Case Studies

Purdue University - A Novel Approach to Teaching Secure-by-Design Principles

Building cybersecurity skills through hands-on learning

Download Case Study
Purdue University - A Novel Approach to Teaching Secure-by-Design Principles

Executive Summary

Teaching threat modeling, rethought

Amid rising cyberattack risk and growing demand for skilled cybersecurity engineers, universities are central to teaching foundational skills. Threat modeling is one of them, and it is due for a rethink in how it is taught.

In threat modeling, an organization’s attack surface is mapped to identify risks and put mitigations and controls in place. The practice enables a secure-by-design approach: proactive mitigation early in development, rather than reacting to attacks after deployment.

Teaching threat modeling in a software engineering course builds both secure software and a security mindset. Yet many academic approaches rely on component-level analysis rather than a systems-level view, and on tools that are outdated or unsuitable. Traditional methods have been labor-intensive manual processes that demand substantial resources, and their outputs often lose value soon after delivery.

ThreatModeler® accelerates threat modeling with an automated, enterprise-grade platform. Its intuitive interface, expansive threat library, and guided model creation have been shown to increase securityarchitect output tenfold and let non-security professionals build models and address threats. Recently, a semester-long software engineering project at Purdue University featured the ThreatModeler platform, helping students better identify and mitigate security threats in their applications

Show more

Resources

View all Resources
Start Left At Design

Blog

Start Left At Design

Lessons From a CISO Panel

Read More
Secure by Design

Blog

Secure by Design

Proactive Resilience in the era of AI Supply Chain Risk and MCP

Featured

Read More
Calm in the Chaos

Blog

Calm in the Chaos

Why Threat Modeling Matters More as AI Speeds Up the Build-Exploit-Patch Cycle

Read More