Skip to content
Book Open access

"How do security threats affect my work?" - Software Developers’ Mental Models of IT Security Threats and Mitigation Strategies

Aug 2026 · Message Understanding Conference · 0 citations · 29 references
Computer Science

Abstract

While end-user decisions primarily impact their own data, software developers’ security behavior can affect millions of users’ data. To understand developers’ decision-making processes, we explored their mental models of security threats. We conducted semi-structured interviews, based on Wash [89] with 37 professional software developers and categorized the threats they discussed using the STRIDE threat modeling approach. We describe three mental models of threat types: Developers focused on threats as exploits, vulnerabilities, or the impact of the threat. Besides development-specific threats (e.g., injection-, denial-of-service attacks), they also expressed concerns about end-user threats (e.g., malware, phishing attacks). We identified mitigation strategies used across threats: soft skills (e.g., communication), hard skills (e.g., security tools and libraries), and organizational strategies (e.g., IT infrastructure). We also discovered distinct roles through which developers engage with security threats, including collaborator, end-user, tool-user, and business roles. We provide recommendations on supporting developers in managing security risks and decisions.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.