From Experts to Everyone: How we democratize Threat Modeling at Ubisoft
Download resourcesAbout this session
Kristine Barbara, security director at Ubisoft, describes a multi-year effort to move threat modeling from an expert-only practice to something every development team owns. With about 110 security staff supporting roughly 8,000 developers, retrofitted security assessments were slow, quickly obsolete, and never felt worth the effort to teams shipping games. Her team secured executive sponsorship, appointed director-level champions, and rolled out gamified STRIDE-based training to 400 targeted staff, backed by a knowledge base, a community of practice, and a coaching squad for teams new to the practice. A hackathon-born AI assistant, CTM3000, was industrialized to guide teams through the method, suggest threats and mitigations from OWASP Top 10 and internal policy, and track adoption on a KPI dashboard. Engagement events, swag, and a coveted internal conference slot reinforced the culture shift. Results were mixed: training and knowledge-base use scaled well, but champions disengaged over time, some teams ran inconsistent 'flavors' of the practice, and users found the AI's time savings underwhelming. She closes on the pivot underway toward an agentic coding-assistant skill that automates the tedious parts of modeling, and takes an extended audience Q&A on validation, red-team coordination, and measuring coverage.
With 110 security staff supporting ~8,000 developers, traditional expert-led security assessments couldn't scale — so we set out to delegate threat modeling to the teams themselves, and that work is still in progress. This talk covers the early phase of turning threat modeling into a practice teams can own: the resistance, the champions and learning journey that got adopters moving, the AI tool built to speed it up, and what a six-month health check found so farmodeling remains expert-only, and DevOps teams ship designs without structured security insight—creating compounding security debt.
This talk shares how a security team at Ubisoft transformed threat modeling from a niche exercise into an everyday DevSecOps practice now spreading across multiple software development teams.
We’ll walk through the real transformation journey: engaging leadership to recognize the limits of centralized security, designing a shift-left strategy centered on practitioner ownership, and embedding threat modeling from theory into sustained practice.
Beyond mechanics, this session explores the human side of scale: driving adoption without mandate fatigue, selling the 'what's in it for me?', and enabling managers and teams to own security outcomes.
You’ll leave with practical lessons, adoption patterns that worked (and failed), and a realistic roadmap for scaling threat modeling in large software organizations—without scaling your security team.
Key takeaways
- Get named, visible executive sponsors who talk about the practice publicly and repeatedly; passive 'yes, we support this' backing is not enough to sustain a bottom-up security transformation.
- Pair any new training with something that activates ability right after, such as a coach, a community of practice, or an assistant tool; training alone does not translate into people actually doing the work.
- Expect champions to disengage as priorities and people change; give them a concrete playbook and recurring visibility commitments rather than relying on initial enthusiasm.
- Survey your own program periodically, not just launch it and go quiet; a six-month silence let adoption drift and inconsistent practices spread unnoticed.
- Set realistic expectations for an AI assistant embedded in a security process: measure whether it actually saves time and produces relevant output, rather than assuming the pitch that sold the project.
Speakers

Kristine Barbara is a security transformation leader at Ubisoft who turns security from a specialist function into a shared practice across the development community — through global programs in security culture, threat modeling, and behavior change.

