Simon Gibbs & Devika Gibbs -- Building Bridges with Games
with Devika Gibbs and Simon Gibbs
on Threat Modeling and Security Testing
Audio hosted by Buzzsprout. Nothing loads until you press play.
Simon and Devika Gibbs, the innovative minds behind Cybersec Games, join us on the episode today. Discover how the Gibbs duo are revolutionizing the way we teach and learn security concepts through interactive gaming. Learn about their journey from developing stationary for agile teams to delving into the world of threat modeling games like Elevation of Privilege. We talk about the power of gamification in cybersecurity education, and get the inside scoop on their Cybersecurity Game Challenge, which invites creative minds to bring their game ideas to life.
Mentioned in this episode
- Cybersec Gamescybersecgames.com
- Cybersecurity Game Challengecybersecgames.com
- Elevation of Privilegeowasp.org
- OWASP Cornucopiaowasp.org
- OWASP Cornucopiacornucopia.owasp.org
- Threat Modeling Manifestothreatmodelingmanifesto.org
- Adam Shostackadam.shostack.org
- EU Cyber Resilience Actdigital-strategy.ec.europa.eu
Enjoyed this one? Get Reasonable AppSec, the newsletter with new episodes and picks from the archive.
Transcript
5,491 words · assemblyai
0:00Chris RomeoSimon and Devika Gibbs, the creative duo behind CyberSec Games, are transforming how we teach and learn security concepts. Simon Gibbs is a code wrangler and engineer with over 20 years of development experience spanning startups to corporates. Devika Gibbs is a finance strategist and problem solver. As a qualified accountant, she's led high-stakes projects, handled market-sensitive communications, and fixed tangled international operations, always bringing calm clarity to complex challenges. Together, this dynamic pair started their journey creating stationery for development teams, but discovered their true calling when they stumbled upon Adam Szostak's Elevation of Privilege, a colorful security game that completely changed their direction. Now, through their sister brand, CyberSec Games, they're helping thousands of people learn threat modeling and security concepts through engaging, hands-on gameplay. Today, we'll explore how games can bridge the gap between security teams and developers, why the cybersecurity community has been so welcoming to newcomers with fresh ideas, is and their new Cybersecurity Game Challenge, an opportunity to have your game idea transformed into a real physical product.
1:05Today's episode is brought to you by Security Journey. Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10. Learn more at securityjourney.com.
1:19Chris RomeoHey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I am a VP at Security Compass and a general partner at Curve Ventures, joined as always by the world traveler, Robert Hurlbut, who appears to be back in front of his slightly tannish-colored wall.
1:48Yes.
1:51Chris RomeoHey, Chris. Yeah, Robert Hurlbut, and, uh, principal product security architect and threat modeling trainer with Torion. And yes, back from some travel doing training, uh, at the different conferences in different places. So yes, great to be back. How many words are in your title, by the way? A lot.
2:10Yeah.
2:11Chris RomeoI don't know. I can count them. It's like a, it's like a mouthful. It's like a paragraph. Yeah, I think 7. In my head, it's, uh, about 7. Oh, it's all good. It's all good. Well, super excited to be joined by, uh, Simon and Devika here today. But I'm gonna let them explain who they are, where they're coming from, and then we'll let them set the stage. So, Devika, coming to you first for an origin story, help us understand kind of where you're coming from. Okay.
2:39Well, I come from quite a non-security background. I spent majority of my career working as a business analyst for banks. Which I have to say was fun to some extent, creative. I got to work on projects to some extent. I am a big fan of efficiency, and that it was not. I spent a lot of time working on projects, but always felt there was a better way to do this. And then Simon once one day came up with the, uh, with an idea to, to start something where we could create stuff, and I jumped on the opportunity and, um, left my corporate world and started my own business making, to start with, stationery for professionals. Um, I won't go as far as where we are now, so I'll let Simon introduce himself, and then I'm sure we'll, we'll cross paths.
