Case Studies
Purdue University - A Novel Approach to Teaching Secure-by-Design Principles
Building cybersecurity skills through hands-on learning
Executive Summary
Teaching threat modeling, rethought
Amid rising cyberattack risk and growing demand for skilled cybersecurity engineers, universities are central to teaching foundational skills. Threat modeling is one of them, and it is due for a rethink in how it is taught.
In threat modeling, an organization’s attack surface is mapped to identify risks and put mitigations and controls in place. The practice enables a secure-by-design approach: proactive mitigation early in development, rather than reacting to attacks after deployment.
Teaching threat modeling in a software engineering course builds both secure software and a security mindset. Yet many academic approaches rely on component-level analysis rather than a systems-level view, and on tools that are outdated or unsuitable. Traditional methods have been labor-intensive manual processes that demand substantial resources, and their outputs often lose value soon after delivery.
ThreatModeler® accelerates threat modeling with an automated, enterprise-grade platform. Its intuitive interface, expansive threat library, and guided model creation have been shown to increase securityarchitect output tenfold and let non-security professionals build models and address threats. Recently, a semester-long software engineering project at Purdue University featured the ThreatModeler platform, helping students better identify and mitigate security threats in their applications
See it for your environment
Book a live session with a solution engineer — we'll walk through the use cases that matter most for your stack.



