Threat Modeling 201: Beyond Risk Assessments - How to Maximise the Value of Your Threat Model?
18 November 2026 | Bucharest
Threat Modeling as an Operational Capability
Many take the view that threat modeling is an exercise to generate a list of threats with STRIDE, manage risk, and conclude it as a one-off exercise. While this is a good start for an organisation that might be building up their state of security, this is leaving plenty of untapped potential of a threat model on the table.
In this edition of threat modeling classes, we will explore how threat modeling can become an operational security capability. We will connect architecture and threat analysis to attack simulation, red teaming, threat hunting, and continuous defensive improvement.
The workshop begins with a concise recap of the foundations of threat modeling before moving into the challenges of modeling complex systems, particularly AI-enabled systems. Participants will use multiple frameworks such as STRIDE, MITRE ATT&CK and MITRE ATLAS to build threat scenarios at different levels of abstraction, in order to understand threats across modern architectures. We will answer questions such as: how deep must my data flow diagram go before it is deemed good enough?
We will also focus on how the threat model can be transformed into attack simulations and red team activities, and make use of these exercises to translate into actionable defensive requirements. This demonstrates to the C-suite how threat modeling can be useful as a proof of value for attack simulations and red team activities, which are often misunderstood in terms of the value they offer, and mismanaged at the C-suite level with metrics that are not always appropriate to answer questions such as: can our systems be resilient against our likeliest adversaries?
We will also tackle emerging literature in threat modeling topics. Enterprises have looked into how threat modeling can improve blue team processes such as threat hunting. We will go into how threat modeling enables the generation of structured threat hypotheses, prioritization of such threat hunts, and how threat hunting can be iterated with threat modeling. We attempt to operationalize white papers written by reputable organizations on this topic, so that threat modeling is seen not as a one-off exercise, but as the cornerstone of any mature security program.
Why is this workshop relevant?
What happens after you have finished your threat model?
A threat model should not become a document that sits in a repository collecting dust. There is so much more security teams can do with their threat models, and this is where Threat Modeling 201 comes in.
In Threat Modeling 201, we will explore how to turn threat models into something much more useful: a bridge across architecture, offensive security, and defensive operations.
We will start by revisiting the foundations of threat modeling before tackling the harder problem of modeling complex and AI-enabled systems. You will see how frameworks such as MAESTRO and MITRE ATLAS can help us reason about threats across modern AI architectures, alongside frameworks such as STRIDE and MITRE ATT&CK for threat enumeration.
Then we will move from “What could go wrong?” to “Can we actually demonstrate it?”
You will learn how threat scenarios can be transformed into penetration tests, red team operations, breach and attack simulations, and purple team exercises, so you can justify how these security activities validate the risks highlighted during the threat modeling exercise, answering the question: can our systems be resilient against our likeliest adversaries?
Finally, we will turn to the other side of the fight: threat hunting. Threat models can provide a powerful source of hypotheses for defenders, while threat hunting results can reveal gaps and assumptions in the original model. We will explore how to connect these activities, break down security silos, prioritise hunts, and create a continuous feedback loop between modeling, attacking, and defending.
Whether you are a threat modeler, red teamer, blue teamer, security architect, or simply someone trying to get different security teams to work together, this workshop will show how threat modeling can become more than an exercise in documentation. Do justice to the threat model you have just done, and show how it can become the connective tissue between understanding threats, validating them, and defending against them.
Who is it for?
This is ideally an intermediate to advanced class. Participants should have a basic understanding of cybersecurity and already have exposure in one or more security domains.
Participants are not expected to know a breadth of security topics. Exercises are structured so that different team members can contribute their own security expertise, in order to build a threat modeling program that harmonizes with the different security roles and functions in an organization.
A recap of fundamental topics is provided, including data flow diagrams, STRIDE, attack trees, threat scenarios and risk. That said, participants should expect this class to be fast-paced.
Ideal audience
- Threat modeling practitioners
- Security architects and engineers
- Application and product security professionals
- Red teamers and penetration testers
- Blue teamers and threat hunters
- SOC and detection engineering teams
- Incident responders
- Cybersecurity consultants
- AI and ML security practitioners
- Security managers responsible for integrating offensive and defensive security activities
Participants do not need to be expert red teamers or threat hunters. The workshop is specifically designed to demonstrate how these disciplines can work together through a common threat-model-driven approach.