3:40Right. Yeah. So I've been an engineer, mostly Java coding, server-side, REST APIs, front-end, bit of database since really, I guess I started 2002. It's been a while now. And so the idea that sort of kicked us off was, But back in the day when we had physical offices and we were clustering around whiteboards full of stationery twice every morning, not more often, looking at the state of the world in terms of the state of our work, we'd just notice how scruffy it looked. And people seem to actually care about the state of their physical whiteboard. So, we We started making stationery for running agile development teams with tidier stationery. The idea was that, hey, if we can get people to switch from spending loads of money on, you know, this thing that's not very good and doesn't look very tidy to something slightly tidier, we'll make loads of money because everyone's buying those all day. People weren't necessarily persuaded, but we got into card games. Planning poker was a big one. That's a big estimation tool for agile teams. And then started doing events, started doing sort of in-person shopping. And one day when we wanted something more colorful on the stand, we went and we found Adam Showstack's Elevation of Privilege, and we thought, hey, why don't we try this colorful security game? And it sort of took us in another new direction completely. So we started doing a whole load of games. more threat modeling games. Um, and then, uh, that just started to sort of take over and then David had this big idea at the beginning of the year to change things up a bit.
5:36Chris RomeoAnd so you actually, you actually printed a, um, had a, had a version of the Threat Modeling Manifesto as well, right?
5:46Yeah, we've done posters. Yeah.
5:48Yeah.
5:49Nice. Cool. Yeah, we started doing lots of things in security, and we felt like something I was saying earlier, we felt we needed a space of its own. And it was the start of the year that we launched our sister brand, as we'd like to call it, called Cyberside Games. And that's where our kind of focus is now to lift it off and just go deep in this space, which so far has not, you know, it's, it's not, it's, it's just been a lot to explore and do. So, yeah, it's been exciting in this space.
6:27Chris RomeoOkay. And so now I'm curious, you, you mentioned CyberSec games. Gamification's been a, a kind of a passion of mine for the last couple of decades. So what are we talking about here when we say games? What's that word mean from the context of what we're discussing today?
6:48We don't mind what it means. So, we know that some people can be quite precious about the idea of playing a game in the office, and they don't see that as appealing because it seems somehow unserious. We think estimation poker is a game, right? And that is a routine, a ritual that produces an artifact, an outcome. Which is an estimate, right? So, um, it's a little bit gamey. Um, you have that simultaneous reveal of information in it. Um, but, um, in terms of what games are actually talking about, we, we stock all the variants of modeling games, um, educational games, fun games, um, some of which are just purely gameplay, others are more outcome-focused, elevation of privilege. OWASP Cornucopia are more, I like to compare them to, like, training wheels for threat modeling. It's not necessarily, like, the best way to ride a bike, but it actually gets you somewhere, right? Gets you—
7:52Yeah.
7:52But if you threat model a real system with OWASP Cornucopia, you'll learn stuff about a real system that you can go ahead and use. Yeah, it's true.
8:04Chris RomeoAnd it's not necessarily how you want to be doing it at scale with 10,000 people, but it's a great way to introduce the idea, to learn it. It's a fun approach to it versus just having somebody lecture to you for a period of time about here's what you're going to do. Being able to be involved in the game is, you know, as human beings, we like to play games. Like we play games from the time we're small, just as soon as we can start moving around on our own, we're playing games. all the way up to, I believe that people still like to play games, you know, as long as they're on this earth.
8:38Yeah. And I think when I look at games, I see them as tools where people, first of all, get together. And you could argue, well, they get together in a meeting, they can, or workshop, and, you know, they'll be together. So why use games? I think games not only get people together, But they engage people in a very different way. You do start feeling relaxed. You have maybe not a lot of fun, but some fun. Just the idea will help relax people. And yeah, games like Elevation of Privilege might not be able to, you know, I think, introduce threat modeling at, you know, at such a large scale. But we've had customers who when they were trying to implement threat modeling at scale, but at a basic level within the development team, they went for a game because they felt that that was a far easier way to implement threat modeling at a basic level at scale and get teams getting self-sufficient to just think about threat modeling rather than having a centralized team to work with people at scale. They felt that was a harder job. So, I think at a basic level, I think it ticks a lot of boxes. And yeah, I think for me, that's like a great game that we obviously sell and ticks a lot of boxes, yeah.
10:04The keyword in that for me is developers, right? So, there's what, 5 million security people and there's like 38 million developers. Like, you're not gonna get around all of them. So, if you've got something that's reasonably structured, that helps you draw people in, helps them get involved, you are actually scaling your community to actually engage with another community that it has to engage with to get it done. Because, you know, developers are producing insecure code all day, but they try their best. We try our best, but they are certainly at risk of introducing—
10:41Yeah.
10:42a defect at any time, right? And the more you engage with them, the more you get around them. And you get around each of them and engage them and enable them to spot the common mistakes, they're gonna catch it earlier. They're gonna catch it before they actually have to, you know, write the wrong code, right? And so, it's that shift-left thing where, you know, you hope for You know, more efficiency, better outcomes, just a more predictable plan.
