Threat modelling is taking on new importance as AI threats increase
Threat modelling is hardly new for organisations with a mature, defence-in-depth approach to cybersecurity. It has long been a cornerstone of preventative security, helping businesses identify and address weaknesses before they can be exploited.
For security teams, the value lies in moving from reacting to incidents to anticipating them. Closing off potential attack paths before they can be exploited can reduce exposure, limit the impact of an intrusion and strengthen the resilience of an organisation’s technology estate.
The rapid adoption of AI-assisted coding, however, is changing the equation. While AI is promising significant gains in software development productivity, it is also introducing new attack vectors and expanding the enterprise attack surface, thereby creating a fresh set of challenges for security and engineering leaders.
However, when leveraged by a security-proficient expert, AI technology can also be a very powerful asset for enhancing and accelerating threat modelling. Developers have long struggled to truly claim a seat at the table in traditional threat modelling programs, but with the right skills, they have the opportunity to wield AI responsibly to seriously cut risk and rework in their codebase.
Current shortfalls
Threat modelling has traditionally existed in the realm of security professionals. It’s always been their job to predict the many ways threat actors can enter a network or compromise software.
More recently, suites of automated scanners and tools designed to spot hundreds or even thousands of potential vulnerabilities have entered the picture and supplemented security teams’ personal knowledge. Once vulnerabilities were found, security teams would typically rely on developers to fix programs and applications, especially if a vulnerability was deemed critical or dangerous.
This relationship tended to cultivate an unhelpful ‘us versus them’ mentality between developers and AppSec professionals, but the results remained impressive for a long time. It may not have been terribly efficient, but the ends often justified the means.
While this approach might have been successful in the past, the evolving threat landscape is making traditional threat modelling practices increasingly unworkable in a modern software development ecosystem.
Developers have been brought on the threat modelling journey in some enterprise environments, sometimes working side-by-side with their AppSec counterparts. This is a productive partnership, as developers know their code best and, if they are security-aware, they are well-positioned to identify potential security weaknesses that could be exploited.
Even now, this set-up is relatively rare, and many companies do not engage the development cohort for these activities. The primary reasons tend to vary, but generally, it comes down to a combination of:
- Inadequate security awareness: Unfortunately, many developers do not have the knowledge, tools or skills required to assist in threat modelling.
- Manual processes: Even if a senior, security-skilled developer is the right person for the job, traditional threat modelling processes are tedious, manual and rarely integrate well into a development workflow.
- Outdated tools: It’s a harsh reality that by the time a threat model is completed, it is likely already outdated. Static threat models tend to have limited value in enterprise environments for this reason.
Defence evolution
We’ve reached a point where the threat landscape is now far more dangerous than it has ever been.
Bots are everywhere and they can probe millions of networks for vulnerabilities in the blink of an eye.
Modern threat modelling takes a more holistic, developer-focused approach and it is made far more seamless with the right AI tooling. It’s clear that AppSec teams can’t keep up with threats from ground zero anymore. Rather, security experts are increasingly recommending that we need to shift threat modelling away from the beachheads of our production environments and back into the development process.
This gets to the core of what threat modelling was supposed to do in the first place: preventing threats from even launching by not giving attackers any leverage to work.
Putting AI to work
A new threat-modelling collaboration effort might not happen overnight and it will require small steps at first. It might start with group meetings, ideally involving security awareness personnel. Once that is accomplished and developers and AppSec professionals see and respect each other as equal and supportive colleagues, they can move into more advanced threat modelling tactics, assisted by approved AI tools.
Insights from HackerOne’s (2025) Hacker-Powered Security Report reveal that 67% of security researchers already leverage LLMs in their threat modelling, yet according to ISC2’s (2025) AI Pulse Survey, only 7% of companies use them frequently for this purpose, despite their significant potential.
It’s crucial to understand that AI cannot — and should not — replace human intuition. However, it’s equally important to recognise that its integration into the threat modelling process serves as a powerful catalyst for modern development.
By augmenting human empathy with machine precision, teams can secure their codebases at scale, ensuring that efficiency and security are no longer at odds, but are instead the foundational pillars of a streamlined workflow.
Australian employees are losing half their week to admin
Research by Workday has shown that roughly 30% of ANZ employees now lose more than seven hours a...
Visibility versus value: what are you really trying to buy?
Withn CRM systems it is crucial to understand that visibility itself doesn't improve the...
The risk of letting GenAI define the future of AI
Conflating GenAI with the much broader discipline of artificial intelligence puts the effective...
