Uploaded December 2025 | Updated September 2026, 3 weeks ago
“Breaking the Black Box – Using the OWASP Threat Model Library to End Security via Obscurity” makes the case that publishing threat models is no longer a radical gesture but an emerging baseline. After recapping the initial momentum of the OWASP Threat Model Library, the talk maps the regulatory context (EU NIS2, Cyber Resilience Act, DORA, U.S. Executive Order 14028, SEC disclosure rules) that are turning transparency into a compliance requirement.
With Adam Shostack's "Publish your threat model" blog and the CycloneDX Transparency API, the community movement is already here. It then unpacks why organizations should aim to start releasing threat-model documents: to foster customer trust, crowd-sourced security, audit-ready evidence and talent attraction. Potential downsides (adversary insight, IP leakage, maintenance burden, stakeholder panic) are addressed with a pragmatic “publish-after-mitigation” approach, automation and executive summaries of identified risks. Real-world examples (HashiCorp Vault, Kubernetes, Kata Containers, AWS Nitro, Apple Platform Security, Cloudflare Workers) prove the concept is already working. Finally, the session walks through a live publication of the Devarmor threat model - demonstrating scoping, JSON generation and GitHub release - before inviting attendees to join the transparency movement and contribute their first model - and tag it #ThreatModelLibrary #BreakTheBlackBox
Petra Vukmirovic
Numan
Head of Information Security at Numan and Fractional Head of Product at Devarmor
medium.com/@petra.v1986
Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led her to pivot into cyber security, earning a Master’s in Information Security and Digital Forensics._x000D_
_x000D_
Starting as a cybersecurity intern at Glasswall, Petra quickly advanced to a security engineer role, where she developed machine learning capabilities that led to a patent for using content disarm and reconstruction (CDR) to detect unknown malware. She progressed to senior security engineer roles at Zava and Jobandtalent, where her expertise and leadership saw her rise to Director of Cyber Security at Jobandtalent. In Jobandtalent she hired and led global security teams, while leveraging her creative problem-solving skills to drive compliance with industry standards like NIST and ISO27001. _x000D_
_x000D_
By combining her passion for threat modelling and AI, Petra is also leading the product development at Devarmor as a Fractional Head of Product - to transform threat modelling and security design reviews with automation, integration and enforcement. _x000D_
_x000D_
In her current role at Numan - as Head of Information Security, Petra is utilising her unique background in both healthcare and technology to give her a well-rounded perspective, enabling her to deliver business value by bridging technical expertise with operational insight and taking Numan's information security to the next level.
Managed by the OWASP® Foundation
owasp.org
“Breaking the Black Box – Using the OWASP Threat Model Library to End Security via Obscurity” makes the case that publishing threat models is no longer a radical gesture but an emerging baseline. After recapping the initial momentum of the OWASP Threat Model Library, the talk maps the regulatory context (EU NIS2, Cyber Resilience Act, DORA, U.S. Executive Order 14028, SEC disclosure rules) that are turning transparency into a compliance requirement.
With Adam Shostack's "Publish your threat model" blog and the CycloneDX Transparency API, the community movement is already here. It then unpacks why organizations should aim to start releasing threat-model documents: to foster customer trust, crowd-sourced security, audit-ready evidence and talent attraction. Potential downsides (adversary insight, IP leakage, maintenance burden, stakeholder panic) are addressed with a pragmatic “publish-after-mitigation” approach, automation and executive summaries of identified risks. Real-world examples (HashiCorp Vault, Kubernetes, Kata Containers, AWS Nitro, Apple Platform Security, Cloudflare Workers) prove the concept is already working. Finally, the session walks through a live publication of the Devarmor threat model - demonstrating scoping, JSON generation and GitHub release - before inviting attendees to join the transparency movement and contribute their first model - and tag it #ThreatModelLibrary #BreakTheBlackBox
Petra Vukmirovic
Numan
Head of Information Security at Numan and Fractional Head of Product at Devarmor
medium.com/@petra.v1986
Petra is a technology enthusiast, leader and public speaker. A former emergency medicine doctor and competitive volleyball athlete, she thrives in challenging environments and loves creating order from chaos. Initially pursuing a medical career, Petra's passion for technology led her to pivot into cyber security, earning a Master’s in Information Security and Digital Forensics._x000D_
_x000D_
Starting as a cybersecurity intern at Glasswall, Petra quickly advanced to a security engineer role, where she developed machine learning capabilities that led to a patent for using content disarm and reconstruction (CDR) to detect unknown malware. She progressed to senior security engineer roles at Zava and Jobandtalent, where her expertise and leadership saw her rise to Director of Cyber Security at Jobandtalent. In Jobandtalent she hired and led global security teams, while leveraging her creative problem-solving skills to drive compliance with industry standards like NIST and ISO27001. _x000D_
_x000D_
By combining her passion for threat modelling and AI, Petra is also leading the product development at Devarmor as a Fractional Head of Product - to transform threat modelling and security design reviews with automation, integration and enforcement. _x000D_
_x000D_
In her current role at Numan - as Head of Information Security, Petra is utilising her unique background in both healthcare and technology to give her a well-rounded perspective, enabling her to deliver business value by bridging technical expertise with operational insight and taking Numan's information security to the next level.
Managed by the OWASP® Foundation
owasp.org










