Product
Platform
Platform
Platform
Developers
Quickstarts
Resources
Explore
Pricing
Download
get a demoLogin
Most developers are already threat modeling. They just don't call it that.
Mike Shema (Application Security Weekly) joins FusionAuth's Dan Moore for a casual conversation about what threat modeling looks like once you strip away the industry jargon. They'll use MCP as a topical entry point. MCP was a spec that shipped fast, without security fully baked in, and is already on version 2.0. But MCP leads to a bigger question: Did LLMs and agentic systems meaningfully change the threat landscape or just give old problems new names?
From there the conversation moves into the parts of threat modeling that tend to get skipped: What happens after the exercise is documented (the “Day 2” problem), how threat modeling identity differs for customers versus employees, and why business logic — who can act as whom and what those actions entail — matters more than chasing the next CVE.
This is a security-101-level conversation for a developer audience who works with security every day but doesn't think of themselves as security people.


By submitting, I agree to the processing of my personal data by FusionAuth as described in the Privacy Policy.