O
6

Chose threat modeling over pentest tools, my devs actually listened

I had to pick between buying a $12k automated scanner suite or setting up a simple threat modeling program with the team. I went with the modeling because the scanner would just dump findings on a Slack channel nobody reads. After 3 weeks, the devs started catching their own auth flaws before I even looked at the code. Anyone else ditch the fancy tools for boring whiteboard sessions?
0 comments

Log in to join the discussion

Log In
0 Comments

No comments yet

Be the first to share your thoughts on this discussion.