Threat Modelling for Developers training course

Learn how to identify, analyse and mitigate security threats early in the software development lifecycle using modern threat modelling techniques. Through practical exercises and real-world scenarios, you'll apply current cybersecurity best practices, including Secure by Design, DevSecOps, OWASP, STRIDE, MITRE ATT&CK and Agile development workflows to build more secure applications from the outset.

JBI training course London UK

"The topics (threat modelling frameworks, zones of trust, annotating your own diagrams, implementing security into Agile practices) were all well-chosen and appropriate.GL, Software Engineer, Threat Modelling, February 2021

Public Courses

28/09/26 - 2 days
£5000 +VAT
09/11/26 - 2 days
£5000 +VAT
21/12/26 - 2 days
£5000 +VAT

Customised Courses

* Train a team
* Tailor content
* Flex dates
From £1200 / day
EDF logo Capita logo Sky logo NHS logo RBS logo BBC logo CISCO logo
JBI training course London UK

  • Gain an overview of secure SDLC and understand how threat modelling fits in
  • Understand where and how Agile architecture fits in
  • Gain an introduction to several common security classification systems
  • Define elements of software that are security concerns
  • Explore threat model types
  • Learn about the traditional threat model process
  • Discover dependencies
  • Understand the Rapid Threat Model Prototyping (RTMP) process
  • Apply Zones of Trust and use Zone rules to find threats
  • Understand how to quickly classify threats
  • Learn mitigation analysis
  • Integrate RTMP in an Agile/DevOps process
  • Convert risks into backlog items
  • Learn validation and triaging of threats
  • Explore threat modelling of an internal system
  • Identify vulnerabilities and tackle them with threat models
  • Discover the relationship with threats and the Mitre ATT&CK framework
  • Create the ability to use key parts of the Common Weakness Enumeration (CWE), OWASP Top 10 (OT10) and STRIDE in finding threats and mitigations
  • Learn how to integrate the secure aspects of the AWS and Azure Well-Architected frameworks into a threat model

 

An excerpt from a 2 day JBI Threat Modelling training course showing an agile architecture session.

Overview

• The main recipients for the course are security subject-matter experts,  technical non-security professionals who have no/little experience of threat modelling (e.g. software devs, architects and engineers) and technically-oriented project leaders.

• The purpose of the course is to deliver the concept of threat modelling and to be able to complete a basic threat model using the Rapid Threat Model Prototyping methodology.

• By the end of the course, the class will understand threats, mitigations and risk rankings and will be able to use basic threat modelling techniques to drastically improve secure design of software.

• The course will enable participants to integrate RTMP into any software development process.

Threat modelling 101

• Overview of secure SDLC

• How Threat Modelling fits into a secure SDLC

• How Agile Architecture fits in

• Introduction to several common security classification systems

• What are STRIDE and OWASP Top 10

• Mini Lab - mapping system relationships

• Defining elements of software that are security concerns

• Threat Model types

• Traditional threat model process and its shortcomings

• The importance of context diagrams to threat modelling and reusing existing software designs

• Dependencies

• Mini Lab - discovering dependencies    

Rapid Threat Model Prototyping 201

• Pareto Rule (80/20 ratio) and use in secure software development

• Introduction to the Rapid Threat Model Prototyping methodology

• Elements of a threat model

• How to integrate RTMP in an Agile/DevOps process

• Zones of Trust and using Zone rules to find threats

• Adding Zone and threat metadata to a software diagram

• Mini Lab - applying Zone rules • Mitigation analysis

• Mini Lab - discovering mitigations

• Validation and triaging of results in an Agile/DevOps process

• Lab – full threat model of an internal system    

Rapid Threat Model Prototyping 301

• How to convert risks into backlog items that are prioritised accordingly (e.g. into Jira, MS DevOps or similar workflow systems)

• Examples and open conversation of threat models that you have from the real world, starting with simple systems and building up to more complicated systems

• How to use RTMP to quickly highlight flows/processes/etc that are high risk

• Advanced techniques using calculation of the RTMP elements. Formulae are outlined and broken down for comprehension.

• Discussion around how to implement a good security champion program to drive deep adoption of Rapid Threat Model Prototyping across the software development lifecycle.

• Use of RTMP in other parts of a business.

JBI training course London UK

The main recipients for the course are security subject-matter experts,  technical non-security professionals who have no/little experience of threat modelling (e.g. software devs, architects and engineers) and technically-oriented project leaders.


5 star

4.8 out of 5 average

"The topics (threat modelling frameworks, zones of trust, annotating your own diagrams, implementing security into Agile practices) were all well-chosen and appropriate.GL, Software Engineer, Threat Modelling, February 2021



“JBI  did a great job of customizing their syllabus to suit our business  needs and also bringing our team up to speed on the current best practices. Our teams varied widely in terms of experience and  the Instructor handled this particularly well - very impressive”

Brian F, Team Lead, RBS, Data Analysis Course, 20 April 2022

 

 

JBI training course London UK

Certification


Every delegate will be entitled to a certificate of achievement on completion of the course.

