PASTA
Process for Attack Simulation and Threat Analysis — a seven-stage methodology that starts from business objectives, not from a diagram. PASTA simulates how a real attacker would target what matters to you, so security decisions are framed in terms of business impact a board can act on.
What it is
PASTA is a risk-centric threat-modeling methodology. Where STRIDE asks "what can go wrong with this component?", PASTA asks "what is worth protecting, who would attack it, how, and what would it cost the business?". It is heavier than STRIDE and deliberately so: it produces an evidence-based, attacker-simulated risk picture that ties technical findings to business consequences.
It works through seven stages, each feeding the next — from defining objectives down to quantifying residual risk.
The seven stages
What the system exists to do, the assets it handles, and the compliance and business impact at stake.
The infrastructure, components, dependencies and trust boundaries in play.
Map data flows, entry points, actors and privileges — the surface an attacker can reach.
Use real threat intelligence to identify which threats and threat actors are credible for this system.
Correlate threats with actual vulnerabilities and design weaknesses in the system.
Build attack scenarios and trees that simulate how an adversary would chain weaknesses to reach the assets.
Quantify residual risk and prioritise countermeasures by business impact, not just technical severity.
How it works — the architecture
PASTA is built to be evidence-driven and collaborative. It pulls in threat intelligence, real vulnerability data and attacker behaviour rather than reasoning purely from a diagram, and it keeps business stakeholders, architects and security in the same conversation. The output is not just a list of threats but a set of simulated attack scenarios with a quantified, business-aligned risk rating — the kind of artefact a CISO can take to a board.
How we audit your systems with PASTA
- We start from your crown jewels — the assets, revenue and obligations that define what "bad" actually means.
- We bring threat intelligence — credible actors and techniques for your sector, not a generic checklist.
- We simulate the attack — chaining weaknesses into realistic scenarios, validated against the live system.
- We quantify business risk — each scenario rated by likelihood and impact in terms leadership understands.
- For AI systems — we model GenAI-specific attack paths (prompt injection into tool use, data exfiltration via agents) as first-class scenarios.
How we implement it
PASTA suits organisations that need security framed as business risk — regulated sectors, board-level reporting, or a formal risk programme. We run it as a structured engagement, deliver attack scenarios and a quantified risk register, and map findings to the EU AI Act, NIST AI RMF and ISO/IEC 42001 so they slot into your governance. For lighter, design-time work we often pair it with STRIDE for discovery and DREAD for fast prioritisation.
PASTA is a published, risk-centric threat-modeling methodology. This page reflects NexusFinLabs' practice and is general guidance, not legal advice.