Threat Modeling
for Critical Infrastructure
IEC 62443-3-2 asks you to partition a system into zones and conduits, then run a detailed risk assessment on each. ThreatTree gives OT and ICS security teams a structured place to build that model entirely offline from the control system itself -- nothing installed on, or connected to, your OT network.
The zone/conduit risk assessment, mapped to ThreatTree
IEC 62443-3-2's risk assessment workflow moves through five stages. Each one has a direct home in a ThreatTree forest.
| IEC 62443-3-2 step | In ThreatTree | |
|---|---|---|
| 1 | System under consideration & asset identification PLCs, HMIs, historians, engineering workstations, SCADA/DCS servers |
Model each asset as a DFD process or data store, so the system under consideration is drawn, not just listed |
| 2 | Zone & conduit partitioning Group assets into zones by function and trust level; conduits are the connections between them |
Trust boundaries around each zone (e.g. IT/OT boundary, safety zone, process zone), with labeled data flows as conduits between them |
| 3 | Threat identification What could compromise each zone's availability, integrity, or confidentiality |
STRIDE tagging on every DFD element surfaces spoofing, tampering, and denial-of-service threats systematically across zones and conduits |
| 4 | Detailed risk assessment Unmitigated risk per zone, combining likelihood and consequence |
Attack Trees decompose each threat into AND/OR attack steps, linked back to the zone or conduit targeted, tagged with CAPEC and MITRE ATT&CK |
| 5 | SL-Target determination & countermeasures Assign a target Security Level per zone and select countermeasures |
Likelihood x Impact scoring generates a ranked risk register automatically across the forest, exportable as evidence for SL-T assignment and countermeasure selection |
What this is, and isn't: ThreatTree is a threat modeling tool, not a certification body or a substitute for an IEC 62443-qualified assessor. It gives your team a structured place to build the zone/conduit model and risk assessment the standard describes -- SL-Target assignment and countermeasure selection still require your OT security engineers' judgment, and it doesn't connect to or scan your control system network.
Built for OT teams that can't run agents on the network
Everything in a ThreatTree forest traces back to a zone or conduit, and every risk decision traces back to a rated attack path.
-
Zone-Based Trust Boundaries
Draw the IT/OT boundary and every zone inside it as nested trust boundaries in your DFD -- the same diagram your engineers already sketch on a whiteboard, made structured and exportable.
-
Attack Path Decomposition
Break each threat into an Attack Tree with AND/OR logic, from attacker goal to atomic step, so the path from an IT compromise to an OT consequence is documented, not assumed.
-
Prioritized Risk Register
Likelihood x Impact scoring generates a ranked risk register automatically across every zone in a forest, so SL-Target and countermeasure decisions are backed by traceable evidence.
-
Audit-Ready PDF Reports
Generate a report with the zone/conduit architecture, attack trees, and ranked risk register in a single PDF -- built to sit alongside NERC CIP or IEC 62443 audit evidence.
Critical infrastructure threat modeling, answered
What OT and ICS security teams ask before adopting ThreatTree.
Does ThreatTree connect to our OT network or SCADA systems?
No. ThreatTree is a modeling tool your team uses in a browser to document architecture and threats -- nothing is installed on, or connects to, any control system asset. Your zone and conduit model is built from what your engineers already know about the system, not from network access.
Does ThreatTree assign IEC 62443 Security Levels automatically?
No. ThreatTree's Likelihood x Impact scoring is method-agnostic -- your team determines the SL-Target for each zone using your chosen approach, and the resulting risk register reflects that scoring. ThreatTree does not compute the Security Level for you.
Does this satisfy NERC CIP audit evidence requirements?
ThreatTree helps you build and document the asset identification, risk assessment, and zone/conduit evidence NERC CIP-002 and CIP-010 describe. It is not a certification body or a substitute for your compliance team -- whether specific evidence satisfies an audit is your auditor's determination.
Can I model a single production line or a whole plant?
Both. A forest can scope down to one production line's zones and conduits, or up to a full plant spanning multiple zones -- the DFD layer and nested trust boundaries scale to either.
Start your zone/conduit model in ThreatTree
Free plan available -- no credit card required. Be up and running in minutes.