Threat Driven Software Development

Tue, Aug 4, 2026 3-minute read

If you’re a Blue Teamer trying to write secure services or secure an organization that does, Threat Driven Software Development is the book you’ve been looking for. This was a deep collaboration between Michael Howard, Sherrod DeGrippo, Shawn Hernan and I - and I’m so excited to be able to get this expertise into the world.

What excites me most about this book is that there are many resources on traditional Application Security: how to protect yourself from things like Cross-Site Scripting, Prompt Injection, and many other risks so carefully described in resources like the OWASP Top 10. But there aren’t resources on how to secure and protect the operational aspects of building an online service. How should you manage keys and identities? What’s the best way to isolate production from development? How should you secure your build systems?

Most importantly, the guidance in this book doesn’t come from idle speculation or building theoretical castles in the sky. This guidance comes directly from lessons Microsoft has learned over 25 years of inventing the Security Development Lifecycle, building and shipping secure online services, and now adapting to modern Threat Actors through the Secure Future Initiative.

You can buy Threat Driven Software Development from any of your favorite book sellers:

And if you’re interested in hearing Michael, Sherrod, Shawn, and I discuss the book in more depth, be sure to check out our appearance on the Microsoft Threat Intel podcast: Behind the Book: Threat-Driven Software Development

Here is the full Table of Contents:

Part 1 When Software Meets the Real World

  • Ch 1 Understanding the Threat Landscape
  • Ch 2 Security Is More Than One Team
  • Ch 3 Why Microsoft Adopted SFI
  • Ch 4 How Operational Security is Different
  • Ch 5 Understanding the Terrain
  • Ch 6 Controlling the Terrain

Part 2 The Role of AI in Security

  • Ch 7 AI Security Backgrounder
  • Ch 8 How Threat Actors Use AI
  • Ch 9 Defensive AI
  • Ch 10 Security Engineering with AI

Part 3 Threats to Systems

  • Ch 11 Build and Engineering Systems
  • Ch 12 Identities and Secrets
  • Ch 13 Production Tenants and Systems
  • Ch 14 Production Networks
  • Ch 15 Monitoring, Detecting, and Alerting
  • Ch 16 Response and Remediation
  • Ch 17 Product Security

Part 4 Learning from SFI An Implementation Playbook

  • Ch 18 Crawl, Walk, Run: How to add Security Discipline
  • Ch 19 Tracking and Quantifying Risk
  • Ch 20 Reducing Risk
  • Ch 21 Getting Ahead of Security Vulnerabilities

Part 5 Some Final Thoughts

  • Ch 22 Rethinking the Role of C and C++
  • Ch 23 Are We More Secure Today?