11:13Chris RomeoSo either of you can answer, how have you been welcomed in the community? What have you seen so far?
11:22Do you want to start, Lynn? I don't know where to start.
11:35So, obviously, it can be pretty intimidating coming into cybersecurity. So, from an engineering standpoint, cybersecurity is, it's got its own separate language, it's got its own separate norms, red teams, blue teams, purple teams, sort of bewildering. And you think that, well, are people going to sort of take us seriously as, you know, one engineer and one BA turning up and and trying to help and support best we can, you know, really deeply expert security folks, you know, with games, right? It's intimidating.
12:14But actually— We didn't come with a network, by the way. We honestly, I think this is one thing I look back on and think we started a business, Simon, right? You know, most people start businesses with a kind of strong network in place because they know with this network they'll be able to, get where they want to get. We generally— some I've noticed, we come in with an idea, which is probably one of the biggest things you shouldn't do when you start your own business. It's a mixture of things you should have in place. But we're just— we get passionate and creative about our ideas and that's what we do. So we literally came in without this kind of, you know, without having a strong security network.
12:51Chris RomeoAnd Yeah.
12:55Kieran's hand.
12:55Yeah.
12:56So, we're very much newcomers, outsiders, like, hey, we've got some cool ideas how we can help. Do you mind? And yeah, people have been pretty open to it. I think one of the reasons why, like, the attention of the business, if you like, has sort of slowly sort of focused more and more on security is because actually you're pretty faithful folks to start with, right? You all seem About a third of you are probably D&D fans. You all seem to be.
13:23Chris RomeoProbably a higher percentage have played D&D at some point in their life, right? Like probably above, probably north of 50%, I would guess.
13:32And it just seems to be that sort of really creative open space for play and sort of nerdy pursuits. How can we fix this system with pieces of paper? It's actually quite surprising how engaged the cybersecurity community was already with these ideas. In terms of the industries we work with, so we do a lot of, like, facilitators and agile coaches and stuff. They don't invent as much in terms of productized games as the cybersecurity community does. In terms of building cybersecurity products, there's more coming out of them. of gaming products. There's more coming out of this industry than others. Um, you know, you could say maybe they're doing more ad hoc games, don't get formalized into products. They're maybe taking a different angle on it. Whatever angle's being taken, it's just been so open and welcoming to us.
14:34Chris RomeoAnd, um, glad to hear that. Glad to hear that the community has, uh, has opened their arms and kind of welcomed you in, because that's, uh, that's the type of community we want to be a part of. We don't want to be a place— and, and the— I know you've, you've been around the OWASP community for quite a while as well, and OWASP is just very open to welcoming, uh, new ideas, new people. It's, it's one of the, one of the best spaces that's out there. So, um, Simon, you mentioned security and development a little bit, and I know you've, you've admitted that you have some development experience here, you lumped your— you quickly lumped yourself in that 38 million, into that, in the developer kind of pool. I mean, what's been your experience in the relationship between security and development?
15:23Well, I don't think I've ever met a security person in the office. I've been working in software engineering for 20 years plus. The first time I met a pen tester was in San Francisco at an event. Doesn't mean I didn't deal with them. May have had phone conversation with one once. I've seen some pen test reports. It's a really, really distant relationship. Certainly that pen tester field. It really couldn't be more arm's length. It's quite odd because it's such an important concern, increasingly so. But in terms of actually getting together and engaging with security, as in the security function engaging with the development function, doesn't happen very often. And when it does happen, it's, you know, someone rings your manager and says, hey, you can't release that yet because there's some red flags on the pen test. And that, you know, naturally leads to antagonistic relationships, should we say? Because you've got someone that you've probably never met, haven't had very close dealings with, suddenly saying that, you know, the feature that you've sweated Blood and tears to get out. You know, it can't go live yet while it's ready. And often developers will feel that, you know, they've thought about security, they've done their best, they know their best practices, they know how to insert a parameter into a query, they know how to do input validation sometimes. But then, you know, the security team turn up and they nix it.
17:18Yeah.
17:18So it can be quite a frustrating, distant relationship. So, you know, that's one of the reasons why we like to sort of support that relationship with games, because actually getting around a whiteboard before you make the thing and saying, hey, this is what my expectations are gonna be, this is what we're gonna find.
