Threat Modeling cover
Pages
624
Year
2014
Level
intermediate
Read time
16h
Adam Shostack · Wiley · 2014
Reviewed by Ashish Sheth · Updated August 2026

Threat Modeling

Designing for Security

4.5 / 5
AMAZON · 339 RATINGS
security
SUBJECTS
Check Price on Amazon →
What you'll come away with
01.
A structured way to ask what can go wrong before you build
02.
How STRIDE surfaces spoofing, tampering, and the rest, category by category
03.
Why a good data flow diagram is most of the work
04.
How to move from a list of threats to prioritized fixes
05.
How to run threat modeling so a team keeps doing it
Strengths
+The definitive treatment of threat modeling from a field founder
+Gives you repeatable frameworks instead of vague advice
+Deep and thorough, with plenty of worked examples
+Applies well beyond software to any system you design
Caveats
Long and dense at 624 pages; it reads like a reference, not a tutorial
Published in 2014, so cloud and modern pipeline examples are thin
Heavier going for developers new to security fundamentals
★ 4.5 FROM 339 READERS ON AMAZON
Check Price on Amazon →
Read this if
Architects and engineers who make design decisions with security stakes
Security champions who want to run structured threat-modeling sessions
Anyone who wants to catch flaws on the whiteboard, not in production
Skip this if
Beginners still learning basic web vulnerabilities
Readers wanting a quick, code-first security primer
Teams looking only for hands-on exploitation practice
Head-to-head comparisons
Threat Modeling vs Alice and Bob Learn Application Security Threat Modeling vs Security Engineering
MORE SOFTWARE SECURITY BOOKS
Frequently asked
Is Threat Modeling by Adam Shostack still worth reading in 2026?
Yes. The frameworks it teaches, the four-question method, STRIDE, and data flow diagrams, are still the standard vocabulary for threat modeling and have not been replaced. The 2014 examples predate today's cloud and CI/CD tooling, so read it for the durable method and apply that method to your own modern architecture.
Is Threat Modeling good for beginners?
It suits readers who already grasp basic security concepts and now make design decisions. At 624 pages it is thorough and reads like a reference, which can overwhelm a newcomer. If you are new to security, start with Alice and Bob Learn Application Security, then come here when you need to run structured threat-modeling sessions.
Do I need to be a security expert to use this book?
No, but a working knowledge of software design helps. Adam Shostack wrote it so that engineers and architects, not only security specialists, can run threat modeling. The four-question framework gives non-experts a way in, and the deeper chapters on STRIDE and attack trees are there when you are ready for them.
Read this next
2 alternatives
Alice and Bob Learn Application Security cover
Tanya Janca
Alice and Bob Learn Application Security
★ 4.7 · 225 RATINGS
Security Engineering cover
Ross Anderson
Security Engineering
★ 4.8 · 265 RATINGS
Ready?
Check Price on Amazon →