IriusRisk

IriusRisk Competitive Intelligence & Landscape

iriusrisk.com ·

IriusRisk
ForesightIQ Predictions

What is IriusRisk likely to do next?

ForesightIQ connects IriusRisk's hiring, product, web, ad, and market signals to forecast strategic moves — often months before they're announced.

Hiring signal

Senior hiring patterns point to a planned enterprise product line launching within two quarters.

High confidence · Next 1–2 quarters
Product signal

Quiet changes to docs and pricing pages signal an upcoming usage-based pricing tier and new API surface.

Likely · Next quarter
Market signal

Ad spend and partnership activity indicate a push into the mid-market segment across two new regions.

Plausible · Next 2–3 quarters
IriusRisk Unlock IriusRisk's predicted moves

Free · generated in ~60 seconds · no signup to preview

Overview

IriusRisk Overview

IriusRisk (iriusrisk.com) is a leading provider of AI threat modeling tools designed to enhance secure software development. The company's core mission, established since its founding in 2015 by Stephen de [Source: https://www.iriusrisk.com/about-us], is to empower enterprises to Build-Safer-Faster by integrating security by design into their software development lifecycle [Source: https://www.iriusrisk.com/about-us]. Initially launched under the Continuum Security brand in 2016 before rebranding, IriusRisk aims to make threat modeling a common and integral part of every organization's software development process [Source: https://www.iriusrisk.com/leadership-team]. The company is now part of ThreatModeler, further strengthening its position in the market [Source: https://iriusrisk.com/].

The flagship product from IriusRisk is its AI Threat Modeling Tool, an automated solution that significantly reduces the time required for threat modeling—from an average of 80 hours to just 8 hours [Source: https://iriusrisk.com/]. This tool is powered by a powerful AI Assistant that aids in diagram creation and saves time, along with Bex AI, which provides conversational security directly in Jira [Source: https://iriusrisk.com/].

IriusRisk also offers tailored services to help elevate threat modeling practices, key features like integrations with existing SDLC technologies, and a comprehensive content library to meet regulatory and industry best practices [Source: https://iriusrisk.com/]. Notably, IriusRisk was the first to threat model AI and ML applications [Source: https://iriusrisk.com/].

IriusRisk targets a broad market, including security teams, developers, and CISOs, enabling them to increase development speed, reduce risk, and demonstrate the value of their security posture [Source: https://iriusrisk.com/]. The company serves various industries such as financial services, medical devices, operational technology, and public services [Source: https://iriusrisk.com/]. According to a Forrester report, IriusRisk provides a 203% ROI, with payback typically seen within six months [Source: https://iriusrisk.com/]. Headquartered in Huesca, Spain, with global offices, IriusRisk saw significant growth in 2021, doubling its customer base and annual recurring revenue [Source: https://www.iriusrisk.com/contact], [Source: https://www.iriusrisk.com/resources-blog/iriusrisk-doubles-the-team-and-annual-recurring-revenue-in-2021].

Competitors

IriusRisk Competitors

IriusRisk, a leading AI threat modeling tool for secure software development, faces competition from several key players in the application security and software supply chain security markets. Its top direct competitors, according to CB Insights, include ArmorCode, Backslash, and Devici [https://www.cbinsights.com/company/iriusrisk/alternatives-competitors]. While specific differentiators and market shares for these companies against IriusRisk are not detailed in the provided sources, it can be inferred that they also focus on aspects of software security throughout the SDLC. Veracode, a notable indirect competitor, specializes in Application Risk Management, offering services like vulnerability detection, AI-assisted code fixes, and security training to enhance software security across the development lifecycle [https://www.cbinsights.com/company/iriusrisk/alternatives-competitors]. This comprehensive approach to application security positions Veracode as a strong alternative for organizations seeking end-to-end solutions beyond just threat modeling.

Another significant competitor is InvisiRisk, which distinguishes itself as the first CI/CD Firewall [https://invisirisk.com/]. InvisiRisk's unique market positioning focuses on stopping threats as they enter the software supply chain, rather than after they've breached production. It acts as a Build-time Application Firewall (BAF), enforcing zero-trust policies across CI/CD transactions before code reaches production [https://invisirisk.com/]. This differs from IriusRisk's primary focus on AI-driven threat modeling earlier in the design and development phases, offering a distinct security layer for the "Last Mile of the Software Supply Chain." While IriusRisk aims to proactively identify and mitigate threats through modeling, InvisiRisk offers a real-time, preventative measure during the build process.

