Skip to main content

itemis SECURE
Mastering cybersecurity risk

Create individual, consistent threat and risk analyses with minimal effort and adapt them within seconds. Threat modelling and risk assessment – verifiable and efficient – thanks to intelligent AI integration.

itemis references
Atruvia avitea Bauerhin BLG BSH DB Deutsche Bahn Denso Draeger ETAS Forvia-Hella Kostal magnotherm MAN ODAS parcIT Pixelboxx Remondis TECE Thalia ZF zurich

Analyze. Assess. Prove. Secure.

itemis SECURE is an AI-powered platform for threat analysis and risk assessment (TARA). It lets you model systems, identify threats and assess cybersecurity risks to ISO/SAE 21434, IEC 62443 and CRA. The results are available as consistent, audit-proof documentation.

Changes to the system can be carried into the analysis within seconds, and AI assistants speed up recurring tasks.

Book a demo
itemis SECURE editor screenshot
Compliance

Multi-standard support

itemis SECURE supports you in meeting the central cybersecurity standards – efficiently, verifiably and at scale.

ISO/SAE 21434

The automotive industry must demonstrate cybersecurity under ISO/SAE 21434 and UNECE R155. The challenge is time-consuming, fragmented and error-prone manual TARAs across multiple product lines and versions.

IEC 62443

IEC 62443 requires translating risk-based cybersecurity requirements into consistent, architecture-driven technical controls for complex industrial systems, while maintaining conformity and documentation.

EU Cyber Resilience Act (CRA)

The EU Cyber Resilience Act demands continuous cybersecurity across the entire product lifecycle: secure-by-design development, vulnerability management and regulatory documentation are all part of it.

DIN CLC/TS 50701

DIN CLC/TS 50701 governs cybersecurity in the railway sector and builds on IEC 62443. The challenge is to demonstrate threats and requirements consistently for the zones and conduits of railway-specific systems.

IEC 81001-5-1

Manufacturers must demonstrate the cybersecurity of medical devices under IEC 81001-5-1 and FDA requirements. This includes a documented threat and risk analysis across the entire product lifecycle.

Highly configurable

Your standard is not listed? Methods, assessment models and reports can be adapted to further standards and company-specific requirements. Get in touch, and we will set it up together with you.

Features

Features at a glance

End-to-end TARA

The complete threat and risk analysis in a single, linked model.

  • All TARA steps

    Item definition, assets, damage and threat scenarios, attack paths, risk and measures in one place.

  • Automatic risk calculation

    Every change is re-evaluated immediately and carried along the attack paths.

  • Consistent reports

    Reports and artifacts follow automatically, without manual reconciliation across spreadsheets.

AI assistants

AI speeds up the initial analysis and its maintenance – in the browser and in your own agents.

  • AI assistants

    From drafting new threat scenarios to revising existing assessments.

  • MCP interface

    Any MCP-capable agent works directly on your TARA model.

  • Your own AI provider

    Store the provider and access keys for your organization or for individual projects.

Your method

The tool adapts to your method, not the other way around.

  • Configurable models

    Risk, feasibility and impact models can be freely adapted.

  • Standard templates

    Preconfigured for ISO/SAE 21434 and IEC 62443 for a quick start.

  • All domains

    Automotive and industrial projects run side by side in one tool.

SBOM Integration

Your TARA knows which software is in your system.

  • Package mapping

    Link the components of the TARA to the packages of your SBOM.

  • Traceability

    Always visible which software is built into which part of the system.

  • Lifecycle Management

    The basis for a living TARA across the entire product lifecycle.

Editions

The three editions

itemis SECURE Classic

The desktop app for threat analysis and risk assessment compliant with ISO/SAE 21434, with interactive attack tree modeling and analysis.

itemis SECURE Cloud

The hybrid approach with real-time collaboration: work on multiple TARAs in parallel and automate collaboration and processes.

itemis SECURE Lifecycle Integration

Full V model coverage from requirements to start of production, with data from existing systems in a knowledge graph.

Feature matrix

What is in which edition?

Compare the scope of itemis SECURE Classic, Cloud and Lifecycle Integration.

itemis SECURE feature comparison by edition
Feature
itemis SECURE Classic
itemis SECURE Cloud
itemis SECURE Lifecycle Integration
Analysis & modeling
Threat analysis and risk assessment compliant to ISO/SAE 21434
Interactive attack tree modeling and analysis
Collaboration & automation
Hybrid approach and real-time collaboration
Working on multiple TARAs
Collaboration and automation of processes
Lifecycle Integration
Full V model coverage from requirements to start of production
Integration of data and information from existing systems into a knowledge graph
Risk-based decision-making considering multiple layers of dependencies
Customer success

Rely on proven TARA expertise

itemis SECURE is a versatile instrument that helps me make my work more dynamic and easier. With itemis SECURE I can meet my customers' needs.

Senior Cybersecurity Engineer

AVL Software and Functions

itemis SECURE, with its wide range of functions and features, enables project teams to produce comprehensive TARAs and supports assessors in carrying out effective independent reviews for ISO/SAE 21434 compliance.

TARA Assessor

ZF Group

Looking for an ISO-compliant tool, we came across itemis SECURE, which has become our standard TARA tool for automotive projects, helping us meet ISO 21434 and earn our customers' trust.

Pavol Bulka, CTO

Sygic

itemis SECURE is our TARA tool of choice; it helps me make my work more dynamic and easier. itemis SECURE enables me to meet our customers' needs.

Kálmán Simon, Technical Lead Cybersecurity

Knorr-Bremse

Insights

Insights on itemis SECURE

FAQ

Frequently asked questions about itemis SECURE

What is itemis SECURE?
itemis SECURE is an AI-powered platform for threat analysis and risk assessment (TARA). Systems are modeled, threats identified and cybersecurity risks assessed. The results are available as consistent, audit-proof documentation.
Which standards are supported?
ISO/SAE 21434, IEC 62443, the EU Cyber Resilience Act, DIN CLC/TS 50701 and IEC 81001-5-1. Methods, assessment models and reports can be adapted to further standards and company-specific requirements.
Which editions are available?
Three: itemis SECURE Classic (desktop app with interactive attack tree modeling), itemis SECURE Cloud (hybrid approach with real-time collaboration) and itemis SECURE Lifecycle Integration (V model coverage with data from existing systems in a knowledge graph). The feature matrix shows the differences.
How does AI support the analysis?
AI assistants speed up the initial analysis and its maintenance, from drafting new threat scenarios to revising existing assessments. Through an MCP interface, any MCP-capable agent can work directly on the TARA model. The AI provider can be stored for the organization or for individual projects.