If you are missing your certificate - please use the link below to apply - you can also use this link to sign up for the JBI Training newsletter to receive technology tips directly from our instructors - Analytics, AI, ML, DevOps, Web, Backend and Security.
 



Threat modelling is a process to identify security weaknesses in software design and architecture, and define countermeasures that mitigate the malicious effects of the discovered weaknesses before any code is cut.

Our Threat Modelling  training course is designed for software developers and architects in mind. Threat modelling is language-agnostic. It can be easily used for any software development project and with any modern workflow such as Agile or DevOps. The analysis work is done on the design of the software system in order to improve the quality of the code that will be delivered in-sprint.
 
You will learn how to address security design concerns faced by software development teams with a combination of teaching modules and practical threat model exercises. The participants will be encouraged to work in teams, to foster discussions on how to implement security controls for the modelled threats on their software architecture.
 
All key stakeholders in an application development workflow should know how to assess the weak points in their systems and what questions to ask. The course will provide a framework to assess these questions and will yield immediate beneficial results.
 
You will gain a practical overview of the necessary disciplines for resolving application architecture and design issues according to OWASP good security practices.
 
We aim to instill skills that allow you to perform rapid threat modelling in a consistent, repeatable and measurable manner.

Threat modelling is a structured approach to identifying security threats, vulnerabilities, attack surfaces and potential risks in a system. It is typically performed during the design and development process so that security issues can be identified and mitigated before they become implementation or deployment problems. JBI's training focuses on practical threat modelling techniques that can be applied to software and modern development environments.
Secure by Design is an approach to software and system development where security is considered from the earliest stages of design rather than being added after implementation. JBI's Secure by Design training explores how security principles can be incorporated into existing development and build processes.
The training is suitable for software developers, solutions architects, security engineers, cybersecurity professionals, DevOps and platform engineers, AI and machine-learning engineers, technical leaders and engineering managers. The course group includes options for both people new to threat modelling and professionals looking to strengthen existing security engineering skills.
Depending on the course, delegates can learn how to identify threats and attack surfaces, create and evaluate threat models, assess security risks, develop mitigations, apply threat modelling during software development, and use Rapid Threat Model Prototyping. The training also covers secure-by-design principles and, on relevant courses, threats affecting agentic AI systems.
Rapid Threat Model Prototyping is a practical methodology for developing threat models quickly and iteratively. JBI's threat modelling training teaches delegates how to use RTMP to develop, test and refine threat models and integrate threat modelling into Agile and DevOps development processes
Yes. Threat modelling can be integrated into modern software development workflows, including Agile and DevOps. JBI's Threat Modelling for Developers course covers how to integrate Rapid Threat Model Prototyping into an Agile or DevOps process and how to convert identified risks into backlog items.
Yes. JBI offers dedicated training focused on threat modelling for agentic AI systems. The training addresses AI-specific attack surfaces, security risks and approaches for applying threat modelling and security controls to AI-enabled applications.
Threat modelling focuses on systematically identifying and analysing threats and security risks in a system. Secure Design focuses more broadly on designing systems with security principles and controls built into the architecture from the outset. The two approaches complement each other and are covered across JBI's Threat Modelling & Secure Design training portfolio.
No. Threat modelling is also relevant to developers, architects, engineers, DevOps professionals and technical leaders. JBI specifically describes its training as suitable for technical non-security professionals as well as security subject-matter experts.
Yes. JBI offers onsite training for teams, with content that can be adapted to the organisation's technology stack, development processes, threat modelling maturity and security objectives. The course-group page states that onsite delivery is particularly suited to teams of five or more.
Not necessarily. JBI's course portfolio includes training suitable for people who are new to threat modelling as well as professionals who want to develop existing security engineering capabilities. The Threat Modelling for Developers course is specifically designed for people with little or no previous threat modelling experience.

CONTACT


+44 (0)20 8446 7555

enquiries@jbinternational.co.uk

 

Copyright © 2026 JBI Training. All Rights Reserved.
JB International Training Ltd  -  Company Registration Number: 08458005
Registered Address: Wohl Enterprise Hub, 2B Redbourne Avenue, London, N3 2BS

Modern Slavery Statement & Corporate Policies | Terms & Conditions | Contact Us

POPULAR

AI training courses                                                                        CoPilot training course

Threat modelling training course   Python for data analysts training course

Power BI training course                                   Machine Learning training course

Spring Boot Microservices training course              Terraform training course

Data Storytelling training course                                               C++ training course

Power Automate training course                               Clean Code training course