In the realm of commercial threat modeling tools, IriusRisk also competes with GuidePoint Security Application Threat Modeling and Avocado Reveal. GuidePoint Security's offering provides similar threat modeling capabilities, and users often compare features, ratings, and integrations side-by-side to find the best fit for their security stacks [https://cybersectools.com/compare/guidepoint-security-application-threat-modeling-vs-iriusrisk-threat-modeling-tool-iac]. Avocado Reveal, another commercial threat modeling tool by Avocado Systems, is also frequently compared with IriusRisk Threat Modeling Platform, particularly by product and application security teams building cloud-native architectures [https://cybersectools.com/compare/avocado-reveal-vs-iriusrisk-threat-modeling-platform]. These direct comparisons highlight the competitive landscape where companies vie for market share based on features, ease of integration, and suitability for specific architectural needs. Furthermore, for AI and ML systems, IriusRisk AI Threat Modeling & ML stands out as one of the few threat modeling libraries designed around ML-specific attack surfaces, competing with tools like Apiiro AI-Powered Risk Detection which also offers commercial threat modeling capabilities [https://cybersectools.com/compare/apiiro-ai-powered-risk-detection-vs-iriusrisk-ai-threat-modeling-and-ml].

Alternatives

IriusRisk Alternatives

Product & Pricing

IriusRisk Product and Pricing Intelligence

IriusRisk offers a comprehensive AI Threat Modeling Tool designed to enhance secure software development. Their platform, fused with AI, enables users to craft robust threat models, pinpoint threats and countermeasures, identify vulnerabilities and compliance gaps, and integrate with existing tools for seamless collaboration.

IriusRisk emphasizes secure design, aiming to embed security controls early in the SDLC to avoid costly rework, which is 100x more expensive at later stages. The company highlights a significant ROI of 203%, with payback often seen within six months, by focusing on cost-saving and remediation avoidance through their automated threat modeling solutions.

For pricing, IriusRisk offers a flexible structure that varies based on the number of licenses or threat models required, prioritizing transparency and charging only for actual usage [Source: https://www.iriusrisk.com/plans]. Their flagship offering is the IriusRisk Community Edition, a free SaaS subscription intended for individuals [Source: https://www.iriusrisk.com/community]. This freemium version provides lifetime access to threat modeling tools, libraries, and their AI assistant, Jeff, including three free threat models. The Community Edition includes diagramming capabilities, automated threats and countermeasures, and manual updates, with some integrations requiring a paid plan [Source: https://enterprise-support.iriusrisk.com/s/article/Getting-Started-with-IriusRisk].

The AI assistant, Jeff, is a key feature across IriusRisk's offerings. It aids in diagram creation, allows users to take text prompts or images, and offers AI-powered Smart Views for focused threat mitigation [Source: https://www.iriusrisk.com/ai-threat-modeling]. While the Community Edition provides a strong foundation with AI assistance, advanced features like automated test-result ingestion are exclusive to paid plans.

IriusRisk also offers tailored services and configurations, including outstanding onboarding packages with self-paced learning via the IriusRisk Academy and live working sessions, to help users maximize their investment and expedite time to value [Source: https://www.iriusrisk.com/services].

Hiring & Layoffs

IriusRisk Hiring and Layoffs

IriusRisk, a leading provider of AI threat modeling tools, exhibits a consistent growth-oriented hiring strategy, signaling strong expansion within the secure software development market. The company emphasizes a commitment to a Growth Mindset, Resilience, Empathy, Accountability, and Teamwork (G.R.E.A.T.) in its recruitment process, reflecting its core values and how employees collaborate and develop within the organization [https://www.iriusrisk.com/careers]. This approach is crucial for a company that has experienced nearly 100% year-on-year growth, expanding from two co-founders to a global team of 200 employees across Europe, North America, and New Zealand [https://www.iriusrisk.com/about-us].

The appointment of Sarah, a Chief People Officer, in 2023 underscores IriusRisk's dedication to building and retaining an exceptional team to meet evolving customer needs [https://www.iriusrisk.com/leadership-team]. Her role focuses on driving business success through a people-centric lens, ensuring the company remains a great place to work. While specific recent job openings are not detailed, the company openly invites interested candidates to explore all available positions on its careers page [https://www.iriusrisk.com/careers]. This indicates a continuous need for talent to support its expanding operations and innovative product development, particularly with the integration of its platform with ThreatModeler [https://iriusrisk.com/].

