Step 3 - Risk calculation and mitigation

At this point, we have a very clear picture of the possible risk scenarios for the system under consideration. Next, we will quantify the risk by assigning a risk score to every risk scenario. Having correlated the assessment process between assets and having cross-assessed the system up to this point, the scoring will be a relative number showing where best to spend mitigation efforts to create the best return on investment and where our efforts will have the most impact.

For the scoring, we will use the earlier defined formula:

This gives us the following risk score calculation for the Siemens S7-400 ...

Get Industrial Cybersecurity now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.