As development gets more autonomous, the checkpoints that need human judgment don't get automated — they get skipped. If a threat model was never considered, unknown vulnerabilities are created that are just waiting to be exploited. Catch it at plan — that's a conversation. Catch it after deployment — that's an incident.
A short list of tools referenced in the talk — useful for actually diagramming the systems you're threat-modeling.
I'm building out a 5-week class for startups off the back of this talk — combining threat modeling, shared responsibility, and baseline security guardrails into one pre-deployment curriculum.
Grab 15 minutes on my calendar, or send me an email directly.
ana@anashah.com