Workshop agenda
Top-level agenda. The detailed breakdown may still change as the trainers finalise the material.
About the trainers
DONAVAN CHEAH
Cybersecurity Consultant
Donavan Cheah is a Physics graduate turned cybersecurity consultant, with ten years of experience across offensive security, threat modeling, maturity assessments, security architecture and GRC, in both the private and public sectors.
He co-leads the Singapore chapter of Threat Modeling Connect and is a founding member of Kinryu Labs, which specialises in threat intelligence and in uncovering malware and APT groups. He sits on the advisory board of VULNCON, on the review board of OASec, and advises several BSides events.
He writes on post-quantum cryptography, threat modeling and the social sciences of cybersecurity for ISACA and for Infosecurity Magazine, and is a member of the ISACA Emerging Trends Working Group. At Thales he led the team behind Defend the Breach, a Singapore cybersecurity gamification experience in which players role-play as CISOs to explore security decision making and trade-offs.
Donavan has spoken at conferences across Singapore, Japan, India, Taiwan, Romania and Uzbekistan, including DEF CON SG, CYSAT Asia, SINCON, SECCON JP, Seasides, VULNCON, the Global Cybersecurity Camp and DefCamp.
CERTIFICATIONS
OSCE3 · OSCP · OSWP · CISSP · CRISC
He holds an M.Sc. in Cybersecurity Policy from Georgia Tech and a B.Sc. in Physics from the National University of Singapore.
TAKAHARU OGASA
CEO, Secure Modeling Inc.
Takaharu Ogasa is CEO of Secure Modeling Inc. and a security consultant with more than a decade of experience in application security, penetration testing, and security consulting.
He is the founder and chapter leader of OWASP Sendai and a leader of Threat Modeling Connect Tokyo (TMC Tokyo), where he works to grow the threat modeling community in Japan through meetups, hands-on workshops, and collaboration with practitioners from different disciplines.
His work focuses on making threat modeling practical and collaborative, helping organizations integrate security into system design and enabling development and security teams to build threat modeling capabilities themselves.
Takaharu has delivered threat modeling workshops and training sessions across Japan for engineers, security professionals, and IT practitioners. His workshops emphasize collaborative modeling, bringing together different perspectives from development, infrastructure, operations, security, and business to improve shared understanding of systems and uncover risks that may otherwise be missed.
He is particularly interested in making threat modeling a team-owned practice rather than an activity performed only by security specialists.
Key learning objectives:
✔ Threat Model Complex & AI Architectures: model sophisticated and AI-enabled systems using industry frameworks like STRIDE, MITRE ATT&CK, MITRE ATLAS, and MAESTRO at multiple levels of abstraction.
✔ Bridge Threat Modeling with Offensive Security: transform abstract threat scenarios into actionable penetration tests, red team operations, breach & attack simulations, and purple team exercises.
✔ Operationalize Blue Team & Threat Hunting Processes: leverage threat models to generate structured hypotheses, prioritize threat hunts, and create a continuous feedback loop between detection, defense, and modeling.
✔ Establish Threat Modeling as a Continuous Capability: shift threat modeling from a static, one-off risk documentation exercise into a dynamic operational security capability.
✔ Demonstrate C-Suite Value & Resiliency: translate offensive and defensive simulation outcomes into concrete metrics and actionable requirements that prove system resilience to business leaders.
Other information & prerequisites
TBD
Other information
Estimated Workshop Duration: 8 hours (one day)
Language of Instruction: English
Participation fee: EUR 230
FAQs
If we do not meet the minimum number of participants, you can either transfer to another workshop and pay or receive a refund for any difference in price, or opt for a full refund. You will be notified in advance and given options to choose what works best for you.
The workshop price covers food. However, accommodation is not included, but we can recommend nearby options for your convenience.
Yes, full refunds are available up to 15 days before the workshop start date. However, if you cancel after that, we can offer only 50% of the price.
You will receive an email with all the necessary details, including the workshop location, prerequisites, and schedule, at least one week before the event. If you have any immediate questions, feel free to reach out to us directly.