Build skills

Threat modeling training

Hands-on workshop for up to 25 people, available for companies onsite or remote. Individual practitioners can join public classroom sessions.

Why

Benefits

Threat modeling lets development teams find design risks before they turn into expensive fixes.

Identify Vulnerabilities Early

Finding security issues during design costs less than finding them during testing, after release, or during incident response.

Reduce Development Costs

Addressing security flaws before coding begins reduces rewrites, retrofits, and maintenance costs.

Enhance Security Awareness

Early threat modeling gives developers, architects, and product managers a shared way to reason about security throughout the SDLC.

Improve Design Decisions

Teams make better design choices when they can see how functionality, security, business goals, and usability interact.

Minimize Risk

Early detection and mitigation reduce the risk of future security incidents, protect sensitive data, prevent downtime, and preserve customer trust.

Support Compliance

Frameworks such as the EU CRA, GDPR, HIPAA, and NIST CSF expect secure design practices. Threat modeling gives teams evidence they can use in compliance work.

Price

In-Company Practical Training

Live full day hands-on training for up to 25 attendees.

Hands-on

€5700 +VAT

Threat modeling workshop for practitioners.

  • Onsite / remote options
  • Printed materials
  • STRIDE
  • Attack kill chains
  • MITRE ATT&CK
  • AI/ML security
  • Threat modeling rollout strategy
  • Success metrics
Request a quote

Complete

€6900 +VAT

Follow-up sessions help your team roll out threat modeling on real products.

  • Hands-on training, plus:
  • 2 rollout strategy follow-up calls (1 hour each)
  • 3 threat modeling sessions with your teams on your products (1 hour each)
Request a quote

Customized

Let's talk

Custom training adapted to your products, architecture, and team goals.

Schedule a call

Agenda

Topic outline

Introduction to threat modeling

  • What is threat modeling?
  • Why threat model?
  • When and how often?
  • Who should threat model?

What are we working on?

  • Defining the right scope
  • Data flow diagrams (DFD)
  • “Draw what we are working on with a DFD” hands-on exercise
  • Trust boundaries with examples
  • “Trust boundaries” hands-on exercise
  • Group review of each team’s diagram

What can go wrong?

  • Introduction to STRIDE
  • “Identify threats” hands-on exercise
  • Group review and discussion

What are we going to do about it?

  • Strategies to address threats
  • “Address discovered threats” hands-on exercise
  • Managing risk and prioritization
  • Discussion: tracking threats, assumptions, and mitigations

Attack Kill Chains

  • The Lockheed Martin Kill Chain
  • “List threats per kill chain” hands-on exercise
  • Group review and discussion
  • STRIDE vs. kill chains
  • MITRE ATT&CK®

Did we do a good job?

  • How to evaluate threat modeling sessions

AI Development

  • Development time threats
  • Threats through use
  • Runtime security threats

Rolling out a threat modeling program

  • Threat modeling capabilities
  • Convincing stakeholders
  • Rollout strategies
  • Adopting SSDLC
  • Security champions program
  • Soft skills for successful threat modeling sessions
  • Tooling and processes
  • Measuring threat modeling program success

Details

Trainers

Nariman Aga-Tagiyev

Nariman Aga-Tagiyev

Product Security Architect

Nariman Aga-Tagiyev is an Application Security Architect with more than 20 years of experience in software development. He has worked as a full-stack web application developer, backend developer, DevOps engineer, and cloud developer. Since 2016, he has focused fully on application security work.

Eden Yardeni

Eden Yardeni

Application Security Architect

Eden Yardeni has built application security programs across several large enterprises. A software engineer by background, she joined the OWASP ASVS working group in 2024 and specializes in security champions programs, threat modeling, and secure software development lifecycles (SSDLCs).

Details

FAQ

1. Why adopt threat modeling now?
Automated scanners cannot reason about design intent, trust boundaries, or abuse cases. Threat modeling gives software teams a structured way to find those risks before code is written. It also supports EU CRA readiness because manufacturers need evidence of secure design work instead of scan results alone.
2. What is the target audience?

This workshop is designed for people involved in any stage of the software development lifecycle. No prior cybersecurity expertise is required to attend.

  • Cybersecurity Officers, Software Architects, and Software Developers learn how to lead threat modeling sessions.
  • Quality Engineers learn how to define and verify security requirements, with foundational ethical hacking concepts as context.
  • Development Managers and Project Managers learn how threat modeling fits planning, stakeholder work, and delivery risk.
  • User Experience Designers and Business Analysts learn to define and prototype systems with a "secure by design" mindset.
3. What is the course approach?

Participants work in teams of 3 to 4 through each step of the threat modeling process. The scenario is a cloud-hosted application with backend, frontend, mobile client, and IoT device components. Guided by experienced coaches, teams create data flow diagrams, identify threats, propose mitigations, and define follow-up steps.

We also cover the secure development lifecycle for AI and show how to apply threat modeling when designing custom AI models and applications.

By the end of the training, participants can identify threats and propose mitigations with structured techniques.

4. Which topics are covered in the training?
You can find the detailed topics outline in the agenda above.
5. What facilities are required at the training location?
  1. A projector and power outlet for the trainer
  2. Adequate space for working groups of 3 to 4 people during hands-on exercises
  3. Flat surfaces where electrostatic whiteboards (70cm x 100cm) can be mounted for each breakout team

About

What is threat modeling

Threat modeling lets software teams identify, evaluate, and address security threats during design. When teams do it early, they can build security into the architecture before fixes become expensive. The result is software that is easier to defend, review, and maintain.

Make it happen

Request a quote

We’ll prepare a quote for your purchasing team within 24 hours. No spam afterward.

Prefer email? Write to us and we'll get back within one business day.

Email training@securehabits.nl