Let’s Play Harms Modeling Cards, Eliciting Socio-Technical Harms in Age Verification Systems

June 27, 2026
11:20 AM
Golden Wave 2

About this session

Harms modeling complements threat modeling by analyzing the impact of a technology on people's lives (the harms), including potential infringements on human rights. This happens particularly in high-risk socio-technical systems, such as Age Verification Systems. In this hands-on workshop, participants use a new card-based harms modeling game to analyse a real case, elicit harms that traditional threat modeling misses, and integrate them into the final threat model.

About the speaker

About the speakers

Simone is the W3C Security Lead. He has 20+ years of expertise in red/blue Teaming and Web security. He has spoken at OWASP, TEDx, and other events and authored Attacking and Exploiting Modern Web Applications.
Giovanni is a cybersecurity professional specializing in cyber threat intelligence and in threat modeling for security, privacy, and user safety in high-risk systems.
Executive Security Advisor focusing on corporate cyber strategy and security risk advisory, Luca is committed to creating a safe and trusted digital environment to support business growth, protect the brand and customers' information.He brings a broad and different perspective that combines his views across Cyber Security, Corporate Governance, Operational Risk management, and Internal Auditing.

Speaker

Speakers

Simone Onofri
Security Lead, W3C
Giovanni Corti
Cybersecurity Researcher, Fondazione Bruno Kessler
Luca Lumini
Executive Security Advisor