CISOs Are Struggling to Threat-Model AI. Can 15-Minute Sessions Help?
CSO Online, Wednesday, August 19th, 2026
Threat modeling expert Adam Shostack tries a 15-minute format to assess a vibe-coded app handling customer data.
CSO Online follows threat-modeling expert Adam Shostack, who received an email from a client on a busy day. Someone at that organization had vibe-coded an application and put it to work with customer data, and the client wanted to know what risks the tool posed and what to do about them.
They needed answers quickly, so Shostack gave himself 15 minutes to produce them. The article uses the exercise to examine whether short, structured threat-modeling sessions can keep pace with AI-accelerated development.
The argument is that CISOs need a faster, more practical way to identify new risks without losing sight of security basics.