Frameworks / VAST
Threat Modeling · Scale & DevSecOps

VAST

Visual, Agile and Simple Threat modeling — designed to answer a problem the classic frameworks don't: how do you do threat modeling across hundreds of services and every sprint, not once at design review? VAST trades depth-per-model for consistency, automation and scale.

What it is

VAST is an enterprise-scale threat-modeling methodology built around automation and agile delivery. Its premise is that a method only protects an organisation if every team can use it and every change can be modeled — so it favours standardised, visual, tool-supported models over deep, artisanal, one-off analyses. It's the threat-modeling philosophy behind dedicated platforms rather than a whiteboard exercise.

How it works — the architecture

VAST distinguishes two complementary kinds of model, so the right audience works with the right view:

For developers

Application threat models

Built from process-flow diagrams that mirror how the application actually works — the view engineers can own and keep current.

For security & ops

Operational threat models

Built from data-flow diagrams across the infrastructure — the attacker's-eye view of how systems connect.

Both are designed to be standardised and automatable, so models can be generated, updated and checked as part of the pipeline rather than as a manual gate. That makes threat modeling a continuous activity that keeps pace with CI/CD instead of a bottleneck that blocks it.

How we audit your systems with VAST

How we implement it

VAST is the right choice when scale is the problem: many teams, frequent releases, and a need to make threat modeling a repeatable habit rather than a heroic one-off. We help you stand up the templates, integrate them into your DevSecOps toolchain, and train teams to self-serve — then use STRIDE for depth where a component warrants it. Findings stay mapped to OWASP, the EU AI Act and NIST so scale doesn't cost you auditability.

VAST is the methodology popularised by ThreatModeler. This page reflects NexusFinLabs' practice and is general guidance, not legal advice.

Scale threat modeling across your teams.