ICS Security Risk Assessment

Two complementary assessments: standards-based and cyber-physical.

When you need it

  • You need a defensible risk position against IEC 62443 or NIST SP 800-82
  • You want to understand how a cyber event could disrupt a physical process, not just IT
  • An insurer, regulator or customer is asking for evidence of risk management

We offer two distinct but complementary risk assessments for ICS environments.

Standards-based: following IEC 62443 and the guidance in NIST Special Publication 800-82, we identify and evaluate the cyber risks in your ICS environment and deliver a comprehensive analysis with actionable insight and security measures tailored to your operations.

Cyber-physical: we evaluate the potential for cyber-physical incidents and their impact on critical operations, covering safety, environment, production and reputation. With a structured approach we analyse how attack vectors could disrupt a physical process, then provide a customised risk management plan: mitigations, security controls, incident response plans and security enhancements.

How it runs

  1. 1

    Scope and criteria

    Which standard, which zones and systems, and your risk tolerance.

  2. 2

    Standards-based assessment

    Identify and evaluate the cyber risks in the ICS environment against IEC 62443 and NIST SP 800-82.

  3. 3

    Cyber-physical assessment

    How attack vectors could disrupt the physical process, and what that would mean for safety, environment, production and reputation.

  4. 4

    Risk management plan

    Mitigations, security controls, incident response plans and security enhancements, customised to your operations.

  5. 5

    Handover

    A report your engineers, executives and auditors can each use.

What you get

  • Risks evaluated against IEC 62443 and NIST SP 800-82
  • Cyber-physical impact assessed for safety, environment, production and reputation
  • A customised risk management plan
  • Recommended controls and enhancements

Where it is used most

Questions we get asked

Which of the two do I need?

Standards-based gives you a position against a recognised framework. Cyber-physical tells you what could actually go wrong in the plant. They are complementary, and many clients do both.

Do you look at safety systems?

Yes. The cyber-physical assessment considers how an attack could disrupt a physical process, including the impact on safety.

Can this feed a sector submission?

The findings map to sector frameworks such as AESCSF, and we structure the report so it can be reused.

Talk to us about security risk assessment.

Tell us about the site, the systems and what you are trying to achieve. A consultant will reply.