threat-modeling.sgit.ai / papers / Linking Threat Models with Semantic Business Graphs

Linking Threat Models with Semantic Business Graphs

The bridge between technical findings and business impact — the theoretical basis for the ThreatModCon vault's multi-persona demo (one SQL injection, reframed for Board, CISO, CTO and Developer) and for the eleven-layer traversal from Compute up to Customer.

Published
2025-06-02, docs.diniscruz.ai
Role
the bridge to business impact
Co-authorship
Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” in their front matter — kept visible rather than smoothed away, per this site's attribution rule
Source
https://docs.diniscruz.ai/docs/2025/06/02/linking-threat-models-with-semantic-business-graphs.md — the paper itself, on docs.diniscruz.ai. This page summarises; it does not reproduce.

What it argues

What checks it

This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.