17:41Chris RomeoYeah.
17:44This is what we want you to address as you build this thing. That's a much better relationship, right? That's, yeah, that's where we want, that's how we prefer to be engaged than just receiving a report. So I don't know why it doesn't happen more often.
18:00Chris RomeoSo curious about, you mentioned earlier, I think, Simon, you saw or played Elevation of Privilege? What, what happened when you, I think maybe when you first looked at that?
18:14Um, yeah, so, um, I was working on a, um, CMS project and, um, we realized that we hadn't really done very much security analysis on it. Obviously, I have an interest in the game and, um, the team were open to, to trying it. So indeed we sat down and tried it, but I think we, we played it a couple of times. I think I learned very quickly that as a facilitator of one of these games, you need to shut up. So very early in the first session, I understood something about the system that actually, as it turns out, didn't turn, turn out not to be true.
19:03Right.
19:03But I'd diverted people down that route, pushed them towards finding a bunch of threats that later we had to throw away. So that was a bit of a shame, but you learn very quickly to not do that, to lead more from the back of the room and let people find their own space that they want to explore.
19:23Right.
19:26Second time, we did a lot better. We were finding, actually, an interesting stat from that second session is we found a defect every 90 seconds.
19:35Chris RomeoTalk about return on investment right there. Holy cow.
19:39Yeah, I mean, you can, you can argue that some of those weren't very useful, because maybe it was the same one in 5 different components, and this one in 7 different components, or whatever. That's not necessarily the most useful bit of threat modeling. But Each of those is a task that you've gotta consider, or a line item on a Jira ticket somewhere. So, it felt very productive. It felt like useful output. And then, yeah, we were able to take those forward and prioritize it. Unfortunately, we were in a team where we didn't necessarily— there's this thing that happens to software engineering teams, right? And I think it might be useful for the community to understand this. We get a lot of input from lots of different stakeholders, right? And the usual thing that people want is features, features, features, features. So, there's an anti-pattern of team workflows called the feature factory team. They're just sitting there churning through Jira tickets, working on features all day, and they're not given the space in their schedule to address sort of non-functional needs. So, things like data being shuffled between 2 systems all day for no reason. That's the kind of thing that drives me mad, because it's, you know, you're wasting electricity, if nothing else, right? Just moving data forward and backwards. I spent 2 years at a place where that was happening. wasn't able to fix it because there wasn't like a swim lane through the workflow to actually make those things happen.
21:19I agree.
21:19And unfortunately, where we played, we didn't have that sort of swim lane. So, from my own experiences, you know, I've learned it's not necessarily easy. It's easy to find the work, not necessarily as easy to make sure it's the right work or get the work done. And I think that applies probably equally to pen testing, and it did apply equally to pen testing. We had feedback like, you know, we need to upgrade our jQuery to the next version, which sat on our backlog for a year, simply because, you know, the way the work was organized was we were pursuing features, we were laser-focused, and you know, you're under constant pressure to conscientiously focus. Development teams thrive on focus. It's a mix of attention, but the less you can do at once, the better. So, whether it was a card game or a pen test report, you know, these security things ultimately didn't get done, which was a shame. But what I did see was a team that, rattled out a whole load of threat reports, did their own analysis, did their own security analysis of the system, had fun doing it, and learned a whole lot about security that they didn't know before. So, a step in the right direction.
22:44Yeah.
22:45Chris RomeoSo, how popular then, I've always wondered this, because I saw elevation of privilege many, many years ago. Microsoft printed them and gave them out at a conference. Probably 2 decades. Yeah, maybe not quite 2 decades ago, but maybe a decade and a half ago is probably when I got it. So I have a copy still sitting on my, uh, my kind of shelves at home of one of the— it's the original, one of the original kind of decks. But how popular is this across the industry? I've never really had anybody that I could ask that question of, but I feel like I have the right folks here. Cool.
23:24So we know that we're helping thousands of people. you know, every year, one way or another, supporting a game.
23:32So, I think we estimated around probably 10,000 users in the last year.
23:39Wow.
23:40Of the elevation of this. This is just the elevation of privilege. Remember, we've had variations come in by other experts, and that's just been another wave of kind of interest, especially OWASP Cornucopia with the web and mobile app editions. And again, just the frequent updates and everything. So there is a very active community at the moment producing some really good quality work, and we get to make and set. So yeah, it's quite exciting in this space.
24:14Yeah.
