The Application Security Podcast
The Application Security Podcast is a practitioner-led show for anyone building or securing modern software—and now AI-powered applications. Hosts Chris Romeo and Robert Hurlbut talk with the people shaping application security about AI and LLM security, threat modeling, secure development, OWASP, cloud, DevSecOps, security champions, and building programs that help engineering teams move faster and safer. With more than 300 episodes, the show turns real-world experience into practical guidance for developers, architects, AppSec professionals, and security leaders.
The Application Security Podcast
The Threat Modeling Manifesto – Part 2
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
How did a group of experienced practitioners turn months of disagreement into a usable Threat Modeling Manifesto? Part two follows the contributors as they refine principles, test language, and decide what belongs in the final document. The discussion compares recipes with adaptable patterns, examines the gap between documentation and shared understanding, and confronts the difficulty of proving threat modeling’s return on investment. Contributors including Alyssa Miller, Irene Michlin, Fraser Scott, Chris Romeo, and Robert Hurlbut debate whether guidance is essential or optional and whether patterns and anti-patterns can make it more actionable. The episode ends with the final principles and a complete acknowledgement of the people who created the Manifesto.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with the Threat Modeling Manifesto contributors:
→ Threat Modeling Manifesto
→ Chris Romeo on LinkedIn
→ Robert Hurlbut on LinkedIn
Mentioned in this episode:
→ Threat Modeling Manifesto
→ Zoe Braiterman
→ Adam Shostack
→ Jonathan Marcil
→ Stephen de Vries and IriusRisk
→ Irene Michlin
→ Kim Wuyts
→ Robert Hurlbut
→ Brook Schoenfield
→ Matthew Coles
→ Chris Romeo
→ Alyssa Miller
→ Izar Tarandach
→ Avi Douglen
→ Marc French
→ Agile Manifesto
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 From debate to a finished Manifesto
02:48 Recipes, patterns, and adaptable practice
05:04 Documentation versus shared understanding
08:14 The return on investment of threat modeling
09:49 Structure and systematic analysis
12:56 Refining the principles
13:34 Alyssa Miller’s perspective
14:43 Irene Michlin joins the debate
16:12 Essential guidance versus optional advice
17:55 Preserving the power of the principles
19:28 Patterns and anti-patterns
21:15 Helping teams become more effective
22:42 Reading the final principles
24:04 The Manifesto contributors
People on this episode
Podcasts we love
Check out these other fine podcasts recommended by us, not an algorithm.
The Security Table
Izar Tarandach, Matt Coles, and Chris Romeo