Consequence-Based Risk Matrices for IEC 62443-3-2
Andrew Ginter
VP Industrial Security, Waterfall Security
Anyone who tuned into my webinar “Credibility vs. Likelihood,” is aware that I am proposing a new way to talk about risk. I argue that:
- The classic approximation “Risk = Likelihood x Impact” is a poor fit for sophisticated, high-impact attacks, but works adequately for lesser threats.
- The key problem with the classic approximation is that sophisticated attacks are not random. For example, most zero-day exploits reliably / deterministically compromise the software the exploit is launched against.
- The word “Likelihood” is widely interpreted as “probability” by non-technical and some technical people, and probability demands randomness. Assuming randomness for non-random processes can lead to serious risk management mistakes.
- Risk management is about making reasonable decisions, not estimating non-existent probabilities.
- We should therefore define “credible” as “what is reasonable to believe,” for example about: attacker intent & capabilities, our defenses, and what consequences are reasonable to expect when credible attacks meet our defenses.
- We should then evaluate what attacks and consequences are credible, and design reasonable defenses to address those credible threats, especially when credible consequences are unacceptable.
Most high-end risk assessment teams I talk to are already using most of these concepts, but they confuse business decision makers: the people who assign budgets. The confusion stems from discussions involving “qualitative likelihood.” That term is most often interpreted as “estimated probabilities,” and applied to threats and outcomes that are much more deterministic than random.
My proposals thus far have been verbal + slides. In a couple of weeks I’ve promised to submit a proposed new IEC 62443-3-2 Appendix C capturing these ideas for the ISA SP99 working group revising 62443-3-2 – Risk Assessment. Discussions in the standards development committees are confidential, however. This is why I’m posting the proposal here before I submit it, in hopes of getting your feedback while I can.
So if you can manage it, please give this thing a read and let me know what you think.
Appendix C (proposed) Consequence-Based Risk Matrices
Consequence-based matrices may be used where the likelihood-based matrices of Appendix B do not adequately represent the characteristics of the risk scenario. While likelihood is a good fit when adversary intent, targeting and attack scenarios are random, sophisticated cyber attacks are not purely random. Such attacks may have both deterministic and random elements. For example, human errors on the part of both attackers and defenders are reasonably modelled as random. Other cyber behaviors, such as exploits launched against a vulnerable system with correct preconditions, can deterministically compromise the system.
Furthermore, sophisticated attacks can take measures to reduce the effects of randomness. For example, repeated phishing attacks overcome randomness early in an attack scenario, while increased use of exploits of novel vulnerabilities in both automation systems and security systems can blind defenders and thus eliminate randomness later in these same attacks. More generally, it is very often possible to imagine attacks so sophisticated that they deterministically overcomes all cyber automation and cyber defensive mechanisms.
Likelihood = 1
Consequence-based risk modelling uses likelihood for less-consequential attacks and ignores likelihood for attacks where misinterpretation can have very serious consequences. At its most conservative, consequence-based modelling includes the following.
- To encompass even deterministic attacks, likelihood is set to 1 when potential impacts are unacceptable.
- When cyber risk cannot be effectively eliminated by procedural, electro-mechanical and other “deterministic” measures, the system in question must be protected by the strongest practicable cyber measures. In the IEC 62443 standard, SL4 are the strongest protections.
Note: Engineering mitigations in this example are mitigations used by safety engineering and the Cyber-Informed Engineering methodology. Examples include manual operations fall-backs and overpressure-relief valves. Such mitigations are independent of cyber compromise and thus can be regarded as deterministic, remaining effective when cyber-based protection mechanisms have been compromised.

Figure (1) illustrates such a risk matrix. In the matrix, acceptable consequences, or worst-case consequences that have been rendered acceptable by the introduction of non-cyber mitigations, reflect likelihood in their risk assignments. Unacceptable consequences ignore likelihood. In this example, both likelihood and impact contribute to low and medium security level outcomes, and likelihood has no impact on the SL4 target assigned to high and very high impact outcomes the organization in this example has deemed unacceptable.
Note: When using this kind of matrix, assessors estimate very cautiously the activation frequency (AF) for engineering mitigations that can be triggered by a worst-case cyber attack. For example, given that the historical Triton attack caused Safety-Instrumented Systems to shut down a petrochemical facility twice before being detected and eradicated, it may be reasonable to set the AF for unhackable safety systems at 2-5 activations per year.
Credibility vs. Likelihood
A more sophisticated consequence-based approach addresses two limitations of the “Likelihood = 1” approach:
- The approach’s very cautious assumptions can be “overkill” and result in deploying expensive mitigations that are materially in excess of what is justified by the cyber threat.
- SL4 may not be sufficient to mitigate some high-consequence scenarios. For example, some kinds of damage to electric power equipment might be deemed unacceptable in critical infrastructure applications, but most industrial systems deploy software protective relays rather than more deterministic electro-mechanical protections to protect electrical equipment from damage.
The concept of “credibility” is used to address these limitations. Credibility is defined as what is reasonable to believe, for example about:
- adversary intent and capabilities,
- attack opportunities that may remain in defensive postures, and
- what consequences are reasonable to expect when credible attacks meet cyber defenses.
An example of a corresponding risk matrix is illustrated in Figure (2).

In this matrix, again, likelihood is used conventionally for scenarios where impacts are deemed acceptable losses. For unacceptable consequences, the theoretical set of possible attack scenarios, including “science fiction” scenarios that are not considered credible, is divided into two subsets. The lower set in the diagram is the set of attacks that the defensive posture under consideration defeats with a high degree of confidence. The upper set is not thus defeated. All attacks in the set, if successful, have unacceptable consequences.
In this formulation, risk assessors evaluate what attack capabilities of known and postulated adversaries are reasonable to expect – ie: which attacks are credible. For credible attacks, assessors evaluate the effectiveness of SL1-4 mitigations against those attacks, and generally assign a security level greater than or equal to the lowest level expected to defeat the attack scenario with a high degree of confidence, or reduce consequences to an acceptable level. For example, most practitioners would determine that an MFA token defeats password phishing attacks with a high degree of confidence, but may not defeat a phishing attack joined with a zero-day exploit of the MFA system.
This analysis may result in credible threats and attacks with unacceptable consequences that are not defeated by a high degree of confidence, even after deploying SL4 protections. When this is the case, the risk assessment is required to document these residual risks and communicate these risks to authorities in the owner and operator who are responsible for managing risk.
Caution: When evaluating credible consequences of a specific attack scenario, we must account for cyber common cause failures. Any attack that can compromise both the primary and secondary security controls counts as such a failure. For example, multiply redundant protective relays of the same make and model may be strong protection against random relay equipment failures. However, if those same relays are all deployed in the same network zone, they risk being compromised simultaneously by a network-based exploit of a remote code execution vulnerability in the relay software.
About the author
Andrew Ginter
VP Industrial Security, Waterfall Security
Andrew Ginter is the most widely-read author in the industrial security space, with over 23,000 copies of his three books in print. He is a trusted advisor to the world's most secure industrial enterprises, and contributes regularly to industrial cybersecurity standards and guidance.
Share
Trending posts
Consequence-Based Risk Matrices for IEC 62443-3-2
New Attack Visualizations, AI Attack Insights & Threat Data
Is Your OT Actually Isolated?
A 5-Minute Self-Assessment
Stay up to date
Subscribe to our blog and receive insights straight to your inbox