Technical Depth. Global Community. In the Trenches.
June 26–27, 2026 | Melia Vienna
Join the world’s leading security architects and engineers for two days of uncompromising technical focus in the heart of Vienna.

Why attend?

Practitioner-Led Integrity
Skip the high-level evangelism. Every session is vetted by our global Program Committee to ensure you walk away with actionable tools and proven methodologies.
The Sandbox Track
Move beyond presentations. Participate in peer-reviewed Show & Tells, lead collaborative Mastermind roundtables, or dive into technical, hands-on workshops.
The ‘Doctor is In’ Clinic
Bring your architectural "pain points" to our resident specialists—like the Cloud Radiologist or Governance GP—for 15-minute diagnostic consultations.
Global Networking
Strategically timed after OWASP Global AppSec EU, this is the premier opportunity to connect with the pioneers of the Secure by Design movement.

Call for Proposals

Deadline: March 13, 2026
We’re seeking technical, experience-driven sessions that share real-world case studies, practical lessons, and—for the first time—redacted real-world threat models for peer review.
  • Technical Presentations (30 min)
  • Threat Model Show & Tell (Peer Reviews) (30 min)
  • Small Group Mastermind (Roundtables) (70 min)
  • Hands-on Workshops (70 min)
Our commitment to you: Every accepted speaker receives a complimentary full-access pass and 1:1 mentorship from our Program Committee to help refine your content and delivery for maximum impact.
Partner with Us: Sponsorship Opportunities

We believe our community benefits immensely from great threat modeling products. ThreatModCon offers unique, high-engagement sponsorship opportunities, such as:

  • The Exhibition Hall: High-traffic engagement with technical decision-makers.
  • The ‘Doctor is In’ Clinics: Dedicated slots for your technical experts to troubleshoot threat modeling challenges with attendees.
*Threat modeling story/mini case-study (for the un-keynote) 

The Un-Keynote is back—a community-led session featuring five-minute flashbacks from real threat modeling journeys. Share a defining moment: how you got started, a tough lesson, a breakthrough, or what you’d do differently if starting today. These bite-sized stories highlight the human side of threat modeling and inspire others through honest, relatable experiences.

**Poster session

New this year, poster sessions offer a visual, conversational way to share your work. Great for early-stage ideas, research, or prototypes, this format lets you engage one-on-one with attendees and spark informal, thoughtful discussions.

Only a few tickets remain... Grab yours now!

Got you feeling inspired? Stoked your curiosity? Lit the threat modeling fire in your belly?!

Limited tickets are left so get yours now before they're gone (and they will go!).

Speakers

Gain invaluable insights from top industry experts, seasoned practitioners, and thought leaders in threat modeling across technology, security consulting, academia, and beyond. Explore cutting-edge trends, delve into real-world case studies, and discover how these experts have empowered organizations to advance their threat modeling capabilities.

Keynote Speakers
Dinis Cruz
Founder & CEO, The Cyber Boardroom

Dinis Cruz is the Chief Scientist of Glasswall and the founder of The Cyber Boardroom startup, who brings a unique blend of Security and Engineering expertise with 20+ years experience in Cyber Security and Software Development. Dinis is focused on creating Gen AI powered teams and environments where engineering and security are enablers and accelerators for the business, with a big focus on the productisation and commercialisation of advanced technologies.

Jim Manico
Founder & CEO, Manicode Security

Jim Manico is the Founder of Manicode Security, a company dedicated to providing expert training in secure coding and security engineering to software developers. In addition to leading Manicode, Jim is actively involved in the tech startup ecosystem as an investor and advisor. Jim is committed to giving back to the community through his volunteer work with the OWASP foundation. He co-leads projects such as the OWASP Application Security Verification Standard and the OWASP Cheatsheet Series.

Speakers
Isabel Barberá
AI Advisor, Privacy Engineer & Co-founder, Rhite

Isabel Barberá is the author of PLOT4ai. She is also one of the members of ENISA Working Group on Data Protection Engineering and a National Expert at ISO/CEN/CENELEC working on the development of standards related to AI and privacy engineering.

Sebastien Deleersnyder
CTO, Toreon

Sebastien Deleersnyder, CTO Toreon, has a deep cybersecurity background. He has trained many developers in secure coding practices, started OWASP Belgium, contributed significantly to projects like SAMM. Now, he's focusing on integrating AppSec into DevOps and expanding the reach of threat modeling.

