itemis SECURE is the model-based platform for both standards. Instead of fragmented spreadsheets, a living security model is created: TARA, risk assessment, measure tracking and reporting in one tool, with AI support for threat intelligence and attack trees, and with documentation that passes an audit.
The lever is reuse and maintenance. A TARA modelled once can be scaled across variants, new vulnerabilities flow into the model, and the compliance evidence is a by-product of the work, not a separate effort before the audit.
Agentic on a deterministic model
The AI support is not a bolted-on add-on. The agentic capabilities sit on a deterministic model layer, so the AI does not work in a vacuum but uses the complete TARA context. Via the Cybersecurity Lifecycle Integration, the system connects requirements, architecture components and software vulnerabilities with end-to-end traceability directly in the security model. The heavy lifting runs automated, the expert retains control, and every conclusion is grounded in real engineering data.
What the AI concretely handles
- Conversational TARA: create, edit and refine risk analyses via a natural language interface.
- Embedded TARA expert: an integrated assistant contributes domain knowledge and proactively suggests complex threat scenarios.
- Full context awareness: the engine knows requirements, SysML models and previous TARAs. All suggestions are anchored to the concrete architecture.
- Deterministic governance: every AI suggestion is checked against a model-based rule set and adheres to rule sets and industry standards.
- Human-in-the-loop: all suggestions are versioned and show where and when the AI made a proposal, verifiable, adjustable, rejectable.
Typical use cases
- TARA review and completeness check: comparison of the model against known threat patterns uncovers blind spots, missing assets and implausible attack paths.
- Agentic triage and vulnerability sync: assisted triage of SBOM vulnerabilities with automatically proposed TARA updates and extended attack trees based on new CVEs.
- Automatic item definition: accelerated generation from existing artefacts such as requirements, specifications and architecture diagrams.
- Interview mode: the agent asks targeted questions about the system and populates the model automatically, instead of sending the user through menus.
Architecture and business value
| Pillar | Function | Benefit |
|---|
| Lifecycle Management | End-to-end security traceability across development and product lifecycle | Eliminates virtually all manual documentation work for audits |
| Model-Based Governance | Industry-specific rule sets, plausibility and consistency checks | AI suggestions comply with guidelines and regulatory requirements |
| Agentic Automation | Context-aware, automated generation of TARA elements with human-in-the-loop | Up to 80 % less TARA time |
| Live Vulnerability Sync | Continuous triage of SBOM components and CVEs | Living documents for ISO/SAE 21434, IEC 62443 and CRA |
According to itemis, agentic automation reduces TARA effort by up to 80 %, with full human-in-the-loop control. This way even small teams maintain a living security posture and serve ISO/SAE 21434, IEC 62443 and CRA from one model.
itemis SECURE is used by cybersecurity teams in automotive and industry, including ZF, AVL and Sygic.