The ongoing hiring patterns at IriusRisk suggest a strategic focus on scaling its workforce to support its product evolution, including the development of its AI Assistant and conversational security features [https://iriusrisk.com/]. The company's emphasis on global presence, as evidenced by its offices and event participation worldwide, further highlights its ambition to capture a significant share of the secure by design market [https://www.iriusrisk.com/contact, https://www.iriusrisk.com/events]. There is no information available to indicate any recent layoffs, reinforcing a stable and growing employment environment within the company as it continues to innovate in the cybersecurity space.

Leadership

IriusRisk Management and Leadership Team

IriusRisk is led by its co-founders, Stephen de Vries, who serves as Chief Executive Officer (CEO), and Cristina Bentué, who is also a co-founder and has been noted for discussing significant company initiatives like the four-day work week for development staff. Stephen de Vries brings over two decades of experience in secure code design and application security, having played a key role in automating threat modeling to help scale secure design practices globally. Cristina Bentué, alongside Stephen, established IriusRisk in 2015 with a vision to create secure-by-design applications for agile teams, addressing the bottlenecks in the software development lifecycle.

The company has experienced significant growth, leading to strategic leadership appointments and expansion. In 2022, IriusRisk bolstered its team, particularly in go-to-market roles, customer success, and commercial operations, with notable appointments including Sarah Wheeler as the new Chief People Officer in February 2023. This focus on people growth and development underscores the company's commitment to its expanding workforce. The team's growth has also facilitated increased presence across the US, UK, and continental Europe.

Beyond the co-founders, the IriusRisk leadership team includes key roles driving product innovation and service delivery.

Fraser Scott, who was appointed VP of Product Development, now serves as the Chief Scientist (AI), spearheading the strategic vision and practical implementation of artificial intelligence within the threat modeling platform. Other significant leaders include James Rabe as Head of Global Services, responsible for the successful design and adoption of threat modeling solutions for customers, and Dr. Lamine Aouad as Director of Cybersecurity, who is crucial in maintaining and expanding the platform's extensive threat and countermeasure knowledge base. These leaders collectively contribute to IriusRisk's mission of delivering cutting-edge, AI-augmented security solutions.

Financials

IriusRisk Financial Performance, Fundraising, M&A

IriusRisk, founded in 2015, has demonstrated significant financial growth and strategic fundraising throughout its history. The company reported that its customer base and Annual Recurring Revenue (ARR) more than doubled in the financial year of 2021. This strong performance continued into 2022, with IriusRisk achieving over 80% growth despite challenging geopolitical and macroeconomic conditions. This expansion was attributed to the maturing threat modeling market, international expansion, and increased usage of its Community Edition.

In terms of fundraising, IriusRisk has secured substantial investments to fuel its development. In November 2017, the company, then known as Continuum Security, raised a 1.5M€ investment from Swanlaab, JME, and Sonae IM. More recently, in October 2022, IriusRisk successfully closed a $29 million Series B funding round. This round was led by Paladin Capital Group, a prominent cyber and deep tech investor, underscoring the growing importance of threat modeling in secure product design. The company has also received co-funding from the European Regional Development Funding (FEDER) for projects like ACSDA, aimed at developing an Automated Cyber Security Design Assistant, and funding from the European Cybersecurity Competence Centre (ECCC) for its free-forever community edition.

While specific revenue figures beyond ARR growth percentages are not publicly disclosed, IriusRisk highlights significant financial benefits for its users. A Forrester Total Economic Impact study revealed that IriusRisk delivered a 203% Return on Investment (ROI), with payback achieved within just six months. Furthermore, the study indicated substantial cost savings from remediation avoidance, estimated at $4.9 million over three years. Recently, IriusRisk announced its integration into ThreatModeler, signifying a significant M&A event that brings together their respective strengths in AI-driven threat modeling solutions.

Partnerships

IriusRisk Partnerships, Clients and Vendors

IriusRisk, a leader in automated threat modeling and secure software design, collaborates with strategic partners to deliver exceptional service to its clients. Their client roster includes Fortune 100 and Fortune 500 companies, as well as several of the world's top 10 Globally Systemically Important Banks (G-SIBs) [https://www.iriusrisk.com/partners]. Notable examples of their client work include helping a U.S.-based IT consultancy firm implement a threat modeling solution for a major U.S. Airlines company [https://www.iriusrisk.com/case-studies/u-s.-based-it-consultancy-firm-partners-with-iriusrisk-to-implement-threat-modeling-solution-for-major-u.-s.-airlines-company], enabling a Global Top 10 Bank to scale to over 5,000 automated threat models [https://www.iriusrisk.com/case-studies/global-top-10-bank], and assisting a European bank in halving its threat modeling time [https://www.iriusrisk.com/case-studies/european-bank]. Other case studies highlight their work with a U.S.-based financial services firm [https://www.iriusrisk.com/case-studies/us-based-financial-services-firm], a multinational software corporation [https://www.iriusrisk.com/case-studies/custom-threat-modeling-and-powerbi-integration], and a U.S.-based Mutual Life Insurance Company [https://www.iriusrisk.com/case-studies/us-based-mutual-life-insurance-company].

