Why nobody uses TVC model? AI answers.

Somewhere around 2007 I started to use my own TiddlyWiki based ISMS that applied the principle of TVC (Controls offset Vulnerabilities that could be exploited by Threats).

But even today I am unable to find any commercial or open-source product for ISMS/GRC that would apply the same principle. Why's that? Why nobody seems to think that this is the best way to combine risk-based and compliance-based security?

To find the answer I asked three AI: Copilot, ChatGPT and Gemini (click to read their full answers).

Most interesting excerpts from AI's answers

Note: all 3 AI confirm that TVC approach is actually superior and modern today. But they all differ in explanations why it is not really used.

Copilot:

Companies don’t want TVC because TVC forces them to behave like engineering organizations — but most companies treat security as a compliance function, not an engineering discipline.

TVC is engineering. GRC is bureaucracy.

Engineering threatens bureaucracy. So bureaucracy wins.

ChatGPT

Historically, compliance came before risk, the first generation of GRC products (late 1990s–2010) were built primarily for auditors.

TVC is almost identical to modern attack graph theory. Twenty years ago this wasn't mainstream.

A compliance database is easy, modelling threats is not.

TVC isn't directly auditable - auditors need yes/no answers.

Gemini

You were (and are) right about the core concept: a control implemented without a target vulnerability is just security theatre, and a vulnerability without an active threat is just technical debt.

While traditional enterprise GRC tools ignored this, the industry is actually starting to loop back toward your 2007 realization through modern disciplines like:

Threat-Informed Defense (MITRE ATT&CK): Modern SOCs map controls (detections/mitigations) directly to Techniques (Threats) exploiting system weaknesses (Vulnerabilities),
Graph-Based Security: Cyber Asset Attack Surface Management (CAASM) tools are adopting graph databases (Neo4j style) to re-introduce relational linking between assets, flaws, exposures, and controls.