THREATPLANE LIMITED
Threatplane Limited is a UK-based cybersecurity consultancy, founded in 2017, that delivers expert-led risk-based threat modelling engagements and a SaaS Threat Modeling Platform to engineering, security, and product teams in regulated sectors including financial services, government, healthcare, and critical infrastructure.
- Company typePrivate
- Founded2017
- HeadquartersLondon, United Kingdom
- Headcount1–10
- GTM typeB2B
- OfferingServices
What THREATPLANE LIMITED does
Threatplane Limited is a UK-based cybersecurity consultancy founded in 2017 in Bristol by Jonny Tyers. The company delivers risk-based threat modelling engagements to engineering, product, and security teams, structured around a proprietary four-stage process (business context, architecture mapping, threat assessment, controls prioritisation) and an RROC framework that maps technical risks to Revenue, Reputation, Operations, and Compliance business-impact categories. Customers are primarily enterprise and regulated-sector buyers in financial services, government, healthcare, genomics, eCommerce, luxury retail, IoT manufacturing, telecoms, and airports, with case studies spanning a major UK bank (70+ threat models delivered across 250+ AWS accounts), a £3B gross-sales global retail group, a US federal medical research agency, and a UK genomics scale-up.
Threatplane monetises through three connected offerings: (1) expert-led threat modelling consulting engagements delivered in fixed-scope, fixed-price terms over typically four weeks; (2) a SaaS Threat Modeling Platform — available to existing customers — that captures threat model data in structured form, generates audience-specific reports, and integrates with Jira, Linear, GitHub Issues, Slack, Git, draw.io, Lucidchart, Google Workspace, and Microsoft 365, and includes an MCP server connecting to AI assistants such as Copilot, Claude, and Gemini; and (3) fixed-fee developer training designed to transfer internal capability rather than create ongoing consulting dependency. The GTM motion combines direct enterprise field sales targeting engineering leaders, CTOs, and CISOs with a partner channel of technology consultancies, managed security providers, and IT services firms operating in regulated sectors.
The company operates as a private limited company in England and Wales (company number 10549779) with no disclosed external funding, a headcount of approximately ten, and a leadership team anchored by founder Jonny Tyers alongside Principal and Senior Consultants, a Head of Revenue Operations, a Marketing lead, and three board advisors with backgrounds in critical national infrastructure, FTSE 100 security leadership, and the MSP/SME cyber ecosystem. Geographic reach is anchored in the UK and Europe, with selected engagements in the US (federal agencies) and clients serving UK, US, and African markets.
THREATPLANE LIMITED firmographics
Firmographics- Name
- THREATPLANE LIMITED
- Legal name
- Threatplane Limited
- Website
- https://threatplane.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 1–10 employees
- Short description
- Threatplane Limited is a UK-based cybersecurity consultancy, founded in 2017, that delivers expert-led risk-based threat modelling engagements and a SaaS Threat Modeling Platform to engineering, security, and product teams in regulated sectors including financial services, government, healthcare, and critical infrastructure.
- Ownership category
- akta.pro rank
THREATPLANE LIMITED industry classification
Industry- Product category
- Cybersecurity Consulting & Threat Modelling
- NAICS
- Management Consulting Services (54161)
- SIC
- Services-Management Consulting Services (8742)
- akta.pro primary industry
- Enterprise Security Strategy & Program Advisory (BPAKADAA)
- akta.pro secondary industries
- Threat Intelligence Services (BPAEADAC), Security Consulting, Risk Assessment & Security Program Design (BPABAMAE), Business Continuity, Crisis Management & Resilience Planning (BPAKADAI)
Keywords
Where THREATPLANE LIMITED is headquartered
LocationHeadquarters
- HQ city
- London
- HQ country
- United Kingdom
- HQ region
- Europe
Offices1 record
Markets served
THREATPLANE LIMITED business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Operations
Revenue model
- Threat Modeling Consulting Engagements: Expert-led threat modeling engagements delivered over 2-4 weeks with fixed scope and fixed pricing. Engagements include business context workshops, architecture mapping, threat assessment using STRIDE framework, and controls prioritisation with business-justified remediation roadmap.
- Threat Modeling Platform: Platform available to customers that have worked with Threatplane previously; provides greater reporting flexibility, real-time security risk metrics, and enables organisations to integrate security into their own technology teams without heavy engagement of the services team.
- Developer Training: Hands-on training programmes designed around the client's team, using Threatplane's existing methodology and experience. Training is fixed-fee with custom programme design based on team skills and objectives.
