
Where is threat modeling headed? In this closing episode, Chris and Trevor explore practical AI use cases, the future of developer-led security, and how organizations can prepare now. Takeaways:
The reality of AI today: what’s useful vs. overhyped.
Continuous delivery + security: can we really have both?
The long-term shift toward “Security by Design” at scale.
Positions Devici as a forward-looking, AI-enabled platform.
Dec 2, 2025
28 min

Not all tools are created equal. Chris and Trevor compare common approaches — from free tools to heavyweight enterprise platforms — and share guidance on what to look for in the right solution. Takeaways:
When Microsoft TMT is enough — and when it’s not.
Pros and cons of enterprise platforms like IriusRisk/ThreatModeler.
How to measure ROI in terms of risk reduction and developer adoption.
Echoes Devici’s “Threat modeling without the bloat” message.
Nov 25, 2025
27 min

Security teams and developers don’t always speak the same language. This episode explores how to make threat modeling a true “team sport” that fits naturally into developer workflows.
Takeaways:
Collaboration techniques that work.
How diagram-first modeling closes the communication gap.
Making outputs actionable for developers.
Highlights Devici’s real-time collaboration + built-in libraries.
Nov 18, 2025
29 min

Many threat modeling efforts fall flat. Chris uncovers the common reasons — from cultural pushback to lack of developer adoption — and shares proven strategies for success. Takeaways:
The most common pitfalls (and how to avoid them).
Embedding consistency across security teams.
Scaling without adding headcount.
Supports Devici’s “Smarter, simpler threat modeling” positioning.
Nov 11, 2025
26 min

Threat modeling has evolved from sketches on a whiteboard to AI-enabled, diagram-first platforms. This episode explores how teams can modernize without the complexity of bloated enterprise tools.
Takeaways:
Why manual and siloed approaches fail at scale.
The rise of diagram-driven threat modeling.
Where AI fits today — and what’s hype vs. real.
Reinforces Devici’s value as simple, intuitive, and forward-looking.
Oct 7, 2025
17 min

Threat modeling can feel overwhelming, but it doesn’t have to be. Chris and Bruce break down who needs to be involved, what roles matter most, and how to start small without losing impact.
Takeaways:
Key players to engage: architects, AppSec leads, developers, exec sponsors.
How to secure buy-in and avoid resistance.
Practical first steps to launch a repeatable practice.
Aligns with Devici’s “Security by Design starts somewhere — start fast” message.
Sep 29, 2025
24 min

Today we are joined by Altaz Valani from Security Compass and Shaun Mckeag, Principal Software Engineer at Gen Digital, to talk about her personal journey in software development and security. Many listeners are either trying to get into secure software development, or have graduated from a program that teaches security and software development, or perhaps recently transitioned from a different role. It’s nice to have someone with years of experience in the field to give some perspective, guidance, tips, and encouragement. Listen in as Shaun shares her personal journey that will inspire and help those of us who are newer to the secure software space.
Useful links from this podcast:
https://www.linkedin.com/in/shaunmckeag/
https://nakedsecurity.sophos.com/podcast/
https://www.sans.org/blog/
https://www.devseccon.com/the-secure-developer-podcast
https://darknetdiaries.com/
https://owasp.org/events/#AppSec%20Days
https://devcon.org/
https://www.blackhat.com/
Dec 5, 2022
23 min

Today we are joined by Altaz Valani from Security Compass and Pranshu Bajpai, Security Architect at Motorola Solutions, to talk about the use of application security training to influence developers toward embracing security. Many developers are eager to learn about security but they need help. Developers move very fast because their performance is often measured around release frequency. All of this is happening while developers have to keep up with continually evolving frameworks and tools. It is possible for security teams to influence developers without getting in their way.
Nov 8, 2022
26 min

Today we are joined by Altaz Valani from Security Compass and Simone Curzi, Principal Consultant at Microsoft, to talk about the role of developers within threat modeling. When we mention threat modeling, what often comes to mind are data flow diagrams created during a security design process. After these diagrams are created and eventually hit the developer backlog, we discover more insights that further evolve the security design. In this way, developers are crucial to an evolving threat model activity. Yet, many questions exist. We try to answer some of those developer questions related to threat modeling.
Useful links from this podcast:
https://simoneonsecurity.com/
https://threatsmanager.com/
https://www.threatmodelingmanifesto.org/
https://cve.mitre.org/
https://cwe.mitre.org/
Sep 12, 2022
30 min

Today we are joined by Altaz Valani from Security Compass and Jason Keirstead, Distinguished Engineer & Chief Technical Officer of Threat Management at IBM as well as Co-Chair of Open Cybersecurity Alliance. Security tool integrations are largely custom efforts today. That investment alone prevents loose coupling of our security tool architectures and timely delivery of security insights to key decision makers. Jason shares his insights on the work going on at Open Cybersecurity Alliance (OCA) to help solve this problem. The holy grail of an integrated security fabric that shares information across a toolchain can transform our ability to rapidly adapt to a changing threat landscape and allow for early detection of threat actor behavior. Jason shares his vision of how everyone can play a part in making this a reality, from customer procurement to vendor adoption of security standards.
Aug 31, 2022
28 min
Load more
