Join us for two action-packed days of practitioner-led talks, peer discussions, networking, and game sessions that bring Threat Modeling to life!

Agenda

Take a look at our action packed agenda for the weekend, we've expanded the available options this year, for some session slot, you have the choice between hearing from experts or games and workshops, if getting interactive is more your thing. Whatever floats your boat, we've got you covered.

Friday

May 30

Time
Session
Speaker
Location
Type
6:00 PM
Sunset Cruise Reception
On a boat!
Networking

Saturday

May 31

Click on a session name to find out more...

Time
Session
Speaker
Location
Type
8:00 AM
Registration & Coffee
9:15 AM
Jim Manico
Room Sagrada Familia
🎤 Keynote
10:00 AM
Adam Shostack
Room Sagrada Familia
🎤 Expert talk
10:00 AM
Karim El-Melhaoui
Håkon Nikolai Stange Sørum
Room Barcelona
🎤 Expert talk
10:35 AM
Group photo
10:45 AM
Coffee Break
11:20 AM
Kim Wuyts
Avi Douglen
Room Barcelona
💡 Workshop
11:20 AM
Rob van der Veer
Room Sagrada Familia
🎤 Expert talk
12:00 PM
James Rabe
Room Sagrada Familia
🎤 Expert talk
12:30 PM
Lunch - Find My Tribes
1:30 PM
Simone Onofri
Room Sagrada Familia
⚡ Lightning talk
1:40 PM
Dimitri Van Landuyt
Room Sagrada Familia
⚡ Lightning talk
1:50 PM
Anthony Phipps
Room Sagrada Familia
⚡ Lightning talk
2:10 PM
Stanley Harris
Room Sagrada Familia
⚡ Lightning talk
2:45 PM
Coffee Break
3:20 PM
Kelly Kaoudis
Room Sagrada Familia
🎤 Expert talk
3:20 PM
TMC Community Leaders
Room Barcelona
🎉 Showcase
4:00 PM
Dinis Cruz
Room Sagrada Familia
🎤 Keynote
4:20 PM
Room Sagrada Familia

Early bird ticket you say? Book now!

Got you feeling inspired? Stoked your curiosity? Lit the threat modeling fire in your belly?!

The early bird catches the Threat Mod Con ticket... Grab yours by April 15th to take advantage of the early price.

Speakers

Gain invaluable insights from top industry experts, seasoned practitioners, and thought leaders in threat modeling across technology, security consulting, academia, and beyond. Explore cutting-edge trends, delve into real-world case studies, and discover how these experts have empowered organizations to advance their threat modeling capabilities.

Keynote Speakers
Dinis Cruz
Founder & CEO, The Cyber Boardroom

Dinis Cruz is the Chief Scientist of Glasswall and the founder of The Cyber Boardroom startup, who brings a unique blend of Security and Engineering expertise with 20+ years experience in Cyber Security and Software Development. Dinis is focused on creating Gen AI powered teams and environments where engineering and security are enablers and accelerators for the business, with a big focus on the productisation and commercialisation of advanced technologies.

Jim Manico
Founder & CEO, Manicode Security

Jim Manico is the Founder of Manicode Security, a company dedicated to providing expert training in secure coding and security engineering to software developers. In addition to leading Manicode, Jim is actively involved in the tech startup ecosystem as an investor and advisor. Jim is committed to giving back to the community through his volunteer work with the OWASP foundation. He co-leads projects such as the OWASP Application Security Verification Standard and the OWASP Cheatsheet Series.

Speakers
Isabel Barberá
AI Advisor, Privacy Engineer & Co-founder, Rhite

Isabel Barberá is the author of PLOT4ai. She is also one of the members of ENISA Working Group on Data Protection Engineering and a National Expert at ISO/CEN/CENELEC working on the development of standards related to AI and privacy engineering.

Sebastien Deleersnyder
Co-founder and CTO, Toreon

Sebastien Deleersnyder, CTO and co-founder of Toreon, has a deep cybersecurity background. He has trained many developers in secure coding practices, founded the Belgian OWASP chapter, and contributed significantly to OWASP projects like SAMM. Now, he’s focusing on integrating application security into DevOps and expanding the reach of threat modeling.

