Solutions by industry
Threat modeling looks different depending on what you're regulated against. These guides map ThreatTree's DFDs, Attack Trees, and risk register to the specific work products your industry expects.
Auditors and regulators don't accept a generic architecture diagram as evidence. An ISO/SAE 21434 TARA needs damage scenarios and attack feasibility ratings. A HIPAA Security Risk Analysis needs documented threat identification and vulnerability analysis tied to ePHI. A SOC 2 audit needs continuous evidence of risk identification, not a slide deck from a year ago. The underlying discipline is the same everywhere — map the system, enumerate what could go wrong, rate the risk, decide what to do about it — but the vocabulary, the required artifacts, and how deep the paper trail needs to go all change by industry.
ThreatTree runs that discipline once and exports it in whatever shape your industry expects. Build a Data Flow Diagram of the system, decompose the threats that matter into Attack Trees, and roll findings into a risk register — tagging each one against STRIDE, MITRE ATT&CK, OWASP LLM/Agentic Top 10, MITRE ATLAS, or a compliance framework, all in the same model. Nothing gets rebuilt by hand for the next audit.
The seven guides below go deeper on what that looks like in practice: ISO/SAE 21434 TARA for automotive, FDA premarket cybersecurity for medical devices, PCI DSS v4.0 and Secure SLC for fintech, the HIPAA Security Rule for healthcare, IEC 62443-3-2's zone/conduit model for critical infrastructure, OWASP LLM/Agentic Top 10 and MITRE ATLAS for AI and ML systems, and SOC 2 Trust Services Criteria for SaaS.
Automotive
Build the Threat Analysis and Risk Assessment (TARA) work products ISO/SAE 21434 calls for — assets, damage scenarios, attack paths, feasibility, and risk treatment.
Read the guide → FDA Premarket CybersecurityMedical Devices
Build the threat model, architecture views, and risk assessment FDA's premarket cybersecurity guidance expects in a 510(k), PMA, or De Novo submission.
Read the guide → PCI DSS & Secure SLCFintech
Build the cardholder data environment threat model, targeted risk analysis, and evidence PCI DSS v4.0 and the PCI Secure SLC standard expect.
Read the guide → HIPAA Security RuleHealthcare
Build the threat identification, vulnerability analysis, and risk determination a HIPAA Security Risk Analysis expects.
Read the guide → IEC 62443 & NERC CIPCritical Infrastructure
Build the zone/conduit model and detailed risk assessment IEC 62443-3-2 calls for, without connecting to your OT network.
Read the guide → OWASP LLM Top 10 & MITRE ATLASAI & ML Systems
Tag attack tree nodes with OWASP LLM/Agentic Top 10 and MITRE ATLAS, natively alongside STRIDE and MITRE ATT&CK.
Read the guide → SOC 2 Trust Services CriteriaSaaS & Startups
Build the continuous risk-identification evidence SOC 2's Trust Services Criteria expect -- without a dedicated security team.
Read the guide →Get new threat-modeling guides by email as they're published — no more than one a week.