Can Threat Modeling Actually Improve Incident Response?

Can Threat Modeling Actually Improve Incident Response?

You threat model to identify threats and implement mitigations before you deploy an application. In this regard, the overarching reason for your commitment to do threat modeling is to avoid incident response altogether. Theoretically, an application with no...
Whitepaper: What’s Needed to Turn DevOps into DevSecOps

Whitepaper: What’s Needed to Turn DevOps into DevSecOps

DevOps is a natural byproduct of the shift to agile software development and the move to the cloud. One of the main benefits of DevOps is the speed of software iteration, based on user stories and development sprints. The drawback to all this speedy development,...
Cyber Insights 2023 | The Coming of Web3

Cyber Insights 2023 | The Coming of Web3

Web3 is a term that has been hijacked for marketing purposes. Since web3 obviously represents the future internet, claiming to be web3 now is a claim to be the future today. Such claims should be viewed with caution – we don’t yet know what web3 will be. Read more...
Seven Common Misconceptions About Threat Modeling

Seven Common Misconceptions About Threat Modeling

There is general consensus in the DevSecOps community that threat modeling is a good thing. The sooner in the application development cycle you find a threat the less it costs to fix, and there’s hardly any better way to “shift left” than with threat modeling. So, why...
An Overlooked Reason Why There are so Many Data Breaches

An Overlooked Reason Why There are so Many Data Breaches

Take a look at the headlines in any security news outlet and one thing really stands out. There are data breaches everywhere. That happen all the time, to organizations that know better. And it’s not like anyone wants a data breach. In fact, just the opposite is true....
Are Your Threat Models Ready for Q-Day?

Are Your Threat Models Ready for Q-Day?

Threat models are really good at identifying and mitigating cybersecurity threats. But they’re not much good at addressing threats nobody knows about. And that brings us to the security threats expected to arrive on Q-Day. We know about some of the threats that are...