Session
Your Threat Model Is Lying to You: Why Modeling the Design Isn’t Enough in 2026
Threat modeling was created for a time when the intended design closely matched what shipped. That is no longer true. Most teams still model what they plan to build, including user flows, design decisions, and evil user stories, but they rarely re-evaluate the model against what is actually deployed. Pipelines continuously uncover real risks through SAST, SCA, DAST, IaC scans, and cloud configuration checks, yet those signals are not fed back into the threat model. This creates a growing blind spot where decisions are based on assumptions instead of production truth.
This session shows how to extend threat modeling beyond design and incorporate evidence from the built system. You will learn how to treat discovered vulnerabilities as inputs that evolve the model and how to update the model continuously without waiting for new platforms. The approach is practical and can be adopted with tools most teams already have.
Farshad Abasi
Founder | Application & Pipeline Security Architect | OWASP SPVS Co-Author
Vancouver, Canada
Links
Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.
Jump to top