Level Up Your Threat Modeling: Turning Security Into a Team Adventure

Stanley Harris (Co-founder and CEO · Catalyst)

BSidesSF 2026 · Day 1 · AMC Theatre 10

Overview

In this engaging and unconventional talk at BSides SF, Stanley Harris, co-founder and CEO of Catalyst, unveiled an innovative approach to an often-daunting security practice: threat modeling. Titled "Level Up Your Threat Modeling: Turning Security Into a Team Adventure," Harris demonstrated how leveraging the collaborative and imaginative framework of Dungeons & Dragons (D&D) can transform dry, unengaging security exercises into captivating team adventures. The presentation posits that by gamifying the threat modeling process, organizations can significantly increase developer engagement, foster cross-functional collaboration, and ultimately build more secure applications.

Watch on YouTube

Key moments

  1. 0:00 Introduction: D&D themed threat modeling adventure
  2. 1:18 Overview of the D&D threat modeling process
  3. 2:00 How the D&D threat modeling concept was born
  4. 3:00 Successful D&D threat modeling at conferences
  5. 4:15 Essential toolkit for your D&D threat modeling adventure
  6. 6:00 The 6-step D&D inspired threat modeling process

Level Up Your Threat Modeling: Turning Security Into a Team Adventure

Speakers: Stanley Harris, Co-founder and CEO, Catalyst

Conference: BSides SF

YouTube: https://www.youtube.com/watch?v=CVmNw0iHc7s

Overview

In this engaging and unconventional talk at BSides SF, Stanley Harris, co-founder and CEO of Catalyst, unveiled an innovative approach to an often-daunting security practice: threat modeling. Titled "Level Up Your Threat Modeling: Turning Security Into a Team Adventure," Harris demonstrated how leveraging the collaborative and imaginative framework of Dungeons & Dragons (D&D) can transform dry, unengaging security exercises into captivating team adventures. The presentation posits that by gamifying the threat modeling process, organizations can significantly increase developer engagement, foster cross-functional collaboration, and ultimately build more secure applications.

Harris, a self-proclaimed "champion of security champions" and D&D enthusiast, argues that traditional threat modeling often fails to resonate with development teams, leading to disinterest and a lack of adoption. His solution re-contextualizes security risks as "monsters" and mitigations as "safeguards" within a shared fantasy world, complete with character roles, experience points (XP), and a "challenge rating matrix" for risk prioritization. This novel methodology not only makes the process more enjoyable but also encourages a deeper understanding of security concepts among diverse team members, turning what was once a chore into a collaborative quest for resilience.

The talk highlights the critical importance of making security an inclusive, team-driven effort, moving beyond the perception of it as a solo audit or a burden pushed onto developers. By infusing elements of storytelling, role-playing, and tangible recognition, Harris provides a blueprint for organizations to cultivate a proactive security culture where developers are not just participants but active adventurers in securing their systems. This approach challenges the status quo, offering a refreshing and effective alternative to conventional threat modeling practices.

Background

▶ Watch: Introduction: D&D themed threat modeling adventure (0:00)

The genesis of this D&D-inspired threat modeling approach stems from a common, persistent problem in application security: the struggle to make threat modeling "sticky" and engaging for development teams. Stanley Harris observed that developers often perceive traditional threat modeling as a dry, time-consuming imposition that infringes upon their already tight schedules. This lack of interest and engagement frequently leads to superficial analyses or, worse, the complete avoidance of the practice, leaving critical vulnerabilities unaddressed. The inherent complexity and abstract nature of security risks, when presented without a compelling narrative, often fail to capture the imagination or intrinsic motivation of those responsible for building software.

Harris's personal experience highlights this challenge. While working with a client on a security champion program, he encountered significant resistance when attempting to introduce threat modeling. Developers found it difficult to engage, viewing it as an additional, uninspiring task. Coincidentally, Harris had just concluded a D&D campaign with a separate group of developers, noting the stark contrast in their enthusiasm and collaborative spirit during the game. This serendipitous observation sparked an idea: if Dungeons & Dragons could foster such deep engagement and collaborative problem-solving, could its mechanics be mapped onto the threat modeling process?

The core problem, therefore, is not the utility of threat modeling itself – its value in identifying and mitigating design-level flaws is well-established – but rather its delivery and perception. Security professionals often struggle to bridge the gap between abstract security concepts and the tangible, day-to-day work of developers. Prior attempts to make threat modeling more accessible have included various methodologies like STRIDE (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) and tools ranging from simple whiteboards to sophisticated software. However, many still fall short in fostering the intrinsic motivation and collaborative spirit needed for truly effective and continuous security improvement. Harris’s approach seeks to address this fundamental human element, transforming a technical necessity into an enjoyable, shared adventure.

