threat-modeling.sgit.ai / papers / Linking Threat Models with Semantic Business Graphs
Linking Threat Models with Semantic Business Graphs
The bridge between technical findings and business impact — the theoretical basis for the ThreatModCon vault's multi-persona demo (one SQL injection, reframed for Board, CISO, CTO and Developer) and for the eleven-layer traversal from Compute up to Customer.
What it argues
- Technical findings linked to business-graph nodes, so the same vulnerability can be read at whichever altitude the audience needs.
- The theory behind the vault's own working proof — pair this paper with /eleven-layers/, which is the argument made concrete in a published vault rather than a document.
What checks it
This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.