Balancing the Art and Science of Threat Modeling

Take the mystery out of threat modeling with a hands-on guide for developers, security pros, and team leads who want to shift left and build security into design, not just code. Written by Security Journey co-founder Chris Romeo, this guide teaches how to see threats in diagrams and features before they become vulnerabilities. You’ll get practical steps, real-world examples, tool recommendations, and the principles behind the Threat Modeling Manifesto—plus walkthroughs using STRIDE, ASVS, and data flow diagrams. Whether you're launching your first threat modeling session or scaling security across dev teams, this guide helps you embed security thinking at every stage of software development.