Threat Modeling Developer Behaviour: The Psychology of Bad Code @OWASPGLOBAL
Threat Modeling Developer Behaviour: The Psychology of Bad Code  @OWASPGLOBAL
Uploaded December 2025 | Updated September 2026, 3 weeks ago
Security teams threat model systems, but rarely do we threat model the developers building them. What if some of the most persistent AppSec problems aren’t purely technical—but behavioral?

This talk dives into the psychology of insecure code, using principles from behavioral economics to explain why developers take risky shortcuts, ignore secure practices, or ship code that “just vibes.” From copying insecure Stack Overflow snippets, to skipping documentation, to shipping untested features under tight deadlines—these aren’t personal failings. They’re predictable cognitive patterns influenced by incentives, stress, and how our brains are wired.

We’ll explore how well-known concepts such as present bias, automation bias, the bystander effect, and overconfidence play out in real-world development. Then we’ll shift from insight to action—offering behavioral nudges and design patterns you can apply in your SDLC, tools, and team culture to make secure behavior the default.
This talk blends psychology, security, and dev reality to reframe AppSec—not as a checklist, but as a human system.

Tanya Janca
Victoria, Canada

Tanya Janca, aka SheHacksPurple, is the best-selling author of 'Alice and Bob Learn Secure Coding', 'Alice and Bob Learn Application Security’ and the ‘AppSec Antics’ card game. Over her 28-year IT career she has won countless awards (including OWASP Lifetime Distinguished Member and Hacker of the Year), spoken all over the planet, and is a prolific blogger. Tanya has trained thousands of software developers and IT security professionals, via her online academies (We Hack Purple and Semgrep Academy), and her live training programs. Having performed counter-terrorism, led security for the 52nd Canadian general election, developed or secured countless applications, Tanya Janca is widely considered an international authority on the security of software.

Managed by the OWASP® Foundation
owasp.org
Threat Modeling Developer Behaviour: The Psychology of Bad CodeLiving off Microsoft Copilot - Michael BarguryEvolving Threat Modeling Through the Open Threat Model Format - Fraser ScottOWASP Corporate Supporter Spotlight - root.ioOne Cluster to Rule Them All: Pentesting Multi-Tenant Kubernetes ClustersOWASP Finance - Full Summary Readout May 2026OWASP Dependency Track Fortifying The Supply Chain - Aravind Parappil & Vinod AnandanAI and API Security PanelOWASP AIBOM: Pioneering AI Transparency Through Community-Driven StandardsUsing an Application Performance Monitoring (APM) Environment for Security InsightsPrivacy by Design: What Are Engineers Supposed to Do With That?SBOMs in the Real World: Practical Guidance for Managing Three Common SBOM Scenarios
OWASP Foundation |

Threat Modeling Developer Behaviour: The Psychology of Bad Code

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER