Ticket Discounts for Cyber Events

GET ALERTS!

Recommended Event: Gartner Security & Risk Management Summit | 22 - 24 Sep 2026

ThreatModCon San Francisco 2026

Type Conference
Organization Threat Modeling Connect
Event Format Physical
Size 101 - 300 approximate delegates
Registration Not Free
SPEAKING: FREE-TO-SPEAK

Search for other Cybersecurity Conferences in the United States or discover other Cyber Events in California in 2026-2027.

Conference Description

Key Takeaways

  • Practitioner-led conference dedicated exclusively to threat modeling and secure-by-design methodologies
  • Technical focus areas include AI security, privacy engineering, cloud security, digital identity and secure SDLC
  • Designed for security architects, AppSec professionals, DevSecOps teams and product security leads
  • Addresses practical challenges of integrating and scaling threat modeling within development workflows
  • Features hands-on workshops, peer-reviewed presentations and collaborative roundtables

Introduction

ThreatModCon stands as the only global conference built entirely around threat modeling practice and secure-by-design principles. The event serves security practitioners, architects and application security professionals seeking to advance their capabilities in identifying and mitigating security risks during software development. As organisations face mounting pressure to embed security earlier in development cycles—particularly with the rapid adoption of AI systems and cloud-native architectures—the conference addresses the growing need for systematic approaches to threat identification and risk assessment.

About ThreatModCon

ThreatModCon operates as the flagship event for the Threat Modeling Connect community, an international network of security professionals focused on advancing threat modeling as a discipline. The conference runs across multiple global locations, including Vienna, San Francisco and Lisbon, with each event structured around dual presentation tracks, hands-on workshops and collaborative roundtable discussions.

The programme emphasises technical depth over theoretical discussion. All sessions undergo vetting for practical applicability, with peer-reviewed presentations and real-world case studies forming the core content. Attendees participate in show-and-tell sessions where practitioners demonstrate working approaches, and roundtables provide opportunities to troubleshoot specific threat modeling challenges with experienced peers.

Technical Focus Areas

The conference programme spans several interconnected domains within application security. Core threat modeling methodologies receive substantial attention, alongside their application to emerging technology areas where traditional approaches require adaptation.

AI and agentic security has become a significant focus as organisations deploy machine learning systems that introduce novel attack surfaces and trust boundaries. Privacy engineering intersects with threat modeling through frameworks such as LINDDUN, which provides structured approaches for identifying privacy threats in system designs. Cloud security sessions address the particular challenges of modeling threats in distributed, ephemeral infrastructure where traditional perimeter-based thinking proves inadequate.

Digital identity systems present their own modeling complexities, particularly as authentication and authorisation mechanisms become more sophisticated. The secure software development lifecycle remains central, with sessions exploring how threat modeling integrates with agile workflows and DevSecOps practices without creating bottlenecks.

Addressing Practical Implementation Challenges

Many organisations struggle to move threat modeling from occasional exercises to embedded practice. ThreatModCon addresses this gap directly, with content focused on scaling security activities across development teams and integrating threat analysis into existing workflows.

The challenge of keeping threat models current as systems evolve receives particular attention. Static documentation quickly becomes obsolete in environments with frequent releases, and practitioners share approaches for maintaining living threat models that remain useful throughout a product’s lifecycle. Vulnerability management connects to this theme, as threat models should inform both proactive design decisions and reactive prioritisation when new vulnerabilities emerge.

Industry Participation

The conference draws participation from technology companies, financial institutions, healthcare organisations, government agencies and consulting firms. This cross-sector attendance reflects the universal applicability of threat modeling principles, while also surfacing domain-specific considerations that practitioners in regulated industries must address.

Supporting organisations include ThreatModeler, Toreon, IriusRisk, Katilyst, Neo4j, Splunk, PwC, Deloitte, Microsoft, Red Hat and Broadcom. The event maintains a vendor-neutral stance, with content selection driven by practitioner relevance rather than commercial considerations.

Who Should Attend

ThreatModCon serves professionals across the security and development spectrum. Security architects and engineers benefit from technical deep-dives, while product security leads and AppSec managers find value in sessions addressing programme development and team enablement. CISOs and CTOs gain insight into how threat modeling supports broader security strategy and regulatory compliance objectives.

DevSecOps practitioners exploring ways to shift security analysis earlier in pipelines will find relevant content, as will researchers investigating emerging threat categories in AI and cloud systems. The conference accommodates both those establishing threat modeling practices and experienced practitioners refining mature programmes.