ThreatModeler Software, Inc. has acquired IriusRisk for an undisclosed amount, marking a significant expansion in the application security landscape. IriusRisk, known for its open Threat Modeling platform, automates and supports the creation of threat models during the design phase of software development. Its platform provides actionable recommendations to address identified risks and facilitates the management of security risks throughout the entire software development lifecycle (SDLC) through best-in-class architectural diagramming and extensive customization options, enabling seamless collaboration among all stakeholders.
This strategic acquisition is set to enhance ThreatModeler's capabilities by integrating IriusRisk's advanced design-time threat modeling and SDLC risk management features. The combination of IriusRisk's automated approach to identifying and mitigating security vulnerabilities early in the development process with ThreatModeler's strategic position in the application security market is expected to create a more comprehensive and robust offering for customers. The move underscores a commitment to providing integrated solutions that streamline security practices from conception through deployment.
The integration of IriusRisk's platform will allow the combined entity to offer a more holistic approach to application security. IriusRisk's ability to generate threat models with practical recommendations directly at the design stage, coupled with its tools for continuous risk management and stakeholder collaboration, aligns with the growing demand for proactive and automated security measures. This synergy aims to empower organizations to embed security more effectively and efficiently into their development pipelines.
Looking ahead, the unified company is poised to deliver an expanded suite of solutions designed to address the complex and evolving challenges of software security. By combining their respective strengths, ThreatModeler and IriusRisk will focus on accelerating the adoption of automated threat modeling and integrated risk management, ultimately enabling customers to build more secure software faster and with greater confidence.

