VAST
Visual, Agile and Simple Threat modeling — designed to answer a problem the classic frameworks don't: how do you do threat modeling across hundreds of services and every sprint, not once at design review? VAST trades depth-per-model for consistency, automation and scale.
What it is
VAST is an enterprise-scale threat-modeling methodology built around automation and agile delivery. Its premise is that a method only protects an organisation if every team can use it and every change can be modeled — so it favours standardised, visual, tool-supported models over deep, artisanal, one-off analyses. It's the threat-modeling philosophy behind dedicated platforms rather than a whiteboard exercise.
How it works — the architecture
VAST distinguishes two complementary kinds of model, so the right audience works with the right view:
Application threat models
Built from process-flow diagrams that mirror how the application actually works — the view engineers can own and keep current.
Operational threat models
Built from data-flow diagrams across the infrastructure — the attacker's-eye view of how systems connect.
Both are designed to be standardised and automatable, so models can be generated, updated and checked as part of the pipeline rather than as a manual gate. That makes threat modeling a continuous activity that keeps pace with CI/CD instead of a bottleneck that blocks it.
How we audit your systems with VAST
- We standardise the model — a consistent template every team uses, so coverage is comparable across the estate.
- We wire it into the pipeline — models created and updated as part of delivery, not as an after-the-fact review.
- We split the views — process-flow models for developers, data-flow models for security, kept in sync.
- We include AI services — LLM and agent components modeled with the same discipline and OWASP LLM coverage.
How we implement it
VAST is the right choice when scale is the problem: many teams, frequent releases, and a need to make threat modeling a repeatable habit rather than a heroic one-off. We help you stand up the templates, integrate them into your DevSecOps toolchain, and train teams to self-serve — then use STRIDE for depth where a component warrants it. Findings stay mapped to OWASP, the EU AI Act and NIST so scale doesn't cost you auditability.
VAST is the methodology popularised by ThreatModeler. This page reflects NexusFinLabs' practice and is general guidance, not legal advice.