

TMC Singapore: Threat Modeling World Cup
Partake in Threat Modelling Through a Friendly Competition!
TMC Bangalore, TMC Japan and TMC Singapore are proud to bring you the Threat Modelling World Cup! Teams face off through presenting their threat models in a limited time, and presenting their results.
Each participating team will be presented with a common business scenario at the start of the competition. Each team will have 30 minutes to understand the scenario, analyze the threats, organize the risks, and then create a PowerPoint presentation.
This is tough! But through the competition, you will be pushed beyond what you believed you were capable of, in identifying cyber threats before they happen.
Each team will then present their results to other teams and participate in a question-and-answer session. The winning team will be determined through the votes of other participating teams.
Purpose
The Threat Modeling World Cup aims to achieve:
Learning of practical threat modeling while having fun competing.
Facilitating collaboration among participants from different perspectives, such as security, development, product, and business.
Sharing diverse threat modeling concepts and approaches
Developing the ability to explain security risks in an easy-to-understand manner to different stakeholders.
Learning from one another!
Flow of the competition
1. Presentation of Business Scenario
The organisers (TMC chapters) will present a scenario common for all teams. The scenario includes the following.
Service Overview
Business objectives
Users
Main Features
Data flow
Prerequisites
System Configuration
All teams will be given the same scenario.
2. Threat Modeling (30 minutes)
Each team will complete a threat model and create a presentation within 30 minutes.
The submission is a presentation, not a report.
While you are free to design your presentation as you wish, they must be clear and concise, and the content must be easily understood within the time limit.
For example, we recommend including the following:
Understanding business scenarios
Important assets
Users and attackers
Trust boundary
Potential threats and exploitation scenarios
Impact on business
Risk assessment and prioritization
Recommended measures and design improvements
Assumptions, trade-offs, and reasoning
You are also free to propose any threat modelling framework as you deem fit. These can include:
STRIDE
Attack Chain/Attack Tree Analysis
Abuse Case (a persona-non-grata approach)
Combination of frameworks
As long as the approach is logical and achieves the objective of clear threat enumeration, it will receive credit.
3. Presentation
Each team will give a 10 minute presentation to other teams and participants and take a Q&A for 5 minutes.
We are not solely looking for a “list of threats”. Rather, we are looking for the thought process behind the threat modelling work being done. Prompting Claude for “a list of 100 threats” is unlikely to be as good a submission as one where fewer threats are listed, but are contextualised.
In other words, we want to see these questions being answered:
How did you understand the scenario?
Why did you consider that threat important?
How did you assess the risks?
What measures will you propose to mitigate these risks?
How do you know if these measures are “good enough”?
4. Voting
After all presentations and Q&A sessions are complete, the participating teams will vote. One vote per team, and no voting for your own team. Please vote for the team that performed the best threat modeling based on the following criteria.
Quality of analysis
Practicality
Presentation skill
The team with the most votes will be declared the winner.
In the event of a tie, the winner will be determined by additional voting or a decision made by the organisers, as will be announced on the day of the event.
Voting Criteria
Please use the following points as a reference when making your evaluation.
Business Understanding: Did you correctly understand the scenario's purpose, value, users, and constraints?
Discovery of a threat: Were realistic and meaningful threats and exploitation scenarios identified?
Risk Analysis: Were you able to adequately explain the impact of the threat on the business and prioritize it
Quality of countermeasures: Were the proposed measures practical and effective?
Ease of understanding the model: Were the system configuration, assets, trust boundaries, and data flows clearly and concisely organized?
Presentation: Were you able to explain things clearly within the limited time and respond appropriately to questions?
Originality: Were there any new perspectives or excellent insights?
Participants
We welcome the following types of people:
Security Engineer
Software Engineer
Architect
Product Manager
QA Engineer
SRE/Infrastructure Engineer
Student
Threat Modelling Practitioners
For those who want to learn threat modelling through practical experience
Prior experience is not required. If there is demand, we will conduct a 30 minute crash course.
Team Composition
Each team will consist of 2 to 5 people as a basic requirement.
What to Prepare
Each team should have:
Laptop capable of running PowerPoint
Tools for creating diagrams and slides
Threat modelling templates or frameworks you normally use (optional)
An environment where teams can collaborate for 30 minutes.
While templates can be prepared in advance, the business scenarios will not be revealed until the start of the competition.
Agenda
Opening (5 minutes)
Rule explanation (5 minutes)
Business scenario presentation (10 minutes)
Teamwork (30 minutes)
Team presentations (10 minutes each)
Question and answer session (5 minutes each)
Voting
Results Announcement
Closing
Rules of Engagement
Do not interfere with the work of other teams.
Each team gets one vote.
Voting for your own team is prohibited.
Do not include confidential, unreleased, or third-party confidential information in your slides.
The deliverables you create may be shared in accordance with the event's sharing policy.
The voting results will be the final decision (except in the case of a tie).
How to Apply
Please register by signing up on Luma. Please also contact us if you have a choice of preferred team members. If you do not have a preference of teams, we will help you form a team.
Code of Conduct
1. The spirit of respect
We ask that all participants, speakers, sponsors, and volunteers treat each other with respect, regardless of gender, sexual orientation, disability, appearance, body size, race, ethnicity, age, religion, or technology choice.
2. Prohibition of Harassment
The following types of harassment are not tolerated within the community:
Use of sexual language or images
Threats, stalking, harassment
Offensive comments and jokes
Disclosure of other people's personal information
Other inappropriate behavior
3. Participant Responsibilities
Attendees of the meetup are responsible for following these rules. If you witness any harassment, you are required to report it to the organizers.
4. The role of the organizer
The organizers will take appropriate action against any conduct that violates the code of conduct, including issuing warnings or ordering removal from the meetup.
5. Ensuring a safe environment
Our goal is to provide a safe and positive experience for everyone. We ask that each participant contribute to this goal.