Welcome!
Welcome to this month’s edition of Threat Modeling Insider!
In this issue, Amir Kavousian from DevArmor explains why threat modelers need to focus less on static documents and more on code.
He breaks down how policies, rules, tests, and fitness functions can make threat models truly live within the systems they describe.
Next over on the Toreon Blog, Sebastien Deleersnyder expands on the proposed ENISA draft for a Security-by-Design playbook, sharing key insights from our OWASP community input.
We also have plenty of other actionable insights for you, including a core threat modeling lesson from BIML, the story behind a $10,000 iPhone heist, and a practical tip on how to better target your threat models.
Settle in and let’s get started!

