

EP215 Threat Modeling at Google: From Basics to AI-powered Magic
18 snips Mar 17, 2025
Meador Inge, a security engineer at Google, dives into the intricacies of threat modeling, detailing its essential steps and applications in complex systems. He explains how Google continuously updates its threat models and operationalizes the information to enhance security. The conversation explores the challenges faced in scaling threat modeling practices and how AI, particularly large language models like Gemini, is reshaping the landscape. With a humorous twist, Inge shares insights into unexpected threats and effective strategies for organizations starting their threat modeling journey.
AI Snips
Chapters
Books
Transcript
Episode notes
Scoping Complex Systems
- Threat modeling complex systems requires careful scoping, balancing size and usefulness.
- Recursively break down large systems into smaller, manageable chunks for effective analysis.
Keeping Threat Models Updated
- Update threat models incrementally, integrating them into the software development lifecycle.
- Establish a baseline threat model and regularly update it through security and design reviews.
Operationalizing Threat Models
- Simply creating a threat model document isn't enough; it needs to be operationalized.
- Unused threat models are like waterfall design documents – quickly outdated and ineffective.