IriusRisk offers extensive integrations to fit into existing SDLC and technology investments [https://www.iriusrisk.com/integrations]. Their platform can integrate with a wide array of tools, including Cloud Orchestration tools, Testing frameworks, Security tools, SAML/AML integrations, CI/CD tools, and Diagram tools. The company also emphasizes its open API, allowing for broad customization and integration possibilities [https://www.iriusrisk.com/integrations].

Key technology integrations include support for Infrastructure as Code (IaC) files, specifically using Terraform and Cloud Formation to build threat models directly from code, which accelerates threat modeling by creating like-for-like representations of infrastructure [https://www.iriusrisk.com/case-studies/us-based-financial-services-firm]. Furthermore, IriusRisk has joined forces with ArmorCode, seamlessly integrating its automated threat modeling capabilities into ArmorCode’s unified Application Security Posture Management (ASPM) and Risk-Based Vulnerability Management (RBVM) solution [https://www.iriusrisk.com/resources-blog/armorcode-and-iriusrisk-join-forces]. This collaboration helps organizations design and develop secure software faster. They also facilitate integration with tools like PowerBI for enhanced security insights [https://www.iriusrisk.com/case-studies/custom-threat-modeling-and-powerbi-integration].

Events

IriusRisk Event Participations

IriusRisk actively engages with the cybersecurity community through various events, including prominent conferences, summits, and a dedicated online presence. They are a Platinum Sponsor of events such as the OWASP BeNeLux Days 2025 in Belgium, demonstrating their commitment to supporting application security discourse [iriusrisk.com/events]. Additionally, IriusRisk participates in major industry gatherings like OWASP Global AppSec 2024 in Lisbon, where they join over 700 cybersecurity experts to discuss cutting-edge topics [iriusrisk.com/events/owasp-global-appsec-2024-lisbon]. Their involvement extends to specialized summits, including sponsoring and speaking at the Wall Street Cybersecurity Summit and the IDC Foundry Cybersecurity Summit in Madrid, connecting with C-suite executives and senior cybersecurity leaders [iriusrisk.com/events/wall-street-cybersecurity-summit][iriusrisk.com/events/idc-foundry-cybersecurity-summit].

Beyond in-person events, IriusRisk hosts a robust webinar program featuring both live and on-demand sessions. These webinars cover a wide range of topics in threat modeling and broader cybersecurity discussions, offering valuable insights and practical tips [iriusrisk.com/webinars]. Examples include sessions on "Developer-Friendly Threat Modeling," "Better, Faster, Stronger Security with AI Threat Modeling," and "Secure SDLC processes with Threat modeling" [iriusrisk.com/webinars][iriusrisk.com/webinars/ai-threat-modeling][iriusrisk.com/webinars/secure-sdlc-processes-with-threat-modeling]. They also conduct an "Educational Workshop Series" that breaks down the steps to successfully implement a threat modeling program, including practical whiteboard workshops [iriusrisk.com/educational-workshop-series].

IriusRisk is also a key player in fostering a global community around threat modeling. They are integral to Threat Modeling Connect, a community founded in 2022 by leading industry professionals to promote learning, collaboration, and connection among threat modeling practitioners [iriusrisk.com/threat-model-connect]. Through these diverse events and community initiatives, IriusRisk positions itself at the forefront of advancing secure software development practices and knowledge sharing.

Frequently Asked Questions

What does IriusRisk's consistent growth in hiring signal about its market position and product strategy?

IriusRisk's consistent growth-oriented hiring, including the appointment of a Chief People Officer in 2023, indicates a strong expansion within the secure software development market. This strategy supports scaling its workforce to meet evolving customer needs and advance product evolution, particularly in AI-driven features like its AI Assistant and conversational security solutions, as it targets a significant share of the 'secure by design' market.

How do IriusRisk's event sponsorships and participation reflect its strategic priorities?

