LinkedIn·Tuesday, 11 August 2026·15d ago
Threat modelling is no longer optional. NIS2 and the CRA have made risk assessment in software development a legal requirement; ✅…
Approach Cyber
7,548 followers
Threat modelling is no longer optional.
NIS2 and the CRA have made risk assessment in software development a legal requirement;
✅ Documentation
✅ Risk registers
✅ Evidence of security decisions at design stage
✅ A repeatable methodology.
Most development teams have gaps they don't know about.
👇 Our publication maps exactly what's required and where teams typically fall short 👇
https://loom.ly/aBZw2o0
#threatmodelling #securedevelopment #appsec #nis2 #cyberresilienceact #safeholidays
↻ 1
View on LinkedIn Cross-referenced
Related on the wire
Eight weeks. One message: the threat doesn't pause because you do. September brings its own risks; full inboxes, deferred decisions,…
Our pentesters got in. Again. 🚨🥷 5th edition of the Approach Cyber Pentest Annual Report is out. The findings across Belgian…
Does the EU Cyber Resilience Act apply to your product? If your answer is 'probably not' 👉 check again The CRA scope is wider than most…
The NIS2 deadline passed in April. Now what? Compliance isn't a project you finish. It's a posture you maintain; ✔️ continuous risk…
We put a server on the internet. Then we waited ⏳ ⏰ Within hours: automated scanners. 📅 Within a day: active exploitation attempts. 👀 By…
War Story 03: Tokens in the open, Keys to the Kingdom 🔑 Your software development pipelines and internal chat channels might be the…