24:14Chris RomeoIt's great to know. Yeah, especially I've used it for training and, you know, so we always had a smaller group to play the games, but to know it's having that wider expanse and number of customers is fantastic to hear.
24:33And also through universities. So that's been another kind of experience over the last couple of years. We've had at least a couple of universities who've come to us because they added threat modeling now basically in their security courses. So they're taking a threat-based approach and using the STRIDE or STRIPED framework to teach, to spot vulnerabilities with their students. So universities has been a new addition. Security consultants, as you were saying, organizations, where, who are especially EU with the Cyber Resilience Act, they're looking for embedded product security now. And they find the game as a, as a, again, again, I think Chris, you were saying, you know, you can't use the game to roll out security at scale, but it's a, it's a good first step for people to get their teams into the mindset. Yeah. So, so these are the kind of interests we get on a fairly regular basis now, which is Which is really good.
25:38Chris RomeoYeah, I would say if anybody listening is involved in academia and teaching cybersecurity at all, this is the tool you should bring to your classroom. Because once again, everybody likes playing games, but it's just a way to experience the threat modeling process and take— and I believe people are going to remember it better if they have a hands-on experience with a game. It just, it makes your brain just remembers those things differently than if you listen to somebody talk for 30 minutes. And so academic folks need to embrace this far and wide because it's just, it's a great tool for them.
26:14Yeah. Okay.
26:17Yeah.
26:21Chris RomeoWhat's the Cybersecurity Game Challenge? Could you talk, talk to us through, talk us through that?
26:29Deepika, I'll start with you.
26:30Yeah, sure. So yeah, the Cybersecurity Game Challenge is something we, we've been thinking about for, for a long time, but we haven't quite approached it the way we have now with this full challenge in place. Over the last few, I would say easily years, we've come across people who, who had an idea, but then they also have full-time jobs. And I'm actually clear, they had an idea for a cybersecurity theme. the game, but they have their full-time jobs. So I would follow up with them and say, how did it go? Can we help in any way? And never really had a kind of structured, kind of organized way to kind of help them proceed with it, to complete it, to put it together. But we know there's no shortage of ideas out there. Like Sam was saying, this community is very creative and we know it. So we thought to ourselves, well, how can we get this community, take them a step further in taking their idea and turning it into a product? And by the way, just to mention from— we should have mentioned from the start, but we are all about physical games. We like digital games, but we believe that physical games is the best way to do it. If you want to engage people, if you want to let people have fun and just have a good experience, physical games is the way to go. So yes, this challenge is an invitation to people out there who have an idea, and that's all we're looking for, just an idea, and want to take it to the next step. Enter the challenge. 3 questions: What's your idea? What, what, what does it help? How do you play it? What are the gameplay, the components, and how do— does the gameplay and the idea itself work together to achieve the cybersecurity outcome that you want to achieve? We have a great panel of judges. Simon, do you want to introduce the judges? It's, it's, it's a list. I'll go.
28:43Johan Sodesta, who's involved with the OWASP Cornucopia project. Stanley Harris, storyteller and D&D geek who brings that into his work with Security Champions. Klaus Agnoletti, who basically is creating sort of D&D-style scenarios to simulate cybersecurity work. Someone called Devika, who's going to— what are you doing on the panel?
29:19I've got the manufacturing panel. I'm there to make sure that things don't get out of hand.
29:26With Kerry Newton-Seguna. So, Kerry is another outsider. She's the outside, non-security Field judge. She's an expert in organizational archaeology, helping people communicate better, helping people to understand basically how they're really working, how to achieve their— communicate what they really want and get what they want at an organizational level. And she's an expert in neuroscience and a big advocate for using play to teach ways of working and other things. And Adam Szostak, who sort of started the whole thing, formalized threat modeling, formalized the CVE, and is the grandfather of sort of half our range, actually. The OP, the AI variants, all of that, they're all basically variants.
30:33Chris RomeoSo I guess in my mind, the most important question, what can I win? What is, what is the, is there a trophy? Is there a ceremony? Like what happens if I have the best idea?
30:46Well, I think we can beat all that because who needs a trophy when you can get your product made from an idea to an actual physical product. So the prize, Chris, is that your idea gets turned into a— to start with, a professionally developed prototype, a finished product, and then you have the opportunity to list it for sale on our platform with royalties on every sale. So essentially, we're gonna pay to to create your idea. And in addition to that, we are also saying that the top 5 entries will get feedback, will get the formal feedback from the judges, their scores, and a special mention from us, and also an opportunity, hopefully, to work in the future to develop their ideas. We want to find the next kind of wave of games. We want to see what's out there, what people want, and be— and we're just— it's great to have all these judges in place to help us in that journey, to give their feedback, which I think will be crucial to find the best game.