Key Findings

▶ Watch: How the D&D threat modeling concept was born (2:00)

The central finding of Stanley Harris's work is that gamification, specifically through a Dungeons & Dragons aesthetic, dramatically enhances engagement and effectiveness in threat modeling sessions. This approach successfully overcomes the inherent "dryness" and perceived burden of traditional threat modeling, transforming it into a collaborative and enjoyable activity for development teams. Harris demonstrated this through two key iterations of his D&D-inspired threat modeling campaign.

The first iteration was a live, two-hour tabletop exercise conducted at Threat Modeling Con in Washington D.C. Participants, described as "very willing," immersed themselves in the D&D aesthetic, using physical cards and role-playing elements while executing a true-to-form threat modeling process. The feedback from this event was overwhelmingly positive, with participants expressing that it was a novel and engaging way to tackle security, feeling far less tedious than conventional methods.

The second iteration, a virtual version, was run a month later at the Threat Modeling Connects hackathon using Lucid Spark. This online collaborative tool allowed for a similar immersive experience. Harris presented a board from this session, illustrating a "litany of identified threats" and comprehensive mitigation plans developed by participants within a two-hour timeframe. Crucially, the most significant outcome was that "they had fun doing it." This feedback from both events solidified the finding: by framing threat modeling as an adventure with recognizable D&D elements, teams are more likely to participate actively, identify a broader range of threats, and develop robust mitigation strategies. The gamified context fosters a sense of shared purpose and incentivizes proactive security thinking, leading to more thorough and effective security outcomes than typically achieved through traditional methods.

Technical Deep Dive

▶ Watch: Successful D&D threat modeling at conferences (3:00)

The D&D-inspired threat modeling framework is a structured yet flexible methodology that re-imagines the traditional threat modeling process through the lens of a fantasy role-playing game. It meticulously maps core security concepts and activities to D&D mechanics, fostering engagement and understanding.

Gathering the Party: Cross-Functional Teams and Roles

Like any D&D adventure, the process begins by gathering the party, which translates to assembling a cross-functional team. This includes individuals who deeply understand the application or system under review, such as developers, architects, and QA testers, as well as those involved in the design, build, test, and deploy phases. To further lean into the D&D theme, participants are assigned specific roles or "classes":

  • Warrior (Developer): Specializing in "code literacy" and "bug slaying," developers are on the front lines, understanding the code's intricacies and potential vulnerabilities.
  • Diagramancer (Architect): A unique and fitting term coined by Harris, architects are responsible for mapping the system, understanding its architecture, and identifying trust boundaries.
  • Ranger (QA Tester): As "threat hunters," QA testers naturally fit this role, leveraging their expertise in finding flaws and testing system resilience.
  • Bard (Facilitator/Security Advocate): The bard, typically the D&D game master (DM) or facilitator, guides the session. This role is assumed by a security advocate who keeps the group on task, maintains the "lore" (documentation), and acts as the security expert, providing "gut checks" and guiding threat identification.

Each role is designed to leverage existing skill sets while encouraging participants to engage with security in a new, collaborative context.

Mapping the World: The Data Flow Diagram (DFD)

The adventure begins with mapping the world, which is the Data Flow Diagram (DFD). This DFD serves as the foundational "map" of the system, depicting its components, data flows, and trust boundaries. It can be pre-existing or built collaboratively from scratch using whiteboards, physical paper, threat modeling tools, or collaborative platforms like Miro or Lucid Spark. The bard ensures everyone has hands-on involvement in this process.

Storytelling is crucial here. Harris advises framing the DFD as an unknown world, with "crown jewels" (critical data) in a "dragon's lair" (secure component), "trust boundaries" as "moats and walls," and "unmapped logic" as "dark forests." This narrative immersion helps participants disengage from day-to-day work and embrace the adventure. Teams earn experience points (XP) for contributing to and updating the DFD, such as identifying new data flows, unknown components, or discrepancies with production systems. This incentivizes accuracy and comprehensive system understanding.

Revealing the Monsters: Threat Identification

Once the map is established, the party embarks on a monster search – the threat identification exercise. Harris developed 24 distinct "threat cards" or "monster cards," each inspired by D&D lore but directly aligned with the STRIDE threat modeling methodology. For instance:

  • The Gluttonous Slime represents Denial of Service (DoS), as it consumes all system resources.
  • The Mimic of Trust embodies Spoofing, disguising itself as another identity.

These thematic names make abstract security concepts more tangible and memorable. As participants identify real threats within their application's architecture, they "play" these monster cards onto the DFD. This action initiates a conversation within the party: "Why this threat? Why at this particular vector? Explain it to me." The bard facilitates this discussion, ensuring a thorough analysis and helping the team build out their D&D-themed threat model.

