
Sit, Stay, Fetch: How to Train Your AI for ASPICE
Six guardrails for AI agents in ASPICE assessments: scripts over prompts, persisted results and progress, batching, closed questions, prohibitions, flagging.
Read Article
Pierre Dammé
6 min readHolistic protection and seamless traceability for cybersecurity, functional safety, and the Cyber Resilience Act
OverviewMethodological excellence and tailored tools for model-based system and software engineering.
OverviewEnterprise software from a single source: AI integration, legacy migration and full-stack development — cost-efficiently and sovereignly hosted.
OverviewHolistic protection and seamless traceability for cybersecurity, functional safety, and the Cyber Resilience Act
Topic area
Format

Six guardrails for AI agents in ASPICE assessments: scripts over prompts, persisted results and progress, batching, closed questions, prohibitions, flagging.
Read Article
Pierre Dammé
6 min read
Asset identification and impact rating supply one half of the risk value: when an element of the item becomes an asset, whose damage a damage scenario describes, why the safety rating is not security's to set alone, and what keeps ratings comparable across projects.
Read Article
Jens Bühl
15 min read
100% link coverage does not mean ASPICE compliance. How a type check, a consistency check and a consistency score expose semantic inconsistencies with LLMs.
Read Article
Pierre Dammé
7 min read
The Item Definition sets the quality ceiling for the whole TARA — what abstraction level is right, why SBOM mapping forces a minimum resolution, and why a living model is the foundation for API and MCP integrations.
Read Article
Jens Bühl
9 min read
Independence is assessed once in a DFA workshop and never revisited. This whitepaper shows how the independence premise in ASIL decompositions can be verified continuously and machine-executed using graph theory.
Download Whitepaper
From risk definition to a living TARA: a 7-part guide to systematic cyber risk assessment, with direct mappings to CRA, ISO/SAE 21434, and IEC 62443.
Download Whitepaper
The CRA doesn't ask for a one-time risk analysis — it demands a permanently demonstrable security engineering process. How a Living TARA and the Security Digital Thread keep your risk picture continuously current and audit-ready.
Read Article
Dirk Leopold
6 min read
Excel template for CRA risk analysis: TARA in line with ISO 21434 and IEC 62443 — how to start methodically, what you can import, and when Excel becomes the bottleneck.
Read Article
Jens Bühl
6 min read
A TARA is not a threat catalogue — it is an auditable record of risk decisions: what it involves, how the process works, and when Excel reaches its limits.
Read Article
Jens Bühl
6 min read
CRA Article 14 reporting obligations take effect on 11 September 2026. This article walks through the complete notification process chronologically — from the initial assessment to the final report — and identifies the points where reporting processes break down in practice.
Read Article
Dirk Leopold
12 min read
AI can now produce TARAs, traceability matrices, and safety cases that are structurally complete and terminologically correct. That surfaces a question worth asking: what, exactly, is being verified? The problem is not AI-generated documentation. It is compliance processes that optimize for artifacts instead of the properties those artifacts were supposed to encode.
Read Article
Florian Antony
6 min read
How AI assistants reduce TARA creation from weeks to hours — and turn your threat analysis into a real competitive advantage.
Watch Webinar
Jens Bühl
Learn how TARA automation with itemis SECURE (formerly YAKINDU Security Analyst) makes cybersecurity processes in the automotive industry fundamentally more efficient.
Watch Webinar
Jonathan Mohring
Forget high-stress assessments with massive teams and mountains of manual documentation. Discover how to make a leap from five weeks to five hours.
Watch Webinar


itemis ANALYZE moves to the cloud — unlocking a new era of Agentic Engineering where your Knowledge Graph becomes the governance layer for your AI.
Watch Webinar


Your TARA is a compliance document. It should be the operational brain of your CSMS. This whitepaper shows how a Living Digital Thread transforms static security artifacts into a continuous, data-driven lifecycle operation.
Download Whitepaper
How leading OEMs and Tier-1 suppliers unite Functional Safety and Cyber Security enterprise-wide — without disrupting proven engineering environments.
Download Whitepaper
Will your product still be legally sellable in Europe after December 2027? This guide shows manufacturers how to approach CRA compliance in 7 structured steps and secure EU market access.
Read Article
Dirk Leopold
5 min read
itemis SECURE is now available on the web — collaborate on cybersecurity projects simultaneously from any device, just like Google Docs.
Watch Webinar