- Capability Transfer Engagements: Training and enablement to help organisations run threat modeling independently after working with Threatplane, without creating dependency on ongoing consulting
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Standard Threat Modeling Engagement |
| Subscription | Annual | Threat Modeling Platform |
| Other | Multi-year contract | Developer Training |
Go-to-market motion2 records
Distribution channels3 records
Marketing channels4 records
THREATPLANE LIMITED product offering
Product offeringCore offering
Threatplane provides risk-based threat modelling consulting engagements and a SaaS cybersecurity risk assessment platform for engineering and product teams. The core consulting service delivers expert-led threat modelling through a four-stage workshop process using STRIDE and the proprietary RROC framework, producing business-readable, prioritised risk outputs typically within 4 weeks at fixed scope and fixed price. The platform and developer training extend the offering to enable organisations to run threat modelling independently.
Product overview
Threatplane Limited offers a portfolio of three connected offerings: a consulting service delivering expert-led threat modelling engagements (the core product), a SaaS Threat Modelling Platform for organisations that want to run threat modelling at scale without manual overhead, and Developer Training for teams building internal capability. The consulting service and platform share the same methodology (RROC framework, STRIDE-based threat assessment, four-stage process) and are designed to work together or independently: customers typically start with consulting engagements and may transition to the platform for ongoing, self-directed work.
Differentiator
Problem solved
Functional benefit
Products and services
- Threat Modelling (Consulting Service) Expert-led threat modelling engagements using a four-stage workshop process (business context, architecture mapping, threat assessment, controls prioritisation), producing a prioritised, business-readable risk picture mapped to the RROC framework. Delivered in fixed scope and fixed price engagements, typically within 4 weeks (expedited to 1-2 weeks). Designed for engineering and product teams in regulated, high-stakes sectors.
- Threat Modelling Platform A purpose-built SaaS platform that captures threat model data in structured form, generates audience-specific reports (for business leaders and technical teams), manages multiple models across teams and systems, and integrates with existing developer and collaboration tools (Jira, Linear, GitHub Issues, Slack, Google Workspace, Microsoft 365, Git). Includes draw.io and Lucidchart diagram import, an MCP server for AI integration, and a comprehensive API. Available to customers that have previously worked with Threatplane.
- Developer Training Hands-on threat modelling training programme for engineering teams, teaching them to run threat modelling sessions independently using Threatplane's methodology. Designed to build lasting internal capability; integrates with existing development processes without disrupting delivery schedules. Fixed-fee with custom programme design based on team skills, available time, and objectives. May be a single workshop or structured engagement across several teams.
Quantifiable outcome
- 3x faster security assurance for development teams
- +4 more outcomes
Companies that use THREATPLANE LIMITED
Customer profileNamed customers6 records
Segments7 records
Ideal customer profiles4 records
THREATPLANE LIMITED technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration10 records
AI capability1 record
Feature5 records
THREATPLANE LIMITED partnerships and signals
Strategic signalPartnerships
Three partnerships are on record, tiered core.
- Technology Consultancies (unnamed)corePartner network includes technology consultancies serving mid-market and enterprise clients in regulated or high-stakes sectors. These partners use Threatplane to open strategic conversations with clients and differentiate from firms offering only standard tooling. Partners benefit from opening new revenue streams, going deeper into existing accounts, and offering something competitors cannot.
- Managed Security Providers (unnamed)coreManaged security providers use Threatplane's methodology and platform to assess complex, custom-built systems for their clients. The RROC framework maps risks to business impact in terms boards already use, helping MSPs deepen client relationships beyond commodity security services.
- IT Services Firms (unnamed)coreIT services firms serving regulated or high-stakes sectors partner with Threatplane to offer threat modeling capabilities. Partners can unblock engagements stuck due to client confusion or daunted by costs, creating follow-on scope for remediation, training, and ongoing advisory.
Scale indicators11 records
Recent moves6 records
Expansion highlights5 records
THREATPLANE LIMITED competitors and assessment
Company assessmentBroad incumbents
- Bishop Fox: Bishop Fox is a US-based offensive-security consulting firm offering threat modelling, red teaming, and application security services. Comparable to Threatplane in consultancy-led threat modelling for enterprise engineering teams, particularly in financial services and technology sectors.
- Mandiant (Google Cloud): Mandiant, now part of Google Cloud, provides threat intelligence, incident response, and security advisory. While its primary focus is incident response and threat intel rather than proactive threat modelling, it competes with Threatplane for enterprise security strategy and risk advisory budgets in regulated sectors.
