Why Threat Modeling Is No Longer Optional

Threat modeling has transitioned from a "nice to have" security practice to a regulatory expectation. SEBI CSCRF control ID.2 explicitly requires threat and risk assessment. ISO 27001 Clause 6.1.2 demands systematic identification of information security risks, which effectively requires threat modeling methodology. RBI's cybersecurity framework expects banks and NBFCs to conduct regular threat assessments.

Yet many organizations have never conducted a structured threat model. When asked by auditors about their threat assessment methodology, most point to their VAPT reports — which are not threat models. VAPT finds existing vulnerabilities; threat modeling identifies potential attack paths before vulnerabilities are exploited.