IriusRisk vs. ThreatModeler
What the Acquisition Means for Buyers
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Anyone typing “IriusRisk vs. ThreatModeler” into a search bar in 2026 is not asking an abstract product-comparison question. They are almost certainly an existing customer of one platform, or an evaluator midway through a bake-off, trying to figure out what changed on January 8, 2026, when ThreatModeler announced it had acquired IriusRisk for more than $100 million. This page answers that question directly: what each product was known for going into the deal, what the acquisition actually changes, and what to ask before you renew, migrate, or sign.
In This Guide
- The 30-second answer
- What IriusRisk was known for
- What ThreatModeler was known for
- What happened in the acquisition, and when
- What changes: roadmap, licensing, support, and migration
- Questions to put to the combined vendor
- If you need an independent platform
- Frequently asked questions
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
The 30-Second Answer
IriusRisk and ThreatModeler are no longer separate competitors. As of January 8, 2026, ThreatModeler owns IriusRisk, and PeerSpot’s product listings now categorize IriusRisk as “a ThreatModeler product.” Both companies say they are continuing to operate under their existing brand names for now, so the comparison a buyer is actually running in 2026 is not “which platform wins” but “what does the combined roadmap look like, and does either name still describe a product I can commit to for the next three years.” That question does not have a public answer yet. It has to be asked directly of the vendor.
| Before January 2026 | As of this writing | |
|---|---|---|
| Ownership | Separate companies. IriusRisk (Madrid, Spain) backed by Paladin Capital Group; ThreatModeler (Jersey City, NJ) backed by Invictus Growth Partners | Same company. ThreatModeler acquired IriusRisk; Invictus Growth Partners holds the majority stake; Paladin Capital Group remains a shareholder |
| Brands | Marketed and sold as competing platforms | Both product names are still in use; PeerSpot lists IriusRisk as “a ThreatModeler product” |
| Roadmap | Independent product roadmaps | Not yet publicly documented as unified — verify directly with the vendor |
| Combined category standing | Ranked #1 and #2 by PeerSpot mindshare, roughly 76% of category attention between them (April 2026 PeerSpot data) | Same two products, one parent company |
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
What IriusRisk Was Known For
Before the acquisition, IriusRisk positioned itself as an AI-assisted threat modeling and secure-design platform, built to be usable by both security and non-security teams. Its public positioning emphasized architecture-led modeling, a large built-in security knowledge base, automated threat and countermeasure generation, and support for multiple methodologies including STRIDE, TRIKE, OCTAVE, and PASTA rather than requiring a single framework. It also marketed a feature called Bex AI, designed to analyze feature descriptions in tools like Jira and flag potential security issues before code is written. IriusRisk described its customer base as spanning financial services, insurance, healthcare, and industrial automation, including Fortune 500 banks and payment providers.
On PeerSpot, IriusRisk (now listed as “a ThreatModeler product”) held 38.7% mindshare in the Threat Modeling category as of June 2026, down from 42.9% a year earlier, while carrying the highest search interest among large-enterprise buyers researching the category.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
What Happened in the Acquisition, and When
On January 8, 2026, ThreatModeler announced it had acquired IriusRisk, describing the deal as bringing together “the top two enterprise threat modeling platforms” in what it called a $30 billion application security market. Fortune reported the deal at more than $100 million, citing a source with direct knowledge who put the combined companies’ annual recurring revenue at roughly $50 million. ThreatModeler CEO Matt Jones told Fortune the acquisition would let the combined company be more aggressive on its product roadmap; IriusRisk CEO Stephen de Vries and Invictus Growth Partners’ John DeLoche both framed the deal around consolidating two companies with overlapping missions in an AI-accelerated threat landscape. The terms beyond the reported price were not disclosed.
As of this writing, both companies continue to maintain separate product-facing websites, marketing, and (per public statements) go-to-market motion. Neither company has published a detailed public roadmap for how the products will converge, remain parallel, or be phased out in favor of one another.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
What Changes: Roadmap, Licensing, Support, and Migration
None of the following has a settled public answer as of this writing. Each is a question the combined organization should be able to answer for a specific customer, in writing, before that customer renews or migrates.
Roadmap. Will IriusRisk and ThreatModeler continue as two products with separate release cycles, converge into a single platform over time, or split feature ownership (for example, IriusRisk’s developer-facing workflow paired with ThreatModeler’s portfolio-level governance)? Which capabilities announced before January 2026 are still being built as originally scoped?
Licensing and packaging. Will pricing, packaging, or contract terms change at renewal for existing customers of either product? Will customers of one product be offered migration incentives or bundled pricing to move to the other, and on what timeline?
Support. Will support teams, SLAs, and escalation paths for each product remain separate, or will they be consolidated under one support organization? Existing customers should get this in writing rather than assuming continuity.
Migration. If the combined company eventually sunsets one product in favor of the other, what is the committed migration path for existing threat models, libraries, integrations, and historical data? Threat models can represent months of architecture and risk-analysis work; a forced migration without a documented export and import path is a material business risk, not a minor inconvenience.
Data governance. Threat models frequently contain sensitive architecture, control, and vulnerability data. Buyers should ask directly how customer data from each product is segmented, and whether combining the companies changes who inside the combined organization can access it.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Questions to Put to the Combined Vendor
- Is our product (IriusRisk or ThreatModeler) still being actively developed, or is it being maintained while investment shifts to the other platform?
- What is committed on the current public roadmap versus what is still under evaluation post-acquisition?
- Will our contract terms, pricing, or packaging change at our next renewal because of the acquisition?
- Is there a documented, tested path to export all of our threat models, libraries, and historical data in a usable format, regardless of which product we stay on?
- Will our support contacts, SLAs, and escalation process change, and when?
- If we were evaluating a migration from one product to the other, what would that migration actually involve — timeline, data mapping, retraining, and cost?
- How is customer data segmented between the two products today, and does that change under common ownership?
- Can you provide a written commitment on product continuity for at least the length of our current contract term?
Buyers should get answers in writing, not only in a sales conversation, and should treat a vendor’s inability to answer any of these specifically as useful information in itself.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
If You Need an Independent Platform
For organizations that would rather not build their next threat modeling program on top of an acquisition still working through integration, an independent platform is a reasonable category to evaluate in parallel. Fork is VerSprite’s continuous, PASTA-based application threat modeling platform, built around the same seven-stage methodology VerSprite’s CEO co-authored; it is not part of the ThreatModeler/IriusRisk combined entity and has its own independent roadmap.
- See how Fork compares to IriusRisk specifically
- See how Fork compares to ThreatModeler specifically
- Full list of IriusRisk alternatives
- Full list of ThreatModeler alternatives
- Explore Fork continuous application threat modeling
Evaluation point: Fork is affiliated with VerSprite, the publisher of this page. As with any vendor, buyers should validate required integrations, deployment needs, workflow fit, and scale through a demonstration or proof of concept rather than marketing claims from any party, including this one.
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
Choose the Path Before the Vendor Chooses It for You
The IriusRisk/ThreatModeler acquisition is still working through integration, and the combined company’s roadmap decisions will affect existing customers of both products whether or not those customers are actively evaluating alternatives right now. The lowest-risk move for most buyers is to get the roadmap, licensing, support, and migration questions above answered in writing before a renewal date forces the decision, and to know what an independent alternative would look like in case the answers are not satisfying.
Explore Fork continuous application threat modeling
Read the full 2026 threat modeling tools comparison
Return to the Threat Modeling Tools comparison hub
Frequently Asked Questions
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /
- /