Scouting the Enemy: Prioritizing Risks

After identifying threats, the next step is to scout the enemy and prioritize risks. Harris uses a Challenge Rating Matrix, which is a gamified version of impact and likelihood analysis. While acknowledging debates about the best prioritization methods, he finds this format accessible and effective for developers.

The matrix uses D&D terminology:

  • Damage Dice (Level of Impact): Categorizes the potential harm (e.g., minor, significant, catastrophic, legendary).
  • Saving Throw (Likelihood): Assesses the ease of exploitation (e.g., fortified, guarded, exposed flank).

Threats are assigned XP based on their position in this matrix. For example, a "critical hit" (legendary impact) that is "exposed flank" (incredibly easy to exploit) might earn 8 XP. This XP system not only provides a tangible measure of risk but also serves as an incentive. Participants observe a leaderboard, fostering a healthy sense of recognition and motivation to identify high-impact, high-likelihood threats.

Playing Different Mitigations: Safeguards

The final technical stage involves playing different mitigations against the identified threats, represented by "safeguard cards." Similar to the monster cards, these mitigation cards are D&D-themed and aligned with STRIDE categories. Participants, in rotation, analyze each threat and determine the most appropriate mitigation.

While the cards implicitly guide towards STRIDE-aligned mitigations, the primary goal is to initiate collaborative discussion. The team questions and validates assumptions: "Why is this mitigation appropriate for this threat?" This collaborative validation deepens understanding and ensures that proposed mitigations are relevant and effective. Participants earn additional XP for identifying and discussing mitigations, further contributing to their individual and team scores on the leaderboard.

Iterative Adventures and Recognition

The entire process is designed to be iterative. After an initial comprehensive assessment, teams are encouraged to revisit their threat models regularly—every sprint, month, or quarter—to account for system changes, new features, or evolving threats. The storytelling device remains consistent, allowing for continuous engagement.

Crucially, Harris emphasizes the importance of recognition. XP earned throughout the campaign can translate into tangible rewards, such as swag, integration into security champion programs, or public acknowledgments like a "Hall of Fame" or leaderboard. This visible recognition of proactive behavior is considered the strongest driver for sustained behavioral change, encouraging developers to not only participate but to actively "level up their skills" by attending conferences, reading books, and engaging further in security. Rotating the "bard" role among experienced participants also empowers them to take ownership and further embed the practice within their teams.

By combining a familiar and engaging game framework with rigorous security principles, Harris's D&D-inspired threat modeling provides a powerful mechanism for transforming security from a compliance burden into a collaborative, continuous, and celebrated team endeavor.

Demo / Proof of Concept

▶ Watch: Essential toolkit for your D&D threat modeling adventure (4:15)

Stanley Harris provided concrete examples of his D&D-inspired threat modeling in action, demonstrating its viability and effectiveness. The methodology was first brought to life as a live, two-hour tabletop exercise at Threat Modeling Con in Washington D.C. For this event, Harris and his team prepared physical cards representing D&D-themed threats (monsters) and mitigations (safeguards), character cards for participants to embody roles, and a system for tracking experience points. Participants were encouraged to "shed reality" and fully immerse themselves in the role-playing aspect, applying the D&D aesthetic to a true-to-form threat modeling process. The success of this initial demonstration was evident in the enthusiastic feedback from participants, who found the experience highly engaging and a refreshing departure from conventional threat modeling.

Following this, a virtual version of the D&D-inspired threat modeling campaign was run at the Threat Modeling Connects hackathon. For this online format, Harris utilized Lucid Spark, an easy-to-use collaborative digital whiteboard tool. This allowed participants to remotely engage with the DFD (the "map"), place digital "monster" and "safeguard" cards, and collectively prioritize risks and identify mitigations. Harris displayed a screenshot of a completed Lucid Spark board, illustrating the extensive activity within a two-hour session. This board showed a simple initial setup at the bottom (a blank DFD and 20 risk/mitigation cards) contrasted with a "litany of identified threats" and a comprehensive mitigation plan at the end. The key takeaway from both demonstrations was not just the quantity of identified threats and mitigations, but the fact that participants "had fun doing it," highlighting the method's success in fostering engagement and making a typically dry process enjoyable. These events served as compelling proofs of concept, validating that the gamified approach significantly enhances participation and effectiveness in threat modeling.

Defensive Implications

▶ Watch: The 6-step D&D inspired threat modeling process (6:00)

The D&D-inspired threat modeling framework offers several crucial defensive implications for organizations seeking to bolster their security posture and foster a proactive security culture.

