IriusRisk, a leading platform in automated threat modelling, has announced the launch of ‘Jeff: AI Assistant’, a groundbreaking tool designed to help developers and architects generate threat models from image or text inputs. This marks a major advance in the cybersecurity industry as ‘Jeff’ is the first secure-by-design tool that fully leverages the latest AI technology to automate the creation of threat models.
The new AI assistant uses cutting-edge artificial intelligence to analyse inputs, which could range from simple sketches to transcriptions of discussions about a product concept. From this, ‘Jeff’ generates a preliminary draft of a threat model, complete with identified threats, weaknesses, and possible countermeasures. By automating the early stages of the process, the tool enables security teams and software architects to begin their threat modelling faster than ever before.
José López Muñoz, Head of AI at IriusRisk, highlighted the importance of ‘Jeff’ in today’s fast-evolving cybersecurity landscape. “As cyber threats become increasingly complex with the advent of AI, it’s vital that the models used to protect software evolve just as quickly. With ‘Jeff’, we’ve built a tool that enables businesses to confidently create secure-by-design software from the start, streamlining what was traditionally a time-consuming and intricate process.”
AI Revolution in Threat Modelling
Unlike other large language models, ‘Jeff’ focuses specifically on generating actionable insights for threat modelling. The AI assistant is capable of processing inputs in just two to three minutes, producing a tailored outline of a threat model ready for further refinement. According to IriusRisk, this drastically reduces the time it takes to create a functional threat model, enabling users to skip several initial steps.
IriusRisk’s platform, widely used by organisations to detect security flaws and risks in software design, automatically generates potential threats and countermeasures before any code is written. The addition of ‘Jeff’ represents a significant advancement, allowing businesses to generate threat models at a scale and speed not seen before.
‘Jeff’ is available to both paying customers and users of IriusRisk’s free Community Edition platform. Over the coming years, it will be continuously improved and integrated into all IriusRisk products, ensuring users can benefit from its capabilities across various systems.
Addressing Cybersecurity Challenges
The launch of ‘Jeff’ comes at a critical time for the cybersecurity industry, as concerns about AI-driven cyberattacks continue to rise. Earlier this year, the UK’s National Cyber Security Centre (NCSC) warned that AI could lead to an increase in cyberattacks by lowering the barrier of entry for less sophisticated hackers.
In response to this growing challenge, IriusRisk has been focusing on AI-driven solutions to help businesses stay ahead of evolving threats. The company’s latest innovation builds on its previous work, such as the launch of its AI and ML Security Library, which helps organisations model their machine learning systems to identify and mitigate potential security risks before they are developed.
The company’s strategic investment in AI technology has driven significant growth, with a 50% increase in Annual Recurring Revenue (ARR) reported from December 2022 to December 2023. As IriusRisk continues to expand its AI capabilities, the introduction of ‘Jeff’ is expected to further enhance its reputation as a leader in automated threat modelling solutions.
With this new tool, IriusRisk aims to address one of the key challenges in threat modelling—namely, the time it takes to create data flow diagrams and threat models—by harnessing the power of AI to streamline the process.