
The Return on Investment of Threat Modeling
The Security Table team dialogues about the importance of data and metrics in understanding and communicating risk. After Matt defines ROI, Izar emphasizes that while data is crucial, it doesn't alway...
29 Aug 202333min

Jim Manico ❤️ Threat Modeling: The Untold Story
Jim Manico joins Chris, Matt, and Izar at the Security Table for a rousing discussion on his Threat Modeling journey. They also learn about each other's thoughts about DAST, SAST, SCA, Security in AI,...
22 Aug 202356min

Secure by Design
"Secure by Design" has garnered attention with the release of a document by CISA. What does it mean? How does it fit with Threat Modeling? And do you know if Secure by Design will answer our need for ...
15 Aug 202339min

Security Champions as the Answer to Engineering Hating Security
What happens when engineers transform into security champions? Is this beneficial, and what are the implications of this transformation? Izar reveals his transition from a naysayer to a supporter of s...
1 Aug 202343min

Why Do Engineers Hate Security?
There is a relationship between security professionals and engineers. Explore the possibility of engineers disliking security personnel and how security professionals can improve their relationship wi...
26 Jul 202349min

Security Posture is a Thing
What is security posture? Izar was at a conference in Amsterdam, where he was asked to define security posture and how to measure it. Is security posture qualitative or quantitative, and can it be com...
18 Jul 202344min

Should #AppSec be Part of the Development Team?
The big question is if it's possible to lose the application security team and move all the functions directly into development. What are developers' roles in application security (AppSec), and what ...
10 Jul 202337min

Lack of Reasonable, or Everything That Is Wrong with Security Requirements
How do you determine what constitutes "reasonable security" when evaluating vendors? Is “reasonable” a measure of compliance to a set standard? Is it reasonable to expect mature threat modeling practi...
29 Jun 202334min




















