Threat Modeling 101: An A–Z reference of threat modeling, secure-by-design, and cybersecurity terms.
The continuous process of identifying, assessing, and managing the various points of an organization's attack surface.
Automated threat modeling uses AI and threat frameworks to build models and assess security risks continuously across the development lifecycle.
How threat modeling and TARA support automotive cybersecurity compliance across ISO/SAE 21434, UNECE WP.29, and global regional frameworks.
How threat modeling identifies and mitigates blockchain security risks like 51% attacks, smart contract exploits, and consensus manipulation.
Identifying and addressing threats in cloud environments through specialized security considerations and mitigation strategies.
An automated security practice that keeps threat models updated throughout development as systems evolve, rather than relying on a single snapshot.
How threat modeling supports critical infrastructure cybersecurity compliance across NIST CSF, NIS2, and global regional frameworks.
The distinctions and connections between cyber risk, cyber threat, and cyber vulnerability, and how they relate to threat modeling.
Cyber risk management is the process of identifying, assessing, and controlling threats and vulnerabilities to an organization's IT systems and operations.
How threat modeling supports financial services cybersecurity compliance across NIST, DORA, MAS, APRA, and global regional frameworks.
How threat modeling supports healthcare cybersecurity compliance across HIPAA, GDPR, PDPA, and global data protection frameworks.
Intelligent threat modeling is the next evolution of secure-by-design, adding contextual awareness, guided insights, and continuous visibility.
How threat modeling supports manufacturing cybersecurity compliance across NIST, MLPS 2.0, CMMC, UAE NIA, and global frameworks.
OCTAVE (Operationally Critical Threat, Asset, and Vulnerability Evaluation) is a business-oriented framework for assessing and prioritizing organizational cyber risk.
Operational threat modeling gives a holistic view of infrastructure, people, and processes to manage threats across an entire operational environment.
PASTA (Process for Attack Simulation and Threat Analysis) is a seven-step, risk-centric methodology combining attacker analysis with business impact.
Security countermeasures are technologies, policies, or practices that reduce system vulnerability and protect against cyber threats.
A framework for identifying and categorizing six types of security threats to help developers address vulnerabilities early in development.
Threat analysis identifies potential threats, assesses their severity and impact, and develops mitigation plans across an organization's attack surface.
A threat boundary (or trust boundary) is a dividing line between areas of systems where security controls should be implemented between trust zones.
A threat intelligence framework is a structured system that gathers, analyzes, and applies threat data to improve organizational defenses.
A threat library is a central repository of known threats, vulnerabilities, attack methods, and predefined patterns for creating threat models.
Threat modeling methodologies are structured approaches like STRIDE, PASTA, OCTAVE, and VAST used to identify, analyze, and mitigate security threats.
A trust zone groups system elements sharing similar security requirements and trust levels to enable appropriate protection across networks.
VAST (Visual, Agile, and Simple Threat modeling) is a scalable framework for detecting and prioritizing threats to enterprise applications and IT systems.
A simple starting point
Book a personalized demo and see agentic, governed threat modeling on the Secure Design Graph, built into your SDLC.