Loading…
This event has ended. Visit the official site or create your own event on Sched.
It is an annual, community-driven information security conference held in Prague. The event provides a platform for cybersecurity professionals, enthusiasts, and researchers to share knowledge, exchange ideas, and discuss the latest trends in the field. It’s a unique opportunity to connect with like-minded individuals, expand professional networks, and stay informed about the ever-evolving cybersecurity landscape.
More info at www.bsidesprg.cz

Wednesday April 22, 2026 13:00 - 17:00 CEST
No more drowning in checklists! Change “we should probably be more secure” into an actual, risk-prioritized engineering backlog. In this hands-on workshop you’ll learn to threat model systems using STRIDE + data-flow diagrams. You'll leave with a repeatable approach you can drop into product work.

No more drowning in checklists! Change “we should probably be more secure” into an actual, risk-prioritized engineering backlog. In this hands-on workshop you’ll learn to threat model systems using STRIDE + data-flow diagrams. You'll leave with a repeatable approach you can drop into product work.

What we’ll do
Working in small groups, we’ll threat model a software system end-to-end:
  • sketch a data-flow diagram (DFD) and identify trust boundaries
  • apply STRIDE to systematically enumerate threatsprioritize threats by risk, focusing on what matters most
  • turn results into a well-scoped mitigation backlog
  • identify reusable security patterns you can apply elsewhere

What you’ll learn / take home
  • A repeatable workflow for running a threat modeling session with your team
  • How to spend more effort on high-impact risks (and less on low-value busywork) without losing the plot with auditors
  • A set of “next actions” you can implement immediately: mitigations, logging/monitoring hooks, and design changes expressed as backlog items

Who it’s for
  • Developers/engineers who own services in production
  • Security champions embedded in product teams
  • Architects / tech leads responsible for system design

Prerequisites & logistics
No special tools required: either bring pen and paper for diagrams or laptop with a lightweight drawing tool. Basic familiarity with software architecture helps, but you don’t need prior threat modeling experience.






Speakers
Wednesday April 22, 2026 13:00 - 17:00 CEST
Novotel - WR2 Kateřinská 38, Nové Město, 120 00 Praha-Praha 2, Czechia

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Share Modal

Share this link via

Or copy link