# How to be secure by design and not pay millions? — Damian Rusinek | Composable Security

- Speakers: Damian Rusinek
- Channel: [ETH Belgrade Community](https://streameth.org/eth-belgrade-community)
- Date: 2025-10-07
- Duration: 21:08
- Topics: People & Blogs
- Watch: https://streameth.org/watch/yt-9STaG0ihoA4
- YouTube: https://www.youtube.com/watch?v=9STaG0ihoA4

## Description

How to be secure by design and not pay millions? — Damian Rusinek | Composable Security

## Transcript

Hello, thank you for introduction. And now let's start talking about the important things, right? The cars. This is Dodge Challenger, a super car. At least that's my opinion. You can disagree with me. Doesn't really matter. You can use your car here. But the truth is that this car is super fast. Looks very nice, right? But this car wouldn't go that fast, wouldn't go at full performance without four important things. The tires. It has to have a great tires to go full speed. And you may ask why am I talking about the cars. We are at if Belgrade. It's about security. It's tech. But the answer is simple. This car is your project. If you are building one or planning to build one, if you're investing in one, this car is your project. And you also need four tires to be secure and to go at full performance. And today I'm going to talk about four tires of security for your project. These are threat modeling, in-house security competences, uh security advisory and I won't mention the fourth now, but give me a few minutes. Let's start with the first one. Threat modeling. Basically, it's an exercise where you try to find um many scenarios that can break your system, break your protocol, break your process, whatever. And the idea is that um when you have those when you are aware of what can go wrong, you bring some mitigations and you're good like you're you're safe. And there are very different methodologies to do that. Some of them are very big ones and hard to follow or hard to start. And I want to show you our very simple methodology and that will allow you to do it in your team without any help. And you have three points. First of all, you need an object uh that you will build this model for. And this can be a project which is obvious and you need to visualize it somehow. So the best visualization for the project is probably the architectural diagram or some kind of business flow diagram or a mix of that. But the object can be also different. If you remember the bybit hack the the problem there was with the process of signing a transfer. So the process itself can also be a object of threat modeling. And the quite obvious visualization of a process is a flow diagram. Right? Here's an example of a diagram. You don't have to read that. Don't don't worry if you if you can't uh well yeah you can't read that. But uh this is just an example of how a diagram can look that ex that describes some small project. This is actually uh V4 hook that's integrated with a pancake. And this is the first step. You have a visualization of your project. You have all those components. You have external components which is pancake in this case. You have those business operations uh the oval ones um and the users or to be more precise the actors that can use your project. Next you have three questions. First question is what are we have do we have to protect? So you have to identify your key assets. Some of them are obvious like tokens kept by the hook or kept in the pool manager managed by the hook. But others are not that obvious. For example, availability. Right? This is you cannot visualize it very easily. But if you lose availability, your project is down. No users can't use it. We'll probably take out their liquidity and you'll be dead. Your project will be dead. Then the question is who? So who is the potential attacker here? And here again some uh some answers are very simple like all the roles all the users of the project can be a potential threat actor all the external depend dependencies. So the projects that you use uh for example oracles that you use to get some information um can be potential threat because if something bad happens to the oracle it influences your system and also there is one more actor an anonymous user the most important one right and then you have a question how so when you have uh the things that you have to protect and you know who can potentially try to attack your system, then you have to answer the question, how could they could this particular role, this threat actor attack my system to get this key asset? And this this is very specific for for projects. Some of um uh some of the uh threat scenarios are similar for many different projects. Some of them are very specific and you note them on your system. And this is a very simple kind of threat model. And now when you have uh your thread model, you have your uh diagram, you have your uh thread scenarios. So you actually know what can go wrong, you have to decide what to do with that. And you have a couple of options. you can either and if it's possible you should do that mitigate the risk. So for example if the issue is that somebody can access um can access our project some functions um in an unauthorized manner. We might add some modifiers in the code uh or some kind of access control system that will mitigate this risk. Next, you can accept the risk. For example, at the initial stage of your project, you you have a a centralized project. You're going to use multisync to configure your project for some time and then