If you feel like threat modeling is a tedious box to check before you can get on to actually securing your assets, you’re not alone. At Aiven, I built a threat modeling process that’s intended to be fast and easy, but still complete. It depends on taking input from developers and other stakeholders, and it allows the security team to guide a collaborative journey into discovering what controls the organization will need to implement to meet its security objectives. We move away from creating diagrams and artifacts nobody can use, into creating living documents and getting consensus on how to secure the asset.