Shostack + Associates
Shostack + Associates is a Seattle-based threat modeling training and consulting firm founded by Adam Shostack, delivering instructor-led courses, self-paced online learning, expert witness services, and proprietary frameworks (Four Question Framework, SCORE) to enterprise security teams and practitioners globally.
- Company typePrivate
- Founded2021
- HeadquartersSeattle, United States
- Headcount1–10
- GTM typeB2B
- OfferingServices
What Shostack + Associates does
Shostack + Associates is a Seattle-based, privately-held threat modeling training and consulting firm founded in 2021 by Adam Shostack, a co-creator of the CVE system and a former member of Microsoft's Security Development Lifecycle team. The firm sells instructor-led training (corporate on-site, conference workshops at Black Hat, OWASP Global AppSec, and RSAC, and open-enrollment intensives), self-paced online courses through a Thinkific-powered LMS and LinkedIn Learning, expert witness services, and an enterprise "Secure Design Accelerator" coaching program. Its product portfolio is anchored on a proprietary Four Question Framework and the STRIDE methodology, supplemented by threat modeling card and board games (Elevation of Privilege, Control Alt Hack, FuzzNet Labs, Byte Club) and three published books, including the field's foundational 2008 text "Threat Modeling: Designing for Security."
The firm's customer base consists of security practitioners and enterprise security programs seeking to operationalize threat modeling, with named engagements in medical devices (MDIC) and healthcare technology (Google Health). Revenue is generated through a mix of professional services (training, consulting, expert witness), subscription/self-paced course sales, channel royalties (LinkedIn Learning, Cybersec Games), and book royalties. The go-to-market combines event-driven training delivery with a community-led content engine, including a blog active since 2004-2005, a YouTube channel, and active social profiles on LinkedIn, Infosec Exchange, and Bluesky.
In 2025-2026, the firm expanded its curriculum with "Scaling Threat Modeling" and "Threat Modeling AI Systems" courses, the latter co-developed with Cranium's Michael Novack and introducing the SCORE framework for AI explainability. The firm operates from Seattle with 1-10 employees, has no disclosed external funding, and is structurally dependent on Adam Shostack as the principal instructor, author, and brand.
Shostack + Associates firmographics
Firmographics- Name
- Shostack + Associates
- Legal name
- Shostack + Associates
- Website
- https://shostack.org
- Company type
- Private
- Founded year
- 2021
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Shostack + Associates is a Seattle-based threat modeling training and consulting firm founded by Adam Shostack, delivering instructor-led courses, self-paced online learning, expert witness services, and proprietary frameworks (Four Question Framework, SCORE) to enterprise security teams and practitioners globally.
- Ownership category
- akta.pro rank
Shostack + Associates industry classification
Industry- Product category
- Cybersecurity Consulting and Training
- NAICS
- Professional and Management Development Training (61143), Computer Training (611420)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Security Consulting, Risk Assessment & Security Program Design (BPABAMAE)
- akta.pro secondary industries
- Security Risk Assessment, Auditing & Security Consulting Training (BPAKAOAH), Role-Based Secure Practices (Privileged Users, Finance/AP, HR, Executives) (EDABAGAJ), Executive/Board Security Advisory & Risk Briefings (BPAKADAK)
Keywords
Where Shostack + Associates is headquartered
LocationHeadquarters
- HQ city
- Seattle
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Shostack + Associates business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D
Revenue model
- Training Services: Threat modeling training delivered in corporate, open enrollment, and virtual formats. Includes standard and customized content, instructor-led and computer-based training. Courses range from short sessions to multi-day intensives at conferences and on-site.
- Consulting Services: Expert witness services and consulting engagements for organizations implementing threat modeling or secure-by-design programs
- Course Platform (courses.shostack.org): Online learning management system powered by Thinkific, delivering self-paced threat modeling courses including Threat Modeling AI Systems
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Pay-as-you-go | Free introductory courses and minute-long lessons |
| Subscription | Multi-year contract | Conference training (BlackHat, OWASP) |
Go-to-market motion2 records
Distribution channels5 records
Marketing channels5 records
Shostack + Associates product offering
Product offeringCore offering
Shostack + Associates provides threat modeling training delivered via instructor-led courses at security conferences and on-site at client organizations, self-paced online courses, and computer-based training, alongside consulting and expert witness services. The firm also runs a Secure Design Accelerator coaching program to help organizations establish threat modeling and secure-by-design practices, and publishes interactive games and books that teach threat modeling concepts.
