Workshop Intermediate 3 Hours 10:15 - 13:00 August 09, 2026

Robert Hurlbut

This workshop introduces the practical world of threat modeling, combining hands-on exercises and real-world scenarios. In particular, we will focus on how AI can enhance your threat modeling work plus introduce the basics of securing AI systems.

We will review some of the latest threat intelligence and attack methods projected for 2026/2027, including vulnerabilities in LLMs and Agentic AI. Participants will engage in practical exercises inspired by real industry projects, such as integrating threat modeling into security-by-design and DevOps/MLOps workflows. Key features include threat-informed defense using MITRE frameworks such as ATLAS for real-world analysis, leveraging threat intelligence libraries to deepen threat understanding, and addressing modern challenges.

By the end of this workshop, you will walk away not just with knowledge but also the ability to start practicing threat modeling effectively in your organization.

Robert Hurlbut

Threat Modeling Trainer and Consultant (Freelance)

Robert brings over 30 years of experience in secure coding, software architecture. Robert started and led the threat modeling program at Bank of America, filled in a similar role at Aquia and was a trainer and coach at Toreon. He is passionate about helping teams identify, communicate, and understand threats and mitigations and enhance workload security through threat modeling.

Robert is a Microsoft MVP for Developer Security and an ISC2 Certified Secure Software Lifecycle Professional (CSSLP). He holds a Master of Science in Cyber Security from Southern New Hampshire University and is a Ph.D. candidate in Space Cybersecurity at Capitol Technology University.

Robert is co-author of the Threat Modeling Manifesto (https://www.threatmodelingmanifesto.org/), Threat Modeling Capabilities Model (https://www.threatmodelingmanifesto.org/capabilities), and co-host of the Application Security Podcast (https://appsec.buzzsprout.com/).