British Insurance Services Provider moves from manual to automated threat modeling with IriusRisk.

From manual to automated

The company is a UK-based insurance services provider.

The company started threat modeling as a paper-based, tick-box exercise. However they did see the value in good design and the security teams saw the threat modeling process as  “measure twice, cut once’  for software security. In other words, design it right in the first place.

The outcomes...

Saves time thanks to the comprehensiveness of tooling with pre-baked libraries
Audit evidence collecting is much quicker, easier, and reliable
Scalability and easy adoption process for teams to use across the business

The assurance you provide to your clients is improved when they see you are threat modeling.  it provides transparency on how security was built into the product.

Director of Security Architecture