Product overview
Shostack + Associates is a threat modeling-focused training and consulting firm led by Adam Shostack. Their offerings include instructor-led training courses (Threat Modeling Intensive, Threat Modeling AI Systems, Scaling Threat Modeling, Threat Modeling for Security Champions), self-paced learning via LinkedIn Learning, educational games (Elevation of Privilege, Control Alt Hack, FuzzNet Labs, Byte Club), expert witness and consulting services, and published books on threat modeling and security. The portfolio centers on helping organizations build threat modeling capabilities through hands-on training, games, and ongoing coaching programs.
Differentiator
Problem solved
Functional benefit
Products and services
- Threat Modeling Intensive Hands-on, instructor-led training program that teaches participants to threat model through the four-question framework. Includes corporate and open courses, standard or customized content, and instructor-led and computer-based training formats.
- Threat Modeling AI Systems In-depth technical course for security professionals already familiar with threat modeling that focuses on unique challenges AI brings to modern applications, including data science foundations, ML model security, training data pipelines, and how AI system behavior differs from traditional software.
- Scaling Threat Modeling Course focused on implementing threat modeling practices across organizations, covering team structures, processes, and scaling approaches for larger security programs.
- Threat Modeling for Security Champions Course designed to expand distributed class structure and train security champions within organizations to perform threat modeling.
- LinkedIn Learning Courses Online video-based threat modeling courses available through LinkedIn Learning for self-paced professional development.
- Secure Design Accelerator Coaching engagement that accelerates organizations' threat modeling and secure design programs, helping define goals, develop plans, identify obstacles and a path through them to start threat modeling initiatives.
- Expert Witness Expert witness services for legal cases involving security, threat modeling, and software security matters.
- Consulting Advisory services for organizations seeking to improve their security practices, threat modeling processes, and secure development lifecycles.
- Elevation of Privilege Threat modeling card game designed to make security concepts accessible through interactive gameplay, helping teams identify vulnerabilities in system designs.
- Control Alt Hack Cybersecurity-themed board game that teaches threat modeling and security concepts through collaborative gameplay.
- FuzzNet Labs Board game where players build an analogue AI model by hand, used as an interactive learning tool to establish shared context on how AI models are constructed before engaging with technical course content.
- Byte Club Cybersecurity awareness card game that puts players in real-world security decisions, making dense security concepts accessible and memorable for broad audiences.
- Threat Modeling: Designing for Security Adam Shostack's comprehensive book on threat modeling methodologies, frameworks, and security design practices, originally published in 2008 as a foundational text in the field.
- Threats: What Every Engineer Should Learn From Star Wars Book using Star Wars examples to teach essential security and threat modeling concepts to software engineers, published in 2020.
- The New School of Information Security Book exploring contemporary approaches, challenges, and evolving perspectives in information security, co-authored by Adam Shostack with Gary McGraw and published in 2012.
Companies that use Shostack + Associates
Customer profileNamed customers2 records
Segments1 record
Ideal customer profiles3 records
Shostack + Associates technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
Feature3 records
Shostack + Associates partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered minor.
- Cybersec GamesminorCybersec Games distributes threat modeling games including Elevation of Privilege. They also host interactive game sessions at conferences (OWASP Global AppSec EU Vienna). Currently offering Elevation of Privilege at 13% off.
- Alpha Strike and Limes SecurityminorPartnered with Alpha Strike and Limes Security to deliver training at Embedded Systems Security Days in Vienna (November 6-8, 2019). Combined expertise for embedded systems security training delivery.
- CraniumminorMichael Novack is an AI Security & Safety Engineer at Cranium while also serving as course designer and instructor at Shostack + Associates. Work on AI explainability (SCORE Framework) being presented at OWASP Global AppSec EU.
- MDIC (Medical Device Innovation Consortium)minorAdam Shostack contributed to MDIC webinar on medical device threat modeling playbook. MDIC awarded funding for 'Expansion of Case for Quality and Cybersecurity Threat Modeling' initiative.
- Continuum SecurityminorAdam Shostack joined Continuum Security's advisory board. Collaboration on software security approaches emphasizing developer responsibility for security.
