TARA: Threat Analysis & Risk Assessment

Every credible automotive cybersecurity programme starts with a TARA. We run an ISO/SAE 21434-aligned threat analysis that tells you what to protect, what could go wrong, and what to fix first.

The Document Your Whole Programme Depends On

UN R155/R156 and ISO/SAE 21434 both require a structured risk assessment for each vehicle type. The TARA is that document, and it drives everything downstream: your security requirements, your test scope, and your compliance evidence.

Get the TARA right, and the rest of the programme stands on a solid foundation. Get it wrong, and you end up testing the wrong things and certifying on shaky ground.

How We Run a TARA

Asset Identification

We identify the cybersecurity-relevant assets in your item and the properties that matter for each one, whether that is confidentiality, integrity or availability. Everything that follows is anchored to this list.

Damage Scenarios

We define what harm a compromise could cause, whether to safety, finances, operations or privacy.

Threat Scenarios

We map the routes by which an attacker could actually bring each damage scenario about, working back from the harm to the interfaces, assets and steps involved in getting there.

Attack Feasibility

We rate how achievable each attack path really is, weighing the time, expertise, equipment and access it would demand, so effort lands on what an attacker could plausibly pull off.

Risk Determination

We combine the impact of the damage with the feasibility of the attack to give every threat scenario a risk rating, which is what turns a long list of possibilities into an ordered set of priorities.

Risk Treatment

We decide how to handle each risk, whether to reduce, share, retain or avoid it, and turn that into clear cybersecurity goals and requirements.

UN R155 & R156 compliance

What You Receive

A complete, auditor-ready TARA

An asset and damage-scenario catalogue, rated threat scenarios, a risk register, and a clear set of cybersecurity goals and requirements you can hand straight to your engineering team and to your assessor.

Deliverables

A TARA report · a risk register · cybersecurity goals & requirements · full traceability to ISO/SAE 21434 and UN R155/R156.

Certifications

ISO 9001:2015 · ISO 27001:2022 · certified ISO/SAE 21434 experts

Common Questions

A Threat Analysis and Risk Assessment, a structured way to identify the cybersecurity risks for a product, rate them, and decide how to treat each one. It's central to ISO/SAE 21434 and UN R155/R156.
Early, at concept and design, and then maintained through the lifecycle as the product and the threat landscape change.
Our certified ISO/SAE 21434 experts, working alongside your engineering team so the result is realistic and genuinely usable, not theoretical.
No, it defines what to test. The two work together: the TARA scopes the risk, and testing verifies that your controls actually hold.

Start With a Solid TARA

Give your programme a foundation that holds. We'll run an ISO/SAE 21434-aligned TARA and hand back the requirements and evidence the rest of your work depends on.