Loading...
AI Security Engineering / Pillar
Structured threat modelling for AI-integrated systems — before the audit finds the gaps. Prompt injection now appears in over 73% of production AI deployments. Model your risks before you deploy them.
Definition. AI threat modelling is the practice of systematically identifying threats to AI-integrated systems using structured frameworks like STRIDE and DREAD, then documenting the controls that mitigate each threat. It covers prompt injection, training data poisoning, model extraction, inference-time manipulation, and the emerging class of MCP and tool-poisoning threats.
Prompt injection remains the number-one vulnerability in the OWASP LLM Top 10 and appears in over 73% of production AI deployments (Obsidian Security, 2026). AI-assisted cyberattacks increased 72% year-over-year, with the average cost of an AI-powered breach at US$5.72M (AI Security Intelligence Q1 2026 report).
94% of World Economic Forum respondents identify AI as the most significant driver of cybersecurity change in 2026. If your organisation is deploying AI into any production workflow — customer service, code generation, decision support, security operations — a threat model is now table stakes for defensibility.
CyberTeam applies STRIDE and DREAD to your specific AI architecture, mapping threats to the OWASP LLM Top 10, the MCP threat taxonomy (arXiv 2603.22489), and NIST AI Risk Management Framework categories. The output is a document your architects, engineers, and internal audit can all work from.
Coverage
Every AI threat model covers, at minimum:
Frameworks
Every threat model produces mappings to the standards your organisation is measured against:
Output
You get a document your architects, engineers, and internal audit can each use for their own purposes:
Regular threat modelling assumes deterministic system behaviour. AI systems have probabilistic outputs, learn from data, and can be manipulated through natural-language input. The threat classes (prompt injection, model extraction, training data poisoning) do not exist in traditional systems. CyberTeam uses STRIDE and DREAD as the structural framework but the threat taxonomy is AI-specific.
The OWASP LLM Top 10 is a checklist. A threat model is a structured analysis of your specific architecture. The checklist tells you what to look for; the threat model tells you which of those apply to your system, how bad each one is in your context, and which controls you have to mitigate them.
A focused threat model of a single AI-integrated system takes 5-10 working days. A comprehensive threat model of an enterprise AI deployment (multiple systems, agents, and MCP integrations) takes 3-4 weeks. Both include architecture workshops, threat identification workshops, and a formal deliverable review.
We use whatever your team already uses if it exists (Microsoft Threat Modeling Tool, IriusRisk, ThreatDragon). If you have no existing tooling, we produce the threat register as a structured Markdown document that renders cleanly in Confluence, Notion, or your Wiki of choice — because tooling is a delivery detail, not a value driver.
Yes. Every threat modelling engagement includes a knowledge-transfer workshop for your security architects. We show the method, the tooling choices, and the reasoning behind each threat. Many clients run their next threat model in-house using our reference.
A 30-minute call gives you a clear picture of what a threat modelling engagement would look like for your AI systems. We will scope it honestly and tell you if it is the right instrument for your current risk position.
Talk to Tom