Advertisement · 728 × 90

Posts by Shostack + Associates

Preview
Shostack + Friends Blog > Measuring the ROI of threat modeling: moving from activity to impact Shostack + Associates COO Kymberlee Price shares her experience measuring the impact of secure design engineering practices on security outcomes

Kymberlee Price uses her experience with secure design engineering practices to suggest ways to measure the ROI of threat modeling that track impact, not just activity, in our latest blog post .

shostack.org/blog/roi-of-...

5 days ago 2 1 0 0
LinkedIn This link will take you to a page that’s not on LinkedIn

Early bird price extended on our exciting new course, Threat Modeling AI Systems, delivered by Shoshana Cox and Michael Novack on May 19 + 20 in Washington, D.C. The price is active until the end of the day today, April 16, anywhere on Earth.
Claim your spot: courses.shostack.org/courses/Thre...

6 days ago 0 0 0 0
Preview
Shostack + Friends Blog > Adam reflects on BSides SF and RSAC Adam finally caught his breath and sat down to reflect on BSides SF and RSAC 2026.

Adam went to San Francisco for BSides SF and RSAC and immediately jumped into some projects after getting back (did you know we have upcoming open courses?).
He's finally had the chance to post his reflections on the conferences.
shostack.org/blog/adam-re...

1 week ago 2 1 0 0

There's one week left to take advantage of early bird pricing for our newest course, Threat Modeling AI Systems, taking place in-person on May 19-20 in Washington DC.
Register by April 15 at courses.shostack.org/courses/Thre...

2 weeks ago 1 1 0 0
Preview
Shostack + Friends Blog Security, privacy, economics & unrelated topics, since 2005.

First Contact Day falls on a Sunday this year. We did not plan that but we did plan the second post in our Star Trek series. Come meet the crew with us. Picard. Worf. Troi. Data. It turns out the Enterprise senior staff has a lot to teach security engineers. Check back Sunday at shostack.org/blog!

2 weeks ago 1 1 0 0
Preview
Shostack + Friends Blog > DevSecOps: What Every Security Engineer Should Learn from Star Trek Security engineers in a DevSecOps world can learn a few things from Star Trek.

See what Star Trek can teach security engineers. Kymberlee Price sets a course in today's Shostack + Friends blog post. Live long and threat model.

3 weeks ago 3 1 1 0
Shostack + Associates > Home

We're very excited to transport into our new branding today. Let us know what you think of our new look!
shostack.org

3 weeks ago 1 0 0 0
Advertisement

Shields up. Something's coming to the Shostack + Associates website on Wednesday and we're not sure the internet is ready. Make it so.

3 weeks ago 1 1 0 0
Preview
Shostack + Friends Blog > Wasting Failures at RSAC™ 2026 Conference Cybersecurity should learn lessons from industries that are transparent about failure.

Adrian Sanabria of The Defenders Initiative and Adam Shostack take the stage this morning at 9:40 to discuss the case for breach transparency. Find the slides on the Shostack + Friends blog.

shostack.org/blog/wasting...

4 weeks ago 1 1 0 1
Preview
Threat Modeling AI Systems Training: 2‑Day Intensive Course Learn to identify, evaluate, and mitigate AI‑specific threats in this 2‑day, in‑person intensive training. Build skills in threat modeling for ML, generative AI, RAG systems, and AI agents using a…

Our newest course is now available and there’s an open session this May in Washington DC. We’re thrilled to have Shoshana and Michael join us to deliver this timely but durable course. More details and early bird registration at

1 month ago 3 1 0 0
Preview
Contact Shostack + Associates Contact information for Shostack + Associates

Are you subscribed to our course announcements? We have a new Threat Modeling AI Systems course debuting next week, so sign up to find out all the details as soon as they’re public.

Visit our Contact page and sign up under Stay Informed.

1 month ago 0 1 0 0
Preview
The Case for Why Better Breach Transparency Matters It's become a standard practice for organizations to disclose the bare minimum about a data breach, or worse — not disclose the incident at all.

Aviation and medicine improve by studying failures openly. Cybersecurity practitioners’ tendency to hide these failures opens the field up to preventable breaches. Adam and Adrian Sanabria sat down with Dark Reading ahead of their talk at RSAC 2026.

1 month ago 0 0 0 0

A small defensive toolbox limits the choices defenders make, so what models can expand those choices? That’s the subject of Adam’s talk at BSides Seattle, starting now.

1 month ago 0 0 0 0

Hello world! Shostack + Associates will be at BSides Seattle this weekend. Adam’s Track 4 talk, Layering Defenses: A New Hope, starts at 3pm today.

1 month ago 4 0 0 0