Firstly, the approach directly addresses the challenge of developer engagement in security. By making threat modeling an enjoyable, collaborative "adventure," organizations can significantly increase participation and intrinsic motivation among development teams. This shifts the perception of security from a bottleneck or an external audit to a shared responsibility, empowering developers to become active contributors to their system's resilience. Defenders can leverage this by intentionally designing security activities to be more interactive and less prescriptive, using creative formats that resonate with their teams.

Secondly, the emphasis on a current and accurate Data Flow Diagram (DFD) as the "map" is a fundamental defensive practice. The framework incentivizes teams to continuously update and refine their DFDs, recognizing that an outdated map leads to unaddressed risks. By encouraging XP for DFD contributions, organizations ensure that the foundational understanding of their system's architecture remains accurate, providing a robust basis for threat identification and mitigation. This continuous maintenance of system documentation is a strong defensive posture against evolving threats and system changes.

Thirdly, the structured yet gamified identification of threats using STRIDE-aligned "monster cards" ensures a comprehensive and systematic approach to risk analysis. The D&D narrative helps teams visualize abstract threats like "Gluttonous Slime" (DoS) or "Mimic of Trust" (Spoofing), making them more tangible and easier to discuss. This direct mapping to STRIDE ensures that common and critical threat categories are consistently considered, reducing the likelihood of overlooking significant vulnerabilities at the design stage.

Finally, the framework's strong focus on recognition and positive reinforcement is a powerful defensive tool for behavior change. Harris advocates for visible acknowledgment of proactive security efforts, whether through leaderboards, "Hall of Fame" entries, or custom swag. This public recognition incentivizes repeat behavior, fostering a culture where security champions are celebrated and their efforts are valued. Organizations should implement similar reward structures, rotating roles and empowering team members to facilitate, thereby scaling the security advocate program and embedding security consciousness more deeply within development cycles. By making security fun, visible, and rewarding, defenders can transform a reactive security stance into a proactive, collaborative, and continuously improving defense.

Key Takeaways

  • Threat Modeling is a Shared Adventure: It should not be treated as a solo audit or a burden pushed onto individuals. Instead, it's a collaborative experience where diverse team members contribute to a common goal of securing their systems.
  • Everyone Has a Role to Play: By assigning D&D-inspired roles like Warrior (Developer), Diagramancer (Architect), Ranger (QA), and Bard (Facilitator), the framework ensures inclusive participation, leveraging each team member's unique skills and perspectives in the security process.
  • The Map (DFD) is Your Ally: A current and accurate Data Flow Diagram is fundamental. Teams must continuously update and revisit their DFDs to reflect system changes, ensuring that the understanding of the system's architecture remains precise and relevant for threat identification.
  • Naming Threats Gives Power: Using evocative, D&D-themed names for threats (e.g., Gluttonous Slime for DoS) makes abstract security concepts more tangible and memorable, fostering deeper engagement and a personal connection to solving the identified risks.
  • Keep It Fun and Flexible: Infusing creativity, storytelling, and gamification into threat modeling significantly boosts engagement and effectiveness. Organizations should explore various creative formats that resonate with their teams to make security practices more captivating and less daunting.
  • Recognition Drives Behavior Change: Publicly acknowledging and rewarding proactive security contributions, through mechanisms like XP leaderboards, "Hall of Fame," or custom incentives, is the most powerful way to foster sustained engagement and cultivate a strong, security-conscious culture.

About the Speaker(s)

Stanley Harris is the co-founder and CEO of Catalyst, where he champions security champions and focuses on fostering collaboration and finding innovative, fun ways for people to solve difficult problems. He describes himself as an appsec advocate and a "culture warrior." A devoted Dungeons & Dragons enthusiast, former Dungeon Master (DM), and avid gamer, Harris leverages his passion for tabletop games to transform complex challenges, like threat modeling, into engaging, role-playing adventures. He is also a husband and a cat and dog dad, noting that his pets appreciate his gaming enthusiasm. His work is deeply rooted in his belief that recognition and enjoyable experiences are key to driving positive behavioral change in security.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

A competent, well-structured talk on using gamification to solve the real problem of developer disengagement from threat modeling. Harris has clearly done the work, run the experiments, and has a coherent framework — but this is a practitioner methodology talk, not research, and it lives or dies on whether the audience finds the problem worth solving.

Heather Calloway (CISO) — SOLID

A creative, well-executed talk on developer engagement in threat modeling. Useful for security advocates and program builders, but it never climbs to the organizational or governance level where threat modeling programs actually succeed or fail.

→ Top-rated talks at BSidesSF 2026

All talks from BSidesSF 2026