Automating and Scaling of Threat Modelling for Cloud Native Archit... Hanna Papirna & Emma Yuan Fang
About this talk
This talk covers the complexities of threat modeling for cloud-native applications operating in Kubernetes cross-tenant environments. The speakers, Hanna Papirna and Emma Yuan Fang from EPAM Systems, present a block-based methodology that segments applications into four distinct domains: gateway, service mesh, identity management, and storage. This innovative approach enhances the scalability of threat analysis and integrates it into development workflows. Participants will also learn to implement threat modeling as code using declarative models validated in CI/CD pipelines. A demonstration showcases the optimal use of AI tools to identify security risks in intricate microservices applications and emphasizes how CNCF-graduated project controls mitigate several threats while revealing others that need addressing. Attendees will gain a repeatable workflow for threat modeling applicable to various cloud-native architectures.
More from this event
See all 436 talks →
Best of KubeCon + CloudNativeCon Amsterdam 2026
2:17
The Quiet Work of Forever: Sustaining Open Source Communities - O. Hope Amaechi-Okorie, JSON Schema
26:24
Evolving KServe: The Unified Model Inference Platform for Both Predictive and... F. Spolti & J. Lee
32:40
Preventing S3 Cost Storms: Applying Cortex’s Efficiency Lessons to I/O-Heav... A. Fishman-Lichterman
5:32