when you grow, you will do a DAO or you just revoke the ownership and make the project fully permissionless. So, you accept some risks at the beginning. The risk of uh losing a key and losing access to the protocol for example. And then you can delegate and of course if you are building on Ethereum and any other blockchain you already delegate some risks for example the uh denial of service risk you are using somebody the infrastructure provided by somebody uh if you are doing in web two you're probably going to use some cloud services because you know that it's hard to maintain your own infrastructure and if you don't have to do it and you can pay for that you will probably do that to delegate the risk related to the infrastructure. And this is the slide that summarizes uh the methodology the TLDDR of this uh threat modeling methodology that I mentioned h and it mentions all those questions. The the next thing is that there are more questions of course but I'm not going to answer them uh today. H I'm gonna tell you who can try to answer them in a sec because here we have the second tire the in-house security competences and you could say that let's hire CISO chief information security officer and uh he'll take care of everything within our company. The truth is that it's not a good idea. First of all there's not many of them that know web three. uh it's going to be super expensive uh and they are not up to date with your project. So they will have to spend a lot of time to learn your project, learn your team, go through that. And if you are already growing, it's actually too late. He will he won't make it. So there there is there are other options. The first option that you should start as soon as possible is this security champion program. The idea here is that you build uh security competences um on the people that you have within your uh team. So you have to find the best candidate to become a security champion. How to find this person? First of all, you can ask your whole team who likes security, who'd like to do some research in security. And this is the first and I would say an enough uh requirement to start um making this person a security champion. And then you have to specify some goals for that person. For example, you they can answer all those questions about threat modeling, right? When to do it, what to threat model first, how to do it, I can't remember from this slide. I didn't take the picture of the previous slide, so I can't remember. go find this those slides and tell me what when and how we going to do. But you also have to give them some responsibilities. These people have to have some power and need to deliver something. Of course, they will need some extra time for that. So you can tell your for example developer that now you're going to develop 50% of your time and the other 50% is spent on security. Um and it will pay off in time. Why is it better option than CISO? First of all, you don't have to hire uh a new person. Of course, sometimes you have to build a lot. There is a de hard development phase and you don't have time uh of your people to to put in security. But you really should try to find this time. This person will know your product already. So they they know how it works. They know people. So they know their organizational security within your company if it exists of course and this can be your point of contact in terms of security. So any question internal from the team or external from I don't know some security providers whoever maybe maybe some bug bounty initial internal bug bounty all those questions will go uh to that person and then they will distribute it over the team and you should treat this person this security champion as your to be CISO because they will be your CISO at some time but they need to learn it on your project. Next thing is resources. There is plenty of them in the internet. A lot of are open source. But the problem is that you need to find the the best ones. You need to find those that help with your real problems with the problems that your project has. And you can how can you find them? First of all, this can be um um task for your security champion, right? then you can try to find it by yourself and also you can ask your advisor but I'll I'll come back to that in a sec. Of course I have a few examples. The first one is smart contract security verification standard that we actually created uh so I'm based about that but um this is uh we try to make it quite easy to use. This is basically a security checklist but divided into different categories and you don't have to go through all that. You select those categories that are applicable to your project. For example, if you integrate with tokens, if you're building a token, building a bridge, integrating with bridges, etc. Then there is soludit very nice aggregator of uh issues and vulnerabilities coming from different uh reports, different contests all at one place that you can filter and you can for example ask your security champion to find uh the vulnerabilities that have been identified in projects similar to ours. And you can build an uh internal knowledge base where you the first article will be about the common mistakes in the projects like ours. Very specific kind of resource are procedures especially emergency procedures. They basically answer the question what do we do now when there is a hack or there is a reported critical bug in your production system or you lost the key. Um, so you have to know the answer to this question before any of this happens because if it happens and you don't have the answers, it's too late. If you are if you have a bug critical and somebody reported that your phones are at risk. So there is no time to learn how to do it. H you should know that or at least somebody in your team should have a paper and throw it on the table. Okay, we are at emergency situation. And here's what we do. And you don't have to build it from scratch. You can reuse existing ones. This one is from year finance. And very nice uh starting point. Uh okay. The uh third tire is security advisor. And I wanted to ask you please raise your hand if you are building any project and you have somebody or from outside your company not internal team that um can answer your security related question. Basically do you have a security advisor that's external in your company? Please raise your hand. Okay, great. Not not many people, but I'll try to show you that it's a good idea to have such person and it will not cost a lot. It doesn't have to cost a lot. This this might be a myth that it will be very expensive to initiate this topic. Actually I need to mention something that engineer was mentioning that audits is not the all security all about the security there are consultations there are some opinions on design etc and it's nice to have somebody that you can ask about for example their opinion sec in terms of security about your new design of some specific feature of course they don't have to answer it straight away h or they may not they may even not know the answer but they probably have a network and they will have somebody who might know the answer to your questions. So it's really nice to have such person and it doesn't have to be a big network you it can be a one person that has this network and the last but not least the fourth is even if you understand what I said and even if even if you agree with me and even if you want to implement the stuff that I mentioned you won't make it if you don't have an action plan and this is the fourth you need to have an action plan with a list of tasks small enough to be uh done in short time because otherwise you will never have time to finish them and big enough to reach some security milestones. And if I had to give you one slide of my presentation, this would be this one. This is very very draft very alpha uh version of a action plan uh to build to start building your security road map. I've seen many road maps most of them focused on features right we're going to deliver this in Q1 this in Q2 this and Q in Q3 none of them maybe not none but very few of them mentioned any security and if they did it was an audit so Q4 audit that's it security is done right and there is plenty of different uh other services that you can And that's why I wanted to give you a bonus which is a practical security guide that we have created which covers different security services and gives you some practical knowledge, gives you some uh connections to the companies that deliver that. It's not like ours. It's not that we give all those security services. There are uh different auditors, different back bounty uh platforms, uh threat modeling mentioned there a lot of stuff worth uh checking for sure of course for free. Uh feel invited to to check it out and actually that's that's all from me. Thank you. &gt;&gt; Thank you Damian. Uh we can start with a Q&amp;A session. Do we have any questions? I actually have a question for the audience. So you asked uh how many have an adviser, security adviser? How many do you have internal security person in the company full-time? &gt;&gt; Okay. So it's the same ratio. &gt;&gt; You can't raise for yourself. &gt;&gt; But as you can see, it's not that much. like two people have security advisor and two people have internal security guy uh guy or girl &gt;&gt; uh in the in the team. So it's really there's a place to to improve and hopefully this will help you in some way to to do that. &gt;&gt; Okay. &gt;&gt; Okay. Uh there's a question there. How do you see the trends of this uh going forward and uh do the trends vary between let's say a very small company a very large company protocol? Um just curious your perspective uh which option people choose. &gt;&gt; Um so I'll start from from the end. I see the difference between large companies and uh and small new startups um how they treat security and you can you can see the maturity. I'm not saying about all of them. I'm talking about um the ones that we have uh um cooperated with. I see this difference. So this um there is a hope that when you grow you will not only have to but you will want to take care of security seriously. Um and uh talking about trends um I see the shift which is good because that's what we are trying to achieve as well and this shift left a bit this is still an issue in web two uh for years but so we are not there in web three for sure but we uh we noticed this shift um so people are seeing the the value in thread modeling they like to have a big picture on the security of their protocol. People see uh the dangers the threats coming from uh outside web three I mean uh outside of smart contracts like for example any web two components because all projects have web two components. So, so yeah, I I I'm I hope and I'm pretty sure it's going to be better uh even though we just lost like 1.5 billion, right? Because of uh small bug in uh or rather unauthorized access to some uh Amazon bucket Amazon, sorry. Okay, if that's all, let's please give Damian a big applause. Thank you.