A design FMEA is mandatory under ISO 26262 — and expensive to create and maintain by hand. This whitepaper shows how the algorithmic nature of the FMEA method enables full automation from existing engineering work products.
Download Whitepaper
With software-defined vehicles, the start of production is no longer the end of development — a holistic approach to security is now essential.
Watch Webinar
Dirk Leopold
Modelix brings domain-specific languages to non-developers as a modern web application — while seamlessly integrating with powerful tools like JetBrains MPS.
Watch Webinar
Leading experts share why Automotive SPICE 4.0 is a cornerstone of automotive development and what the new version means for your projects.
Watch Webinar
Dynamic-TARA by VicOne and itemis automates vulnerability detection and feeds it directly into comprehensive threat analysis and risk assessment.
Watch Webinar
UN Regulation No. 155 hits motorcycles on July 1st 2029 — discover how to prepare your organization for the homologation challenge and emerging cyber threats.
Watch Webinar
Dirk Leopold
Understand the present challenges in risk management for OEMs and suppliers and learn how best-of-breed toolchains and knowledge graphs deliver real value.
Watch Webinar
Dirk Leopold
How threat analyses (TARAs) and secure data exchange protect the EV ecosystem — from charging infrastructure to the vehicle itself.
Watch Webinar
Dirk Leopold
Learn how model-based TARA tooling combined with knowledge graphs enables CSMS automation for type approvals and gives you the competitive edge.
Watch Webinar
Jonathan Mohring
Learn how to efficiently manage the TARA process, keep your TARAs up-to-date, and apply the 20-50-90 Rule to significantly reduce cybersecurity spend.
Watch Webinar
Dirk Leopold
ISO/SAE 21434 raises the bar for automotive cybersecurity — from company-wide CSMS governance to threat analysis and product-level security controls. This guide, co-authored by itemis and Deloitte, walks you through every clause that matters.
Download Whitepaper
Learn why transitioning from spreadsheet-based TARAs to automated processes is essential and how to harmonize your TARA landscape across OEMs and suppliers.
Watch Webinar
Jens Bühl
For CFOs and auditors, a new family of threats and controls is emerging: cybersecurity controls and audit reports for their companies' connected products.
Watch Webinar
Dirk Leopold
ISO/SAE 21434 and UN Regulation 155 require cybersecurity across the full vehicle lifespan — from development through maintenance to decommissioning. Learn the most important lifecycle aspects and best practices.
Watch Webinar


Get an overview of threat and control catalogs that speed up your ISO/SAE 21434 compliant TARAs throughout the entire vehicle lifespan.
Watch Webinar
Jens Bühl
UN Regulation 155 and ISO/SAE 21434 require the entire automotive industry to ensure security over the entire lifespan of the vehicle.
Watch Webinar


UN Regulation 155 and ISO/SAE 21434 require the entire automotive industry to ensure security over the entire vehicle lifespan — from development through maintenance to decommissioning.
Watch Webinar
Dirk Leopold
Traceability is more than a compliance checkbox. Learn what it means in software and systems engineering, what insights it unlocks, and what challenges come with it.
Read Article
Florian Antony
5 min read
In the automotive domain, security is becoming more and more important – especially for the new generations of connected, (semi-)autonomous vehicles. Learn how to develop a secure system design and which additional security challenges may arise.
Read Article
Dirk Leopold
9 min read
In times of Spectre and Meltdown it's totally clear that security is a big engineering challenge. Learn more about safety and security in this post.
Read Article
Dirk Leopold
8 min read
The increased share of software solutions places high demands on Automotive Security. But what changes are coming for the industry and manufacturers?
Read Article
Dirk Leopold
5 min readA requirements traceability matrix is not just a bookkeeping tool. Learn the five key questions it answers in day-to-day project work — plus one bonus question.
Read Article
Florian Antony
6 min read
Requirements coverage is demanded by process standards like Automotive SPICE, yet remains poorly defined. Learn what it really means and how to measure it properly.
Read Article
Florian Antony
6 min read
A requirements traceability matrix (RTM) is a simple table that establishes bidirectional traceability across your project. Learn what it is and how to build one in four steps.
Read Article
Florian Antony
5 min read
An empirical study with 71 subjects shows that requirements traceability leads to 24% faster task completion and 50% more correct solutions during software maintenance.
Read Article
Florian Antony
4 min read