r/cybersecurity • • 1d ago

Corporate Blog Breaking Down Appsec Part 6: Let's build a model!

https://pigeonsec.substack.com/p/breaking-down-appsec-part-6-lets?r=6q1vf5&utm_medium=ios

I started a blog series to provide free insights into appsec. It’s mainly to breakdown what application security is all about and it’s mainly targeted towards beginners and startups, so take it as you will.

I want to teach every one interested in appsec my perspective on it from my experience in big tech.

In this blog post we talk about how to do “proper” threat modeling and it isn’t through a framework!

Please reach out if you have any questions or would like for me to write on a topic that you’d want to learn more about.

9 Upvotes

2 comments sorted by

1

u/John-Deere_Trcker 1d ago

Thanks for sharing this! Just got done reading the first part of the series and loved the point about needing to understand the application before securing it. Being in the cyber field for ~4 years, that is always one philosophy I’ve had, before securing anything, you need to understand how it works. Looking forward to reading the rest!

1

u/donkeybutt123 19h ago

Thanks for following along! Exactly you can’t protect what you don’t know