Skip to main content
AutoSec Innovation

Risk assessment

Threat Analysis and Risk Assessment Aligned to ISO/SAE 21434

Identify assets, damage scenarios, threat scenarios, and attack paths, then assess risk consistently so engineering teams can prioritise controls with evidence.
Threat analysis and risk assessment pathway

At a glance

  • Concept
  • Architecture
  • Verification
Standards referenced
ISO/SAE 21434UNECE R155
Core deliverables
  • Item definition
  • Asset and damage scenario register
  • Threat scenarios and attack paths
  • Risk assessment record

The problem we are asked to solve

  • TARA results differ between teams because the method is applied inconsistently.
  • Risk ratings cannot be explained during assessment or audit.
  • Threat scenarios are not connected to real architecture or interfaces.
  • Risk treatment decisions are never revisited after the concept phase.

What changes as a result

  • A repeatable, documented TARA method across programmes
  • Risk decisions that can be explained and defended
  • Clear link between threat scenarios and cybersecurity goals
  • A maintainable basis for later verification activities

Scope of work

What the engagement covers

Scope is agreed per programme. These are the activities we most often deliver for this service.

  • Item definition and asset identification
  • Damage scenario and impact rating
  • Threat scenario identification
  • Attack path analysis
  • Attack feasibility rating
  • Risk determination and treatment decisions
  • Cybersecurity goal derivation
  • TARA method definition and tooling support
  • TARA review and re-assessment

Engagement methodology

How we work

A predictable sequence, adapted to your process and release gates rather than replacing them.

  1. 01

    Define the item

    Bound the analysis: what is inside the item, which interfaces cross the boundary, and what is out of scope.

  2. 02

    Identify assets and damage

    Derive damage scenarios from consequences for road users and operators, then rate impact consistently.

  3. 03

    Build threat scenarios

    Identify threat scenarios and attack paths against the real architecture rather than a generic model.

  4. 04

    Rate and decide

    Assess attack feasibility, determine risk, and record treatment decisions with named owners.

  5. 05

    Derive goals

    Convert accepted risk treatment into cybersecurity goals and claims the engineering team can implement.

Deliverables

Every engagement ends with artefacts your organisation owns and can defend in review.

  • Item definition
  • Asset and damage scenario register
  • Threat scenarios and attack paths
  • Risk assessment record
  • Risk treatment decisions
  • Cybersecurity goals and claims

Relevant standards

We help organisations interpret and implement these requirements. We do not certify or approve organisations.

  • ISO/SAE 21434
  • UNECE R155

Typical use cases

  • First TARA for a new item or platform
  • Harmonising TARA method across business units
  • Re-assessment after architecture or feature change
  • Preparing risk evidence for a type-approval submission

Evidence

Case studies covering TARA and ISO/SAE 21434 work are being prepared for publication. Automotive security engagements are normally confidential, so we discuss comparable scope, method, and deliverables directly rather than publishing unverifiable claims.

Questions

Frequently asked

Which TARA method do you use?
We apply the ISO/SAE 21434 risk assessment structure and adapt the rating scheme to your existing method where one already exists, so results stay comparable across programmes.
Can you review a TARA we have already completed?
Yes. A review typically covers scope completeness, threat coverage, rating consistency, traceability to cybersecurity goals, and readiness for assessment.

Discuss Your Cybersecurity Program

Tell us where the programme is today and we will outline a realistic next step.