Threat Modelling in the Real World: Lessons from a First-Time Practitioner

Threat modelling is often introduced as a structured and well-defined process, but applying it in real-world environments can be far more challenging than expected.

As a practitioner relatively early in this journey, I’ve experienced first-hand how threat modelling can become difficult to maintain, disconnected from fast-changing systems, and sometimes overlooked entirely in day-to-day security work.

In this talk, I’ll share practical lessons learned while working with threat modelling in complex environments — including where things didn’t go as planned. From struggling with keeping models up to date, to bridging gaps between different teams, this session focuses on the realities that are often not discussed.

Rather than focusing on theory or frameworks, this talk explores simple, practical ways to make threat modelling more useful and relevant — including connecting it with monitoring, detection, and everyday security workflows.

This session is aimed at anyone starting out with threat modelling or trying to make it work in real-world scenarios, offering an honest perspective and actionable takeaways.


Threat modelling looks great in slides — clean diagrams, structured frameworks, and a false sense of control. In reality, most threat models are outdated, ignored, or quietly abandoned.

This talk is an honest look at what actually happens when threat modelling meets real-world systems. Fast-changing architectures, unclear ownership, and the constant pressure to “just ship it” mean those carefully built models rarely survive beyond the whiteboard.

Instead of pretending the process works as advertised, we’ll break down where it fails — and why. More importantly, we’ll explore how to make threat modelling actually useful: lightweight, iterative, and connected to real security work like monitoring and detection.

No theory-heavy walkthroughs. No perfect diagrams. Just practical lessons, mistakes, and a realistic approach to making threat modelling work where it matters.

The speaker's profile picture
Poulomi Dwibedi

Poulomi Dwibedi is a Senior Cyber Security Engineer in Aviva working across threat modelling, cloud security, and detection engineering in large enterprise environments. Her work focuses on understanding how security practices operate beyond theory — especially when they meet real-world complexity, time pressure, and constantly evolving systems.

While relatively new to public speaking, Poulomi brings a practical and honest perspective shaped by hands-on experience, including where things don’t go as planned. She is particularly interested in bridging the gap between security design and operational reality, making processes like threat modelling more usable, relevant, and connected to everyday security work.

She is passionate about sharing real lessons, not perfect stories — especially for others navigating similar challenges early in their journey.