How Three Threat Modelers Can Influence an Entire Organization - Léandre Forget-B., Laurent Bouchard @OWASPGLOBAL
How Three Threat Modelers Can Influence an Entire Organization - Léandre Forget-B., Laurent Bouchard  @OWASPGLOBAL
Uploaded March 2025 | Updated September 2026, 2 weeks ago
Ever felt ignored when raising security concerns? So did we until we changed the game. This is the story of how a small team can drive change by wielding data-driven insights.

This talk delves into our journey of influencing our entire organization through threat modeling. From adopting a framework to managing threat intelligence, we’ll share the lessons learned and the solutions we found to common challenges.

As a small team, it is not realistic to cover everything by ourselves. We need to focus our energy on high value, high return activities and play the influence game. It was not an easy task, but we managed to do it.

Throughout the presentation, we’ll do an overview of our organization’s size and structure, where our team fits in to give some context and how all of this affects decision-making. We’ll explore the three key strategies we implemented to efficiently work toward our goal, namely:
adopting a common language for threat modeling across the organization,
embedding threat modeling into everyday operations according to the needs of each team, and
managing threat intelligence smoothly in an automated manner.

At the end of this talk, you will leave with actionable insights on what could be your next step and a newfound confidence in your abilities to drive change in your organization.

-

Managed by the OWASP® Foundation
owasp.org
How Three Threat Modelers Can Influence an Entire Organization - Léandre Forget-B., Laurent BouchardThe Broken State of DevSecOps and Its Maturity Model - Eitan Worcel, Dustin LehrLeaking Secrets in the Age of AI: How AI Adoption is Creating New Attack VectorsBuilding Security Into Developer Velocity: How We Made Entra Identity Compliance Invisible track 1Keynote by Adam Shostack: Stop Trying to Manage RiskOWASP Board of Directors - July 2026 Public Board MeetingNo Fate But What We Make: Doing Intrusion PredictionCycloneDX 2.0 Preview: Evolving BOM Architecture for Broader ApplicabilityGuardrails First: Building AI Agents That Won’t Leak Your Secrets - Track 2Red vs. Blue: Threat Modeling Agentic AI & Securing the Unbounded Third PartySecure Financial Analytics with Homomorphic Encryption and GAN Driven Data Track 2Don’t Make This Mistake: Painful Learnings of Applying AI in Security - Eitan Worcel
OWASP Foundation |

How Three Threat Modelers Can Influence an Entire Organization - Léandre Forget-B., Laurent Bouchard

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER