Blog

Strategy, Risk & Compliance

Threat modeling is also a business tool. This collection is for security leaders who need to connect design risk with strategy, compliance and governance. Topics include regulated industries such as financial services and healthcare, third-party and M&A risk, programs like FedRAMP and how to build a threat modeling practice that scales.

Latest articles

PASTA Threat Modeling Methodology

Blog

PASTA Threat Modeling Methodology

PASTA is a risk-centric, 7-step threat modeling methodology that ties technical risk to business impact and compliance.

Read More
OCTAVE Threat Modeling Methodology

Blog

OCTAVE Threat Modeling Methodology

OCTAVE threat modeling is a risk assessment methodology for organizational cybersecurity risk. See how OCTAVE, OCTAVE-S, OCTAVE Allegro, and OCTAVE FORTE work.

Read More
ThreatModeler Achieves FedRAMP Moderate Authorization

Blog

ThreatModeler Achieves FedRAMP Moderate Authorization

Bringing continuous, automated threat modeling to federal agencies without slowing down the mission.

Read More
Why Healthcare M&A Requires Threat Modeling: Before the Deal Closes

Blog

Why Healthcare M&A Requires Threat Modeling: Before the Deal Closes

Healthcare M&A deals inherit far more than revenue — see why threat modeling needs to be a non-negotiable part of due diligence, not an afterthought.

Read More
Start Left At Design: Lessons From a CISO Panel

Blog

Start Left At Design: Lessons From a CISO Panel

A CISO panel reveals why most "shift left" efforts still fail — and why real progress starts with design review, not later-stage scanning.

Read More
Why Threat Modeling Your Third-Party Integrations Should Be Standard Practice

Blog

Why Threat Modeling Your Third-Party Integrations Should Be Standard Practice

A weak admin password exposed candidate data on McDonald's AI hiring platform — a reminder that vendor integrations deserve the same threat modeling rigor as your own systems.

Read More
Modern Threat Modeling for Financial Services: Cybersecurity and Compliance at Scale

Blog

Modern Threat Modeling for Financial Services: Cybersecurity and Compliance at Scale

With financial-sector breaches averaging $5.9 million, see how modern threat modeling helps banks and fintechs close the visibility gaps manual processes can't scale to cover.

Read More