Software and Data systems in most people’s companies are complicated and tend to grow organically. This organic growth can make it difficult to know what/where/how your assets need protecting. Come join me for a cup of coffee while I share the strategies I use through stories from the field on how to help you threat model your environment and take a proactive step to breach protection.
Problem to be Solved: How do I know what to protect?
Solution: Have coffee with your managers and use three simple question to threat model the assets they control.
Delivery: Sharing three stories from my work as a SOC manager, Analyst and Threat Hunter as examples of why to threat model, and how easy it can be.
The Stories:
a. Third Party Vendor Compromise
a. Unpatched Servers.
a. Ransomware and mystery assets.