Threat Modeling: A Second Edition
The long-awaited second edition of Threat Modeling...
I am pleased to announce that Threat Modeling: Designing for Security in an AI World is now available for pre-order at Amazon or wherever fine books are sold. The official publication date is February 2nd, 2027, and we're on schedule.
Similarly, Amazon is pleased to have demonstrated information disclosure threats in database integration... by letting people know about that earlier than we expected. Regardless, it’s a huge update, with roughly half the book being new or substantially re-written. I’ll have a lot to say about that, but for right now, some of the biggies include:
- Two completely new LLM chapters!
- A new chapter on boundaries... you’ll have to trust me... for a little while
- A chapter on attack lifecycle models
- An entire reworked Part on defenses
- A new chapter on diagrams and models, expanded from a dozen pages in the previous “strategies” chapter.
But the really big update is the lessons that comes from customers over a dozen years of teaching, consulting and advising on threat modeling. For example, at one of the world’s largest banks, someone asked “How do I draw a diagram?” What I realized they were asking was “what sort of diagram do I need and why?” The questions that surprised me informed the new book. And so the new diagramming chapter starts from the concrete, and from there goes into how diagrams serve different purposes, and what makes a diagram useful or even stylish. The chapter on boundaries comes from hearing students struggle with it. The examples are more agile, less fancy, and ... well, there’s a fun improvement there that I’ll talk about soon.
Now that the cat’s out of the bag, let me connect the dots through some of my recent work: PHANTOM-B? Layering Defenses? Threat Modeling in the Age of AI? Stop Trying to Manage Risk? All of these have been exploring ideas that reach fruition on the published page.
Let me draw one other line through some of my work: A large chunk of the first edition migrates to the book's website. We’re moving something like 6 chapters and 3 appendices to the web. (Those were Attack Trees; Attack Libraries; Threat Modeling Tools; Requirements Cookbook; Bringing TM to Your Organization and Experimental Approaches. Similarly, Appendices A, B, C and D are moving off paper. Those were Helpful Tools, Threat Trees, Attacker Lists, and the EoP cards.) They’ll be there soon.
Logistically, Threat Modeling: Designing for Security in an AI World is available now wherever fine books can be pre-ordered. I encourage you to get it from wherever you get your books.
People will frequently ask, “where to buy that benefits the author the most” Frankly: Amazon. Most people buy most of their books there, and Amazon’s algorithmic recommendation engines treat sales very seriously. The “people who bought this” recommendations are an important source of awareness. But again, get your books however makes you happy. Amazon helps me a little by helping spread the word, but over time, the thing which has mattered is that the book helps people, and so they spread the word, and for that, I am exceptionally grateful.
Speaking of PHANTOM-B, our partners at Cybersec Games are now selling 10-packs of the PHANTOM-B Wallet cards, joining the classic Threat Modeling Wallet Cards to support your team's threat modeling.
PHANTOM-B Wallet Cards give your team a simple physical reference for design reviews, architecture discussions, sprint meetings or quick conversations at the whiteboard. Pre-order yours before your next design review!