Seven white papers, one argument
Written in a burst — five of the seven inside four days at the end of May 2025 — the papers build on each other: a diagnosis of why threat modeling fails today, a graph-based mechanism to fix it, two papers scaling that mechanism to the supply chain, a bridge from technical findings to business impact, and a policy paper arguing threat models should be mandatory disclosures. A seventh, later paper is the commercial case, kept separate and labelled as positioning.
Attribution. Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” as co-authors in their front matter. That is kept visible on every paper page: this estate's position is that AI-assisted work should be legible as such, and hiding the co-authorship on the research about making security legible would be self-defeating.
Link, never rehost. Every paper page here is a one-screen summary and the key claims, with a link to the paper itself on docs.diniscruz.ai. This site's own release gate caps any quotation from the papers at 40 words.
Advancing Threat Modeling with Semantic Knowledge Graphs
Threats, assets, mitigations and incidents as nodes in a semantic knowledge graph, with MGraph-DB as the memory-first store — so overlaying STRIDE, MITRE ATT&CK and the OWASP Top 1…
Read the summary →Threat Models as Mandatory Disclosures
Security suffers a market-for-lemons problem — vendors know far more about their product's security than buyers do — and the proposed fix is to make threat-model publication a regu…
Read the summary →Graphs of Graphs of Graphs (G³) in Threat Modeling
The reference architecture behind the mechanism: multi-view, multi-graph modelling, organic file-based evolution of the threat graph over time, and ontologies/taxonomies/standards …
Read the summary →Using Threat Modeling and Semantic Graphs to Secure the Digital Supply Chain
Supply chain security taken as the hardest case for the graph approach: mandatory disclosure, semantic graphs as the foundation, then whole-supply-chain modelling with G³ for inter…
Read the summary →Scaling Supply Chain Security using Threat Modeling, Semantic Knowledge Graphs and Maps
Shares the previous paper's spine and adds maps — specifically Wardley maps — as the visualisation layer for prioritising supply-chain risk once it is modelled as a graph.
Read the summary →Linking Threat Models with Semantic Business Graphs
The bridge between technical findings and business impact — the theoretical basis for the ThreatModCon vault's multi-persona demo (one SQL injection, reframed for Board, CISO, CTO …
Read the summary →Supercharging AppSec Threat Modeling Services with GenAI and Semantic Graphs
The commercial framing: GenAI as a force multiplier for AppSec consulting, semantic graphs as a living context layer, personalised multi-stakeholder deliverables and an implementat…
Read the summary →Read in order
The papers were written to build on each other. Move 1 is the diagnosis (paper 1). Move 2 is the mechanism (paper 1, plus G³). Move 3 is the scaling case (the two supply-chain papers). Move 4 is the policy position (mandatory disclosures) — and its reflexive test is this site itself: a site arguing threat models should be mandatory disclosures is judged by whether it discloses its own. See /disclosure/.