Product threat modeling for connected devices
Zybercomply guides manufacturers of connected products and embedded devices through a complete, documented cybersecurity risk assessment — from scope and assets to treatment and monitoring — with an AI assistant drafting each step.
Following the prEN 40000-1-2 §6 workflow
The wizard walks through the clauses in order: context and scope, assets and their confidentiality, integrity and availability needs, risk acceptance criteria, threat identification, risk evaluation, treatment and ongoing monitoring. Each step records evidence so the final report shows coverage of every §6.x requirement.
Threats per asset with STRIDE
For every asset the assistant proposes Spoofing, Tampering, Repudiation, Information disclosure, Denial of service and Elevation of privilege threats, drawing on the MITRE EMB3D catalogue of device threats and mitigations. You accept, edit or reject each one.
CRA and RED (EN 18031) risk assessment
The EU Cyber Resilience Act requires manufacturers of products with digital elements to perform and document a cybersecurity risk assessment, and radio equipment must meet the RED delegated act requirements assessed with EN 18031. The resulting risk register, treatment decisions and coverage report form the evidence for that technical documentation.
What you get
- A risk register with likelihood, impact and residual risk
- Documented acceptance criteria and treatment decisions
- A §6.x coverage report and monitoring log
- Print-ready PDF and Markdown exports