LinkedIn·Thursday, 30 July 2026·27d ago
Most teams know they should be #threat #modelling. But SAMM #Benchmark data shows very few actually do. 🤷 The reasons? It lives in a…
CODIFIC
1,771 followers
Most teams know they should be #threat #modelling.
But SAMM #Benchmark data shows very few actually do. 🤷
The reasons?
It lives in a document nobody updates, it's disconnected from the rest of the security programme, and it feels like extra work rather than part of the workflow.
But there's a deeper problem, most teams blur the line between #risk scenarios and #threats. They're not the same thing.
A risk scenario is a business fear.
A threat is the technical path that makes it happen.
Both need to be captured.
Both need to be tracked.
And they need to connect.
That's what we built into #SAMMY; threat modelling that links business risk scenarios to technical threats, with ownership, priority, and traceability.
Not in a separate document. Inside the same platform where you manage your assessments, roadmaps, and compliance evidence. 🎯
🔗 Link in comments. 👇
Cross-referenced
Related on the wire
"You're right; we need to build this in." So what happens after a #SAMM assessment? That's usually where this service begins. Common next…
Where are the weak or missing controls in your systems - before someone else finds them? Three ways we help, depending on what you need:…
Do you actually know where your secure development program stands? OWASP SAMM is open source so you can assess yourself. But here's the…
"How do we actually do better, so that the path of least resistance is the more secure path?" That's the question Brian Glas keeps coming…
31 days until the first #CRA obligation goes live... 📢 On 11 September 2026, manufacturers must be ready to report actively exploited…
Your compliance team works in spreadsheets. Your engineering team works in CI/CD pipelines. And somehow both are supposed to keep your…