While the IT industry is embracing the cloud-nativetechnologies, migrating from monolithic architecture to serviceoriented architecture is not a trivial process. It involves a lot ofdissection and abstraction. The layer of abstraction designed forsimplifying the development quickly becomes the barrier of visibility and the source of misconfigurations. The complexity maygive microservices a larger attack surface compared to monolithicapplications. This talk presents a microservices threat modelingthat uncovers the attack vectors hidden in each abstraction layer.Scenarios of security breaches in microservices platforms arediscussed, followed by the countermeasures to close these attackvectors. Finally, a decision-making process for architecting securemicroservices is presented.