# When to Threat Model

DevFeed: [When to Threat Model](<https://devfeed.tech/articles/when-to-threat-model-37121.md>)

Original publisher: [Read original article](<https://shostack.org/blog/when-to-threat-model/>)

Author: Adam

Published: 2020-08-12T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [.NET Conf](<https://devfeed.tech/topics/net-conf.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [defcon](<https://devfeed.tech/tags/defcon.md>), [supply-chain](<https://devfeed.tech/tags/supply-chain.md>), [talk](<https://devfeed.tech/tags/talk.md>)

## AI overview

The article discusses when organizations should perform threat modeling. It notes that practices such as doing it every sprint or aligning it with waterfall development are not universal, particularly when considering software supply chains, and highlights organizational discipline factors from a Biohacking Village talk at DefCon.

## Source excerpt

A talk from the Biohacking Village at DefCon brought up a good point.