1. Security Design Review advanced

    A developer-tools company of JetBrains' shape has six security engineers for 200 developers shipping desktop IDEs, a plugin marketplace and a hosted build service. It replaces mandatory pre-launch security review with a self-service threat-modelling questionnaire plus a trigger list, keeping deep review for triggered changes. What has it given up, and when does that bill arrive?

    3 min answer security-design-reviewthreat-modellingtriggerssampling
  2. Security Design Review intermediate

    A security design review consistently produces findings that are expensive to act on. What is wrong with the process?

    2 min answer workosdesign-reviewtimingthreat-model
  3. Security Design Review advanced

    A security team of six supports two hundred engineers. Design reviews are a bottleneck. What do you do?

    1 min answer security-reviewscalingtriagepaved-road
  4. Security Design Review intermediate

    Security reviews happen the week before launch. Findings are usually rejected as too late to fix. How do you change this?

    2 min answer securityprocessinfluence
  5. Security Design Review intermediate

    Your security design review template asks for data flows, trust boundaries, authentication and encryption. A team submits a support assistant that reads customer ticket text and calls three internal APIs with a service account, one of which issues refunds. The template produces no findings. What would you add to it, and what would you leave alone?

    3 min answer security-design-reviewprompt-injectionconfused-deputyagents