Behind the Book: Threat-Driven Software Development
Jul 15, 2026 · 59m
Summary
Microsoft security experts Michael Howard, Lee Holmes, Sean Hernan, and Sherrod deGraft-John discuss their new book, Threat-Driven Software Development. They explain how integrating threat intelligence into the software lifecycle helps developers prioritize security based on actual attacker behaviors. The conversation covers reducing developer toil, leveraging platform guardrails, and addressing modern challenges like AI and operational security to build more resilient systems.
Topics discussed
Introduction and guest backgrounds
Origin story of the book and author selection
Collaborative writing process and diverse perspectives
Threat modeling evolution and reducing developer toil
Platform security, crypto, and avoiding custom implementations
Unique structure: Threat intel stories driving technical content
Bridging security and engineering cultures
Operational security and AI in software development
Understanding threat actors as professional organizations
Foreword, acknowledgments, and real-world applicability
AI's impact on vulnerability discovery and security as a process
Final thoughts and recommendations for readers
Listen ad-free on Castria