IriusRisk's role as a Platinum Sponsor for events like OWASP BeNeLux Days 2025 and its participation in OWASP Global AppSec 2024 demonstrate its commitment to supporting application security discourse and fostering a global community around threat modeling. Its involvement in specialized summits like the Wall Street Cybersecurity Summit also highlights a strategic focus on engaging with C-suite executives and senior cybersecurity leaders to advance secure software development practices and knowledge sharing.

What does IriusRisk's recent integration with ThreatModeler signify for its competitive strategy?

IriusRisk's integration into ThreatModeler represents a significant M&A event that consolidates strengths in AI-driven threat modeling. This move likely enhances its competitive posture against rivals like ArmorCode, Backslash, and Devici by offering a more comprehensive and robust solution, and provides a broader platform for continuous visibility into attack surfaces for enterprise clients.

What do IriusRisk's financial growth figures, particularly the 203% ROI, suggest about its value proposition?

IriusRisk's reported 203% ROI and payback within six months, alongside over 80% growth in 2022 and doubling ARR in 2021, indicate a strong value proposition centered on cost savings and remediation avoidance. These figures suggest that its automated threat modeling tools significantly reduce security-related expenses and enhance efficiency for its users, making it an attractive investment for enterprises.

What is the strategic implication of IriusRisk's focus on AI in its product offerings, especially with the AI Assistant and Bex AI?

IriusRisk's strong emphasis on AI, exemplified by its AI Assistant and Bex AI for conversational security in Jira, positions it at the forefront of automated threat modeling. This focus aims to significantly reduce the time required for threat modeling (from 80 to 8 hours) and provide real-time, context-aware security insights, thereby accelerating 'secure by design' principles within the SDLC and enhancing developer productivity.

How do IriusRisk's partnerships and integrations with tools like Terraform and ArmorCode affect its market reach and customer adoption?

IriusRisk's extensive integrations with Cloud Orchestration, Testing, Security, and CI/CD tools, including Terraform and a strategic partnership with ArmorCode, enhance its market reach by fitting seamlessly into existing SDLC and technology investments. These integrations lower the barrier to adoption for Fortune 100 and Fortune 500 companies, allowing them to build threat models directly from Infrastructure as Code and unify application security posture management.

What do the leadership appointments, specifically Fraser Scott as Chief Scientist (AI), reveal about IriusRisk's long-term product direction?

The appointment of Fraser Scott as Chief Scientist (AI) signals IriusRisk's strong long-term commitment to integrating artificial intelligence deeply into its threat modeling platform. This leadership focus indicates a strategic direction towards advanced AI-driven solutions that will likely further automate and enhance threat identification and mitigation, solidifying its position as an AI threat modeling tool leader.

How does IriusRisk's 'Community Edition' and flexible pricing strategy impact its competitive standing against other threat modeling tools?

IriusRisk's 'Community Edition' offers a free, lifetime SaaS subscription with AI assistance and three threat models, allowing individual practitioners to access core features. This freemium model, combined with flexible pricing based on usage, lowers the barrier to entry, potentially increasing adoption and market share while establishing brand loyalty and a pipeline for paid enterprise solutions, making it competitive against both commercial and open-source alternatives.

What differentiates IriusRisk's approach to threat modeling from competitors like InvisiRisk, which focuses on CI/CD firewalls?

IriusRisk primarily focuses on AI-driven threat modeling in the design and development phases to proactively identify and mitigate threats. In contrast, InvisiRisk operates as a Build-time Application Firewall (BAF) during the CI/CD process, stopping threats as they enter the software supply chain. IriusRisk aims for early-stage threat identification, while InvisiRisk provides a real-time, preventative measure for the 'Last Mile of the Software Supply Chain'.

What does IriusRisk's claim of being 'the first to threat model AI and ML applications' imply for its target market and future growth?

IriusRisk's claim of being 'the first to threat model AI and ML applications' implies a strategic focus on emerging and high-growth technology sectors. This specialization positions the company to capture market share among organizations developing AI and ML systems, offering tailored security solutions for these complex attack surfaces and potentially driving significant future growth as AI adoption expands.

What does IriusRisk's ongoing educational workshop series and 'Threat Modeling Connect' initiative signify for its market education and community building efforts?

IriusRisk's educational workshop series and its role in 'Threat Modeling Connect' signify a strong commitment to market education and community building around threat modeling. These initiatives aim to promote learning, collaboration, and adoption among practitioners, fostering a larger ecosystem that benefits IriusRisk by establishing it as a thought leader and go-to resource in secure software development.

Powered by ForesightIQ · Competitive intelligence from digital exhaust