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![Johan\_Sydseter](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/johan_sydseter/32/369_2.png) [@Johan\_Sydseter](https://threatmodelingconnect.discourse.group/u/Johan_Sydseter)
#### Post date: [October 3, 2025, 8:16am UTC](https://threatmodelingconnect.discourse.group/t/how-do-you-get-your-dev-team-to-shift-security-left/1182/1 "2025-10-03T08:16:57Z")

</div>

![threat modeling for security people](https://us1.discourse-cdn.com/flex002/uploads/threatmodelingconnect1/original/1X/f1b7abf0e7efe87b3775e74a4443c0f24f6a610b.jpeg)

How do you get your dev team to shift security left?  
In your organization, does shift-left mean scanning code for security vulnerabilities, or does it begin with designing it?  
Can threat modeling be part of an organization’s shift-left strategy?  
Our shift-left strategy involves playing games. What is yours?

[https://dev.to/owasp/how-do-you-get-your-dev-team-to-shift-left-by-themselves-for-real-3eap](https://dev.to/owasp/how-do-you-get-your-dev-team-to-shift-left-by-themselves-for-real-3eap)

In the latest version of OWASP Cornucopia, we have added STRIDE analysis to each of the cards: [https://cornucopia.owasp.org/cards/VE2#STRIDE](https://cornucopia.owasp.org/cards/VE2#STRIDE)

At the same time, we ask the questions:

- What are we working on?

- What can go wrong?

- What are we going to do about it?

So, how about “Did we do a good job?”  
In the next major release (v3.0), we will also discuss the last question: “Did we do a good job?”  
Why? Because we want the game to be used in iterative security processes that involve continually adapting security measures in cycles to identify, address, and reassess threats and vulnerabilities, making continuous improvements rather than a one-time fix. What do you think? Can games be used to continuous improve your security?