- Irius RiskminorGary McGraw, a pioneer in software security, joined Irius Risk Technical Advisory Board as board chair. Adam Shostack noted this as significant development for the threat modeling community.
Scale indicators2 records
Recent moves6 records
Expansion highlights5 records
Shostack + Associates competitors and assessment
Company assessmentDirect peers
- Irius Risk: Threat modeling platform vendor that competes with Adam Shostack's consulting practice by offering automated threat modeling tooling, while also partnering with the threat modeling community. Irius Risk is directly comparable as a threat modeling authority with both product and advisory offerings.
- Security Compass: Provides SDLC security and threat modeling services and tooling (SD Elements), serving similar enterprise clients seeking to embed secure-by-design practices. Overlaps with Shostack + Associates' consulting and training on threat modeling within development lifecycles.
- ThreatModeler: Threat modeling automation platform competing for the same enterprise customers seeking to scale threat modeling programs. Comparable as a category leader whose platform-centric approach is an alternative to Shostack's training-led methodology.
- Continuum Security: Threat modeling consulting firm with which Adam Shostack sits on the advisory board. Direct peer providing consulting and training around threat modeling and secure development to enterprise clients, particularly in European markets.
Broad incumbents
- NCC Group: Large global security consulting firm offering threat modeling and security advisory services as part of a broader portfolio. Comparable as a competitor for enterprise threat modeling consulting engagements but at much larger scale and broader scope.
- Bishop Fox: Established offensive security consulting firm providing application security and threat modeling advisory services to enterprise clients. Comparable as a broader security consulting incumbent that includes threat modeling in its advisory portfolio.
- Trail of Bits: Security consulting and research firm that publishes extensively on application security and threat modeling. Comparable as a technical security consultancy that competes for enterprise advisory engagements and contributes thought leadership to the threat modeling community.
- SANS Institute: Dominant cybersecurity training organization offering courses across multiple security disciplines including application security. Comparable as a broader cybersecurity training incumbent whose curriculum competes for corporate training budgets alongside Shostack's specialized threat modeling courses.
Others
- SAFECode: Nonprofit consortium publishing secure development guidance and training resources for the software industry. Comparable as an adjacent thought leader in secure-by-design practices whose guidance overlaps with threat modeling training content.
- OWASP Foundation: Open-source security community producing widely-adopted application security guidance and standards. Comparable as a community-led authority on application security practices that shapes the demand environment for specialized threat modeling training.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat4 records
Key risks5 records
Key highlights6 records
Customer concentration
Shostack + Associates social profiles
Digital presenceShostack + Associates financial estimates
Financial estimateRevenue estimate
Valuation estimate
Shostack + Associates leadership team
Management profileNumber of profiles
Profiles3 records
Shostack + Associates funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Shostack + Associates M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Shostack + Associates
What does Shostack + Associates do?
Shostack + Associates provides threat modeling training delivered via instructor-led courses at security conferences and on-site at client organizations, self-paced online courses, and computer-based training, alongside consulting and expert witness services. The firm also runs a Secure Design Accelerator coaching program to help organizations establish threat modeling and secure-by-design practices, and publishes interactive games and books that teach threat modeling concepts.
Is Shostack + Associates a public or private company?
Shostack + Associates is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was Shostack + Associates founded?
Shostack + Associates was founded in 2021. It employs 1 to 10 people.
Where is Shostack + Associates based?
Shostack + Associates is headquartered in Seattle, United States, in the North America region.
How does Shostack + Associates make money?
Three revenue lines are on record. Training Services are the primary driver. The others are consulting Services and course Platform (courses.shostack.org).
Who are Shostack + Associates's main competitors?
Direct peers on record are Irius Risk, Security Compass, ThreatModeler and Continuum Security. Broad incumbents are NCC Group, Bishop Fox, Trail of Bits and SANS Institute. Others are SAFECode and OWASP Foundation.
Does Shostack + Associates have an API?
No public API is recorded for Shostack + Associates.
What industry is Shostack + Associates in?
Shostack + Associates's product category is Cybersecurity Consulting and Training. Its primary akta.pro industry code is BPABAMAE, Security Consulting, Risk Assessment & Security Program Design, with a secondary code of BPAKAOAH, Security Risk Assessment, Auditing & Security Consulting Training. Its NAICS code is 61143 and its SIC code is 8742.