32:04Chris RomeoI see a future reality show.
32:09A reality show?
32:11I don't know.
32:12Chris RomeoI, I can see, I don't know which, which judge would Adam be. He's not Simon Cowell, 'cause he's way too nice. That's why I like him. He would never yell at anybody or anything in the judging process. We gotta figure out who he's, who he would be. Um, but this is exciting. I think it's an opportunity for folks that have some type of an idea to, uh, to, to put it up, get some feedback, and potentially even see it turned into an actual product. And we need more games in cybersecurity. Just the fact that it's a way to break down the complicated things that we do. It's a way to teach others and provide experiential things for people to really push their knowledge and their understanding of the discipline further. So it's just something that we need to do. So I guess what's a key takeaway? Perhaps a deadline could be part of our key takeaway here. Like, do I have forever? Can I just— submit in 10 years or what's my deadline here?
33:09I think, let's see now, because I put out a post the other day saying there's 35 days left.
33:16Oh, you can't, you can't.
33:1733 days left now. So it's the 10th of October.
33:20Taking us to a date real fast. We're gonna have to get this out, edit it, out the door straight away.
33:25Chris RomeoYeah, 10th. So 10th of October is the submission deadline for folks.
33:28So that's right.
33:29Chris RomeoOkay, so they gotta get their ideas in. How long do you think it'll take to To fill, like, what, what are, what's trying to set this up for our audience that this is not something that's gonna take them weeks of work to, uh, to be a part of this. So like, what do you, what do you think the, if I already had an idea in my head, how much time do you think it would take me to submit it in the process you have?
33:49I would estimate, given off, there is a form online. Um, I would estimate about an hour.
33:56Okay.
33:59Chris RomeoSo pretty quick.
34:00Yeah, pretty quick. It literally is just the, you know, it's kind of the theory that we want from you. What is the idea you have? And we need a kind of overview of how it works. What are the components? You know, if you can. And also we're saying that, you know, if you don't want to, if you don't want to write this up, just send us a video. Send us a video just answering those questions.
34:21Chris RomeoOkay.
34:22And that will be considered. That's absolutely fine. So I think an hour, you know, just share the idea. And remember, this is not— once you submit it, that's not the end of it. You know, we will come back to you. We will— if we want more questions to be answered or any questions to be answered in more detail, we'll come back to you.
34:41Chris RomeoSo, okay.
34:42Yes, we'll work with you on this one.
34:44Chris RomeoVery cool.
34:45It's a hard word count limit, 2,000 words. 4 sides as a hard limit. No one's gonna write that. Yeah, probably get away with a quarter. You do need to draw a picture or do a video presentation. Okay.
35:05Chris RomeoWell, this is—
35:05Right.
35:06You just talk to a camera if you want.
35:07Chris RomeoThis is an exciting opportunity. So I think I'll choose the homework assignment. Normally we let the guests choose the homework assignment for our audience, but I'll choose it for today. And that is, Get your idea out there, submit it into the Cyber Security Game Challenge, and let's let's see you become the next game creator inside of the world of cybersecurity. So Simon Devika, thank you for for joining us on the show, for sharing this. Thank you for all the work you're doing in getting these games out to the community. I think it's it's an important part of the way we teach more people, especially as we bring more people into our industry. We need easier. better ways to ramp them up and teach them some of these principles. And like I said, games are a fun thing. Everybody likes games. So thanks for all you're doing and thanks for bringing this opportunity to us.
35:59Thank you.
36:00Thank you for having us, Chris and Rob.
More on Threat Modeling
- Abhay Bhargav -- Threat Modeling as Code
Abhay Bhargav joins Robert to talk about threat modeling as code. He dives into how this can help you in your threat models.
- Chris and Robert -- The Activities of the Secure Development Lifecycle
On this episode of the Application Security PodCast, we continue our journey through the foundations of application security. We explore the activities of the secure development life cycle.
- Jason Nelson -- Three Pillars of Threat Modeling Success: Consistency, Repeatability, and Efficacy
Jason Nelson, an accomplished expert in information security management, joins Chris to share insights on establishing successful threat modeling programs…