- Coalfire: Coalfire is a US cybersecurity advisory firm providing threat modelling, compliance, and risk advisory services across regulated industries. Comparable to Threatplane's regulated-sector consulting work, particularly in financial services and healthcare, though at substantially greater scale.
- NCC Group: NCC Group is a global cybersecurity consulting firm offering threat modelling, application security, and managed security services. It competes with Threatplane in regulated financial services and critical infrastructure consulting, but at much greater scale and geographic reach.
- Optiv: Optiv is a large US cybersecurity solutions integrator and advisory firm offering threat modelling and risk-based security programme design. It competes with Threatplane for enterprise security strategy engagements, but as part of a much broader portfolio of services and product resale.
- PwC Cybersecurity: PwC's cybersecurity practice offers threat modelling, risk assessment, and security programme advisory as part of its broader consulting portfolio. Comparable to Threatplane for enterprise risk-based security advisory engagements, particularly with regulated financial services clients.
Direct peers
- ThreatModeler: ThreatModeler is an enterprise threat modelling platform with automated diagram-driven analysis and integrations across the SDLC. It competes with Threatplane in the same threat modelling category, particularly for large enterprises seeking platform-led rather than consultancy-led delivery.
- IriusRisk: IriusRisk is a SaaS threat modelling platform for engineering teams, providing automated threat models, risk registers, and developer-workflow integrations. It is the closest direct competitor to Threatplane's platform offering, operating in the same buyer persona (CTO, CISO, AppSec leads) with overlapping threat modelling methodology.
Emerging players
- OWASP Threat Dragon: OWASP Threat Dragon is an open-source threat modelling tool. While not a commercial competitor, it represents the lower-cost tooling alternative that Threatplane must differentiate against when selling its consultancy-led, methodology-driven approach.
- Securible: Securible is a UK-based cybersecurity consultancy focused on application security and threat modelling for engineering teams. It is comparable to Threatplane as a smaller, specialist UK player targeting similar regulated-sector clients with bespoke threat modelling engagements.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
THREATPLANE LIMITED social profiles
Digital presenceTHREATPLANE LIMITED financial estimates
Financial estimateRevenue estimate
Valuation estimate
THREATPLANE LIMITED leadership team
Management profileNumber of profiles
Profiles12 records
THREATPLANE LIMITED funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
THREATPLANE LIMITED M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about THREATPLANE LIMITED
What does THREATPLANE LIMITED do?
Threatplane provides risk-based threat modelling consulting engagements and a SaaS cybersecurity risk assessment platform for engineering and product teams. The core consulting service delivers expert-led threat modelling through a four-stage workshop process using STRIDE and the proprietary RROC framework, producing business-readable, prioritised risk outputs typically within 4 weeks at fixed scope and fixed price. The platform and developer training extend the offering to enable organisations to run threat modelling independently.
Is THREATPLANE LIMITED a public or private company?
THREATPLANE LIMITED is a private company. It is classified as founder individual operated bootstrapped and is currently operating.
When was THREATPLANE LIMITED founded?
THREATPLANE LIMITED was founded in 2017. It employs 1 to 10 people.
Where is THREATPLANE LIMITED based?
THREATPLANE LIMITED is headquartered in London, United Kingdom, in the Europe region.
How does THREATPLANE LIMITED make money?
Four revenue lines are on record. Threat Modeling Consulting Engagements are the primary driver. The others are threat Modeling Platform, developer Training and capability Transfer Engagements.
Who are THREATPLANE LIMITED's main competitors?
Broad incumbents on record are Bishop Fox, Mandiant (Google Cloud), Coalfire, NCC Group, Optiv and PwC Cybersecurity. Direct peers are ThreatModeler and IriusRisk. Emerging players are OWASP Threat Dragon and Securible.
Does THREATPLANE LIMITED have an API?
Yes. The Threatplane platform offers a comprehensive API for custom integrations, supporting custom authentication, SSO, and bespoke tooling integrations. Webhooks are supported out of the box. An integrated MCP (Model Context Protocol) server is also available, allowing connection to Copilot, Claude, Gemini, or any other compatible AI model to bring security insights and threat modelling data directly into AI workflows.
What industry is THREATPLANE LIMITED in?
THREATPLANE LIMITED's product category is Cybersecurity Consulting & Threat Modelling. Its primary akta.pro industry code is BPAKADAA, Enterprise Security Strategy & Program Advisory, with a secondary code of BPAEADAC, Threat Intelligence Services. Its NAICS code is 54161 and its SIC code is 8742.