The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
The Threat Modeling Manifesto – Part 1
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
What should threat modeling mean when practitioners use the term in very different ways? Part one of the Threat Modeling Manifesto documents a six-month collaboration among experienced practitioners trying to create a definition, values, and principles the community can support. The recording preserves real disagreements about people, design, privacy, tools, jargon, and how broad the practice should be. Contributors including Alyssa Miller, Fraser Scott, Brook Schoenfield, Matthew Coles, Chris Romeo, and Robert Hurlbut test individual words against years of teaching and consulting experience. Rather than presenting a polished result without context, the episode shows the difficult work of building consensus and deciding how a short public statement can remain precise without becoming inaccessible.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with the Threat Modeling Manifesto contributors:
→ Threat Modeling Manifesto
→ Chris Romeo on LinkedIn
→ Robert Hurlbut on LinkedIn
Mentioned in this episode:
→ Threat Modeling Manifesto
→ Zoe Braiterman
→ Adam Shostack
→ Jonathan Marcil
→ Stephen de Vries and IriusRisk
→ Irene Michlin
→ Kim Wuyts
→ Robert Hurlbut
→ Brook Schoenfield
→ Matthew Coles
→ Chris Romeo
→ Alyssa Miller
→ Izar Tarandach
→ Avi Douglen
→ Marc French
→ Agile Manifesto
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Why the Threat Modeling Manifesto was created
01:25 Beginning the definition debate
02:57 Putting people at the center
04:16 Defining the boundaries of threat modeling
04:59 Alyssa Miller on security, privacy, and business
06:38 Building a definition the community can support
08:34 Fraser Scott on precise language
09:39 Brook Schoenfield on models and experience
12:09 Quality, buzz, and practitioner expectations
14:03 Short and long definitions
16:27 What counts as a threat modeling tool
18:25 Separating values from principles
20:35 Converging on the wording
23:09 Reviewing the remaining disagreements
25:04 How values become practice
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo