Solutions by industry
Threat modeling looks different depending on what you're regulated against. These guides map ThreatTree's DFDs, Attack Trees, and risk register to the specific work products your industry expects.
Automotive
Build the Threat Analysis and Risk Assessment (TARA) work products ISO/SAE 21434 calls for — assets, damage scenarios, attack paths, feasibility, and risk treatment.
Read the guide → FDA Premarket CybersecurityMedical Devices
Build the threat model, architecture views, and risk assessment FDA's premarket cybersecurity guidance expects in a 510(k), PMA, or De Novo submission.
Read the guide → PCI DSS & Secure SLCFintech
Build the cardholder data environment threat model, targeted risk analysis, and evidence PCI DSS v4.0 and the PCI Secure SLC standard expect.
Read the guide → HIPAA Security RuleHealthcare
Build the threat identification, vulnerability analysis, and risk determination a HIPAA Security Risk Analysis expects.
Read the guide → IEC 62443 & NERC CIPCritical Infrastructure
Build the zone/conduit model and detailed risk assessment IEC 62443-3-2 calls for, without connecting to your OT network.
Read the guide → OWASP LLM Top 10 & MITRE ATLASAI & ML Systems
Tag attack tree nodes with OWASP LLM/Agentic Top 10 and MITRE ATLAS, natively alongside STRIDE and MITRE ATT&CK.
Read the guide → SOC 2 Trust Services CriteriaSaaS & Startups
Build the continuous risk-identification evidence SOC 2's Trust Services Criteria expect -- without a dedicated security team.
Read the guide →