Solutions by industry

Threat modeling looks different depending on what you're regulated against. These guides map ThreatTree's DFDs, Attack Trees, and risk register to the specific work products your industry expects.

Auditors and regulators don't accept a generic architecture diagram as evidence. An ISO/SAE 21434 TARA needs damage scenarios and attack feasibility ratings. A HIPAA Security Risk Analysis needs documented threat identification and vulnerability analysis tied to ePHI. A SOC 2 audit needs continuous evidence of risk identification, not a slide deck from a year ago. The underlying discipline is the same everywhere — map the system, enumerate what could go wrong, rate the risk, decide what to do about it — but the vocabulary, the required artifacts, and how deep the paper trail needs to go all change by industry.

ThreatTree runs that discipline once and exports it in whatever shape your industry expects. Build a Data Flow Diagram of the system, decompose the threats that matter into Attack Trees, and roll findings into a risk register — tagging each one against STRIDE, MITRE ATT&CK, OWASP LLM/Agentic Top 10, MITRE ATLAS, or a compliance framework, all in the same model. Nothing gets rebuilt by hand for the next audit.

The seven guides below go deeper on what that looks like in practice: ISO/SAE 21434 TARA for automotive, FDA premarket cybersecurity for medical devices, PCI DSS v4.0 and Secure SLC for fintech, the HIPAA Security Rule for healthcare, IEC 62443-3-2's zone/conduit model for critical infrastructure, OWASP LLM/Agentic Top 10 and MITRE ATLAS for AI and ML systems, and SOC 2 Trust Services Criteria for SaaS.