Hidden Risks of Customizing Threat Modeling Tools

June 27, 2026
3:45 PM
Golden Wave 1

About this session

Embedding fast-evolving internal security requirements directly into commercial threat modeling tools can create hidden governance and temporal consistency risks. This session presents a real case of scaling a customized tool with hundreds of company-specific rules. While it unified compliance and reporting, it caused structural inconsistencies over time, requiring rollback. Learn how to assess sustainability, detect temporal coupling, and balance functionality with governance stability.

About the speaker

About the speakers

Ivica works as a security domain expert providing the product teams guidelines to security architecture and design, primarily supporting threat modeling.Previously pentester, system engineer, occasional security researcher. Formal education: BSC in Electrical Engineering and Computing, MBA, MSc in computer forensics.

Speaker

Speakers

Ivica Stipovic
Security Enablement and Architecture, Raiffeisen Bank International