Skip to main content
Scaling Cybersecurity Engineering: How Co-Development with ZF Shaped itemis SECURE
Automotive industryCompliance Intelligence

Scaling Cybersecurity Engineering: How Co-Development with ZF Shaped itemis SECURE

ZF Group

ZF and itemis co-develop itemis SECURE, turning real-world automotive cybersecurity engineering challenges into reusable capabilities for catalog-based reuse, versioning, and dependency management.

Cybersecurity engineering becomes increasingly complex as products evolve across variants, releases, and lifecycles. What may start as an individual Threat Analysis and Risk Assessment (TARA) quickly becomes a broader engineering challenge: cybersecurity information needs to remain consistent, traceable, reusable, and maintainable as products and their environments change.

This is where itemis SECURE takes a different approach. Rather than treating cybersecurity analysis as a collection of isolated documents and spreadsheets, itemis SECURE provides a specialized, model-based solution for cybersecurity engineering. It connects cybersecurity artifacts and their dependencies in a consistent model, creating a reliable foundation for managing complex TARAs and evolving them throughout the product lifecycle.

Co-Development grounded in automotive reality

A key part of shaping this approach has been our long-standing Co-Development collaboration with ZF Group.

Working closely with ZF cybersecurity experts gave us continuous exposure to the realities of cybersecurity engineering in a complex automotive environment. Real-world workflows, requirements, and engineering challenges provided an invaluable basis for challenging concepts, validating capabilities, and determining where specialized tooling can create the greatest value.

The objective was never to build a customer-specific solution. Instead, itemis translates insights from real industrial use into reusable product capabilities that address challenges shared by cybersecurity engineering organizations across the industry.

This combination is at the heart of our Co-Development approach: ZF contributes extensive automotive cybersecurity expertise and practical experience from real engineering environments, while itemis contributes cybersecurity methodology, model-based engineering expertise, and product development capabilities.

From individual analysis to scalable cybersecurity engineering

The collaboration has helped evolve itemis SECURE beyond simply supporting the creation of compliant TARAs.

Capabilities such as catalog-based reuse, versioning, and dependency management address challenges that emerge when cybersecurity engineering needs to scale across projects, products, and variants.

Catalogs help teams reuse established cybersecurity knowledge instead of repeatedly creating similar artifacts. Versioning supports the controlled evolution of analyses as products change. Dependency management makes relationships between cybersecurity artifacts transparent and helps engineers understand the impact of changes across their analyses.

Together, these capabilities help turn cybersecurity analyses from project-specific deliverables into reusable and maintainable engineering assets.

For engineering teams, this means greater consistency and traceability while reducing repetitive work. For organizations, it creates the foundation for more scalable cybersecurity processes and helps preserve valuable engineering knowledge across projects and product generations.

Specialized where it matters. Integrated where it counts.

This focus also defines the positioning of itemis SECURE.

Rather than trying to replace existing engineering environments with another all-encompassing platform, itemis SECURE is designed as a specialized cybersecurity engineering solution that integrates into existing toolchains.

Its model-based approach provides the structure required to manage the complex relationships within cybersecurity engineering, while integrations connect cybersecurity activities with the wider development lifecycle.

This combination of specialized cybersecurity capabilities, model-based engineering, reuse, and toolchain integration is what enables organizations to move beyond isolated compliance activities toward systematic and scalable cybersecurity engineering.

Continuing the journey

The release of itemis SECURE Cloud in October 2025 marked an important milestone in making these capabilities available through a modern, collaborative solution. Since then, our Co-Development approach has continued to shape its evolution.

The next step extends the same principle beyond TARA: cybersecurity does not stop once an initial risk analysis has been completed.

Lifecycle integration, vulnerability management, and cybersecurity requirements management will increasingly connect initial risk analysis with the continuous evolution of products and emerging threats. AI-powered capabilities will complement this approach by helping engineers navigate growing amounts of cybersecurity information and streamline selected engineering activities.

Our collaboration with ZF continues to provide valuable real-world input into this evolution.

The underlying ambition remains unchanged: to make complex cybersecurity engineering manageable, reusable, and scalable — while integrating it into the engineering environments organizations already rely on.

Related Projects

Related References

Interested?

Become our next success story.