// ASSUME COMPROMISEDesign to limit operational consequence.
Assume compromise. Design for consequence.
Assume something digital goes wrong. Follow it into the process and find where its consequence can still be limited.
- 01THREE DECISIONS
- 02A MODEL THAT CHANGES WITH EACH ANSWER
- 03OT CONSEQUENCE CHAIN TO KEEP · NO EMAIL NEEDED
You will not be asked for site names, network details or vulnerabilities. Your choices stay in this browser.
Prefer to talk first? Contact ICP// WHAT THIS CHECK ASKS
What digital condition are we testing?
- Loss of communications
- Bad or misleading input
- Unauthorised command
- Loss of visibility
- Not sure
What could operations experience?
- Loss of control
- Degraded operation
- Uncertain state
- Unsafe transition
- Not sure
Where could resilience sit?
- Physical safeguard
- Control fallback
- Architecture boundary
- Operating procedure
- Not sure
A way of reasoning about consequence. It is not a HAZOP, a formal safety assessment, engineering approval or a cyber-risk assessment.
