DSO Overflow

S4Ep10 - Threat modelling with Ashley Ward

Dec 6, 2024
Ashley Ward, CTO at ControlPlane, shares his extensive expertise in cybersecurity and agile leadership. He emphasizes the importance of collaborative threat modeling in cloud-native environments, tackling the unique challenges posed by microservices and rapid release cycles. Ward discusses the integration of AI in security practices, warning of the increased risks as technology becomes more accessible to hackers. He advocates for continuous improvement in security by revisiting and adapting threat models to keep pace with evolving digital landscapes.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Start with What You Know

  • Start threat modeling with what you know within your area of expertise.
  • Then, collaborate with adjacent teams to gain broader perspectives and identify shared mitigations.
ADVICE

Use Frameworks, Iterate

  • Use established frameworks like the CIA triad to guide threat modeling, even for beginners.
  • Don't aim for perfection; iterate and improve your models over time.
ADVICE

Visualize with Attack Trees

  • Visualize threats using attack trees to identify high-impact paths.
  • Prioritize addressing risks along those critical paths.
Get the Snipd Podcast app to discover more snips from this episode
Get the app