CISOs are struggling to threat-model AI. Can 15-minute sessions help?
Brief
A few weeks ago, on a busy day, threat-modeling expert Adam Shostack opened an email from a client. Someone at that organization had vibe-coded an app and put it to work with customer data. Now, the client wanted to know what risks the tool posed. And what it should do about them. They needed answers quickly, so Shostack gave himself 15 minutes to analyze the system.
Soon, he had “a list of meaningful threats,” including hallucination and bias, problems that STRIDE, a widely used application-security threat model framework, would not have shown. “I found some interesting stuff that wasn’t obvious to me when I started,” Shostack says. During those 15 minutes, he used PHANTOM-B, a threat modeling framework he developed. It starts with the standard question “What can go wrong?”
but applies it specifically to the LLM components of a system.
