I helped facilitate the table that discussed “Purpose, Scope and New to Threat Modelling” and we had a very lively discussion covering:
What are the reasons for introducing threat modelling as a security activity
How the purpose of threat modelling should support the business goals
How threat modelling can fit in with or support other security activities like pen-testing
Different approaches to scoping a threat model; from working with teams, to risk assessing systems in order to prioritise.
Threat Modelling systems you integrate versus systems you build
It was really great to discuss the issues people have when trying to make threat modelling successful at their place or work, and to see how much variety in approach people take as they focus on trying to bring value to their businesses.
What a fantastic event in London for the first ever TMC Local Meetup!
We met a great group of people, from varying industries and roles. The threat modeling experience in the room differed person to person. With some being very new to threat modeling, and others who already have an established program in place at their organizations - and were more than willing to share their learnings! After all, this is what a community is all about.
Having this first historic meetup at the stunning IBM London office was a huge treat. Not only did we receive an outstanding presentation from Kreshnik Rexha, CTO of EMEA at IBM, but we got some extra unexpected opportunities like seeing the Boston Dynamics Robot Dog - Spot, and even receiving a talk about the Quantum Computer…
The breakout sessions were a perfect opportunity to share ideas and discuss key topics together which were:
Purpose, scope and new threat modeler guidance
Metrics and success management
Automation, tooling and AI integration
Threat modeling program development
We must thank the brilliant facilitators for making these open discussions possible, so thank you to @Petra, @omarsaenz@Dave and @Noel. I facilitated the fourth topic and found everyone’s experience so insightful and honest. We spoke about common challenges across teams, and how to improve collaboration and attitudes towards creating a program. We even shared culturally what we had seen for risk and security strategies being brought in over the years, and what we could learn from them for our threat modeling efforts.
The networking opportunities were a chance to unwind with good company, meet new people - and old friends - all while enjoying a great selection of pizza I must say!. We were able to talk freely about threat modeling, what we hope to achieve in the future, what manual approaches are already happening, and even one case where AI was proving to be a crucial aid in an established threat modeling process. To summarize, the in-person meetup was a huge success and it was a real pleasure to get to know our fellow Threat Modeling Connect members. We cannot wait to see you at the next one!