Avi Douglen
CEO, Bounce Security/OWASP Board of Directors

AviD is a prominent security architect and developer, with decades of experience building secure products and protecting complex systems. He has been designing, developing, and testing secure applications for over 20 years, and is obsessed with maximizing value output from security efforts, threat modeling in particular.

Karim El-Melhaoui
Principal Security Architect, O3 Cyber / Microsoft Security MVP

Karim is a seasoned and renowned thought leader within cloud security. At O3 Cyber, he conducts research and development and works with our clients, primarily in Financial Industry. Karim has a background in building and operating platform services for security on private and public clouds, developing and executing a cyber security strategy for the world’s largest sovereign wealth fund.

Stanley Harris
CEO and Cofounder, Katilyst

Stanley is the CEO and Cofounder of Katilyst, where he leads initiatives to build and enhance Security Champion programs. An avid MMORPG player since 1999, Stanley leverages his gaming experiences to apply effective gamification techniques in professional settings.

Kelly Kaoudis
Sr Security Engineer - Research, Trail of Bits

Kelly Kaoudis is a senior security engineer in the Research practice at Trail of Bits. She is a tech lead for threat modelling engagements, and contributes to Trail’s academic and industry research projects including open source parser and file formats analysis tooling.

Anthony Phipps
Lead Security Design Consultant, Lloyds Banking Group

Dr Anthony Phipps is a member of the cyber research centre at London Metropolitan University, conducting research into audio based cyber security applications. He is also currently a Lead Design for Lloyds Banking Group, managing a team of security design consultants.

James Rabe
Head of Global Services, IriusRisk

James Rabe is the Head of Global Services at IriusRisk. He is focused on building effective threat modeling programs through pragmatic, lean, and scalable processes. Secure by Design is the outcome and threat modeling is the pathway to get there!

Adam Shostack
President, Shostack Associates

Adam is the author of Threat Modeling: Designing for Security, and Threats: What Every Engineer Should Learn from Star Wars, and the first recipient of the Adam Shostack Award for Threat Modeling.

Elias Brattli Sørensen
Developer & Security Engineer, Kantega SSO

Developer & Security Engineer at Kantega SSO, engineering digital identity standards for secure authentication to the Atlassian ecosystem while facilitating and promoting secure software development practices. Creator of threat modeling game Elevation of MLsec.

Håkon Nikolai Stange Sørum
Principal Security Architect and Partner, O3 Cyber

Håkon has extensive knowledge on implementing secure software development practices for modern teams, designing and implementing cloud security architectures, and securely operating cloud infrastructure. Håkon is a Partner at O3 Cyber, a high-end cyber security advisory for securing the cloud.

Rob van der Veer
Chief AI Officer, Software Improvement Group (SIG)

Rob van der Veer has over 33 years of experience in AI and security, from hacker to CEO. He open sourced international standardization of AI security by establishing the OWASP AI Exchange flagship project, feeding right into the AI Act and ISO standards.

Dimitri Van Landuyt
Associate Professor in Information Systems Engineering, KU Leuven

Dimitri Van Landuyt is Associate Professor in Information Systems Engineering in the Faculty of Economics and Business (FEB) of KU Leuven. Current research focuses on evaluating security and privacy threat modeling methods and tools, and addressing technical, economic risk and legal risk.

Kim Wuyts
Manager, Cyber & Privacy, PwC Belgium

Kim Wuyts is a leading privacy engineering expert with over 15 years of experience in security and privacy. Before joining PwC as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy threat modeling framework. Her mission is to raise privacy awareness and get organizations to embrace privacy engineering best practices.

Simone Onofri
Security Lead, W3C

Simone is the W3C Security Lead. He has 20+ years of expertise in red/blue Teaming and Web security. He has spoken at OWASP, TEDx, and other events and authored Attacking and Exploiting Modern Web Applications.

Join the Conversation

Looking to deepen your understanding of threat modeling? Engage with fellow practitioners, share your experiences, and ask questions in the Threat Modeling Connect forum! It’s a vibrant space where you can collaborate, learn, and grow alongside industry experts and peers.