Skip to content
Book Open access

"How do security threats affect my work?" - Software Developers’ Mental Models of IT Security Threats and Mitigation Strategies

Aug 2026 · Message Understanding Conference · pp. 88-112 · 0 citations · 29 references
Computer Science

TL;DR

This work conducted semi-structured interviews with professional software developers and categorized the threats they discussed using the STRIDE threat modeling approach, finding distinct roles through which developers engage with security threats, including collaborator, end-user, tool-user, and business roles.

Abstract

While end-user decisions primarily impact their own data, software developers’ security behavior can affect millions of users’ data. To understand developers’ decision-making processes, we explored their mental models of security threats. We conducted semi-structured interviews, based on Wash [89] with 37 professional software developers and categorized the threats they discussed using the STRIDE threat modeling approach. We describe three mental models of threat types: Developers focused on threats as exploits, vulnerabilities, or the impact of the threat. Besides development-specific threats (e.g., injection-, denial-of-service attacks), they also expressed concerns about end-user threats (e.g., malware, phishing attacks). We identified mitigation strategies used across threats: soft skills (e.g., communication), hard skills (e.g., security tools and libraries), and organizational strategies (e.g., IT infrastructure). We also discovered distinct roles through which developers engage with security threats, including collaborator, end-user, tool-user, and business roles. We provide recommendations on supporting developers in managing security risks and decisions.

Read PDF

Similar papers

Open access 2026

Web application security using top 10 OWASP

It is concluded that web application security requires continuous assessment and proactive security practices throughout the software development lifecycle, and adopting OWASP guidelines and implementing effective security controls can significantly enhance the protection and resilience of modern web applications.

S. Banu, H. Shanmatha, Mehdi Gheisari et al. · 0 citations
#software testing Preprint Sep 2026

Investigating Developer-Reported Software Security Testing Challenges

Overall, developer-reported SST challenges extend beyond vulnerability detection and include workflow, configuration, interpretation, and remediation concerns and can help researchers, practitioners, educators, and tool providers improve SST usability, documentation, result interpretation, and remediation support.

Md Erfan, A. Ryan, Md. Rayhanur Rahman · 0 citations
Review Open access Sep 2026

Security of The Model Context Protocol Ecosystem: Emerging Threats, Empirical Attack Evidence, Trust and Authorization Failures, Supply-Chain Risks, And Defensive Strategies

- The rapid adoption of agentic artificial intelligence has transformed large language models into agents that can discover tools, access resources, process information, and execute actions in external environments. The Model Context Protocol (MCP) supports this transformation by enabling standardized interaction betwe...

Khalid D. Muhammed, David Chinonso Anih · 0 citations
Review Sep 2026

(Don't) Trust, but (Don't) Verify: Developers'Attention to Security in AI-Generated Code

AI coding assistants are rapidly transforming software development, but are known to produce insecure code. Prior work has measured whether AI-assisted developers produce secure code, but less is known about how they evaluate AI-generated code: whether they can identify vulnerabilities, what cues they use, and how trus...

Hamza Khalid, Ronald E. Thompson, A. Sabater et al. · 0 citations
Open access Aug 2026

‘Follow the Money. Or Jail Time.’ Perspectives on the Role of Senior Management in Secure Software Development

The number of recorded vulnerabilities in software continues to rise, despite attempts to improve secure coding practice. Much software security research focuses on software developers’ abilities, tools and motivations. However, software security budgets and priorities ultimately derive from an organisation's senior ma...

Ita Ryan, U. Roedig, Klaas-Jan Stol · 0 citations
Review Open access Oct 2026

Towards trustworthy foundation models: a systematic review of safety, evaluation, and defence mechanisms

Large Language Models (LLMs) and foundation models are increasingly deployed in security-critical and high-impact settings, including healthcare, cybersecurity, software engineering, and intelligent infrastructure. Their open-ended interfaces and multimodal capabilities create new attack surfaces, where prompt injectio...

Abdullahi Chowdhury, Tasmim Jamal Joti, M. Afikuzzaman et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.