What should we model next year?

We just wrapped up the TMC Threat Modeling Hackathon 2025 a month ago!

(Missed it? Ouch… you missed a good one! Catch the recap here:TMC Threat Modeling Hackathon 2025 Recap)

Believe it or not, our judging panel has already started to plan for the 2026 edition (coming next spring)! And they want your input.

What systems, technologies, or real-world challenges do you want to see modeled next year? Whether it’s something emerging, something messy, or just something you’ve always been curious about—drop your ideas below. :backhand_index_pointing_down:

Yeah next year I would like to suggest a theme “Threat modeling is no Rocket science​:rocket:”, i would love to threat model spaceships, :satellite_antenna::satellite:groundstation, control center and rocket launching pads and similar ICS systems. It will be more fun threat modeling as well as learning such interesting topics and threats which elevates the challenge to the next level.

1 Like

Social Media
… including (but not limited to) service provider as a threat actor.

1 Like

Hi,

A suggestion would be to Threat Model an OT-environment, e.g., how a secure production environment could be designed and implemented.
This could include the product(s) being build, software- and firmware coming from R&D – this would include the entire SDLC, and the supply chain, in terms of the different components being used and vendors supporting the various components – how do you in practice ensure this is done securely.

I know there are much more to it than just this, and this is only a proposal.

2 Likes

I guess whatever is chosen, AI powered solutions are unavoidable and I guess many of us may find modeling threats of AI enhanced services challenging enough. Here are few ideas that I would suggest (each can be fully or partially AI driven e.g. to optimise some functions) - a. AI Managed Smart Homes (or offices) - optimizing energy consumption, safety monitoring and incident management, climate/air conditioning and lighting management etc. b. Disaster Response Systems - real time sensors data collection, AI automated disaster alerting, advanced data analytics and impact simulations, AI optimization of response resources and plans etc.c.Healthcare Management Systems - patient records management, AI-automated appointments with urgent cases prioritization, integration with medical sensors/smartwatches to monitor health status and therapy efficiency, therapy time alerts, medicaments ordering. d. Airport Management and Flight Reservation System - A driven flight scheduling, bookings management, automated passenger check-in and onboarding guidance, and ground personnel allocations.

1 Like