Avi Douglen
CEO, Bounce Security/OWASP Board of Directors

AviD is a prominent security architect and developer, with decades of experience building secure products and protecting complex systems. He has been designing, developing, and testing secure applications for over 20 years, and is obsessed with maximizing value output from security efforts, threat modeling in particular.

Karim El-Melhaoui
Principal Security Architect, O3 Cyber / Microsoft Security MVP

Karim is a seasoned and renowned thought leader within cloud security. At O3 Cyber, he conducts research and development and works with our clients, primarily in Financial Industry. Karim has a background in building and operating platform services for security on private and public clouds, developing and executing a cyber security strategy for the world’s largest sovereign wealth fund.

Stanley Harris
CEO & Co-founder, Katilyst

Stanley is the CEO and Cofounder of Katilyst, where he leads initiatives to build and enhance Security Champion programs. An avid MMORPG player since 1999, Stanley leverages his gaming experiences to apply effective gamification techniques in professional settings.

Kelly Kaoudis
Sr Security Engineer - Research, Trail of Bits

Kelly Kaoudis is a senior security engineer in the Research practice at Trail of Bits. She is a tech lead for threat modelling engagements, and contributes to Trail’s academic and industry research projects including open source parser and file formats analysis tooling.

Anthony Phipps
Lead Security Design Consultant, Lloyds Banking Group

Dr Anthony Phipps is a member of the cyber research centre at London Metropolitan University, conducting research into audio based cyber security applications. He is also currently a Lead Design for Lloyds Banking Group, managing a team of security design consultants.

James Rabe
Head of Global Services, IriusRisk

James Rabe is the Head of Global Services at IriusRisk. He is focused on building effective threat modeling programs through pragmatic, lean, and scalable processes. Secure by Design is the outcome and threat modeling is the pathway to get there!

Adam Shostack
President, Shostack Associates

Adam is the author of Threat Modeling: Designing for Security, and Threats: What Every Engineer Should Learn from Star Wars, and the first recipient of the Adam Shostack Award for Threat Modeling.

Elias Brattli Sørensen
Developer & Security Engineer, Kantega SSO

Developer & Security Engineer at Kantega SSO, engineering digital identity standards for secure authentication to the Atlassian ecosystem while facilitating and promoting secure software development practices. Creator of threat modeling game Elevation of MLsec.

Håkon Nikolai Stange Sørum
Principal Security Architect and Partner, O3 Cyber

Håkon has extensive knowledge on implementing secure software development practices for modern teams, designing and implementing cloud security architectures, and securely operating cloud infrastructure. Håkon is a Partner at O3 Cyber, a high-end cyber security advisory for securing the cloud.

Rob van der Veer
Chief AI Officer, Software Improvement Group (SIG)

Rob van der Veer has over 33 years of experience in AI and security, from hacker to CEO. He open sourced international standardization of AI security by establishing the OWASP AI Exchange flagship project, feeding right into the AI Act and ISO standards.

Dimitri Van Landuyt
Associate Professor in Information Systems Engineering, KU Leuven

Dimitri Van Landuyt is Associate Professor in Information Systems Engineering in the Faculty of Economics and Business (FEB) of KU Leuven. Current research focuses on evaluating security and privacy threat modeling methods and tools, and addressing technical, economic risk and legal risk.

Kim Wuyts
Manager, Cyber & Privacy, PwC Belgium

Kim Wuyts is a leading privacy engineering expert with over 15 years of experience in security and privacy. Before joining PwC as Manager Cyber & Privacy, Kim was a senior researcher at KU Leuven where she led the development and extension of LINDDUN, a popular privacy threat modeling framework. Her mission is to raise privacy awareness and get organizations to embrace privacy engineering best practices.

Simone Onofri
Security Lead, W3C

Simone is the W3C Security Lead. He has 20+ years of expertise in red/blue Teaming and Web security. He has spoken at OWASP, TEDx, and other events and authored Attacking and Exploiting Modern Web Applications.

Don’t Wait—Save 50% Today!

Join the most passionate Threat Modeling Community in the world in the heart of Vienna this June.