Skip to content
// ASSUME COMPROMISEDesign to limit operational consequence.

Assume compromise. Design for consequence.

Assume something digital goes wrong. Follow it into the process and find where its consequence can still be limited.

  1. 01THREE DECISIONS
  2. 02A MODEL THAT CHANGES WITH EACH ANSWER
  3. 03OT CONSEQUENCE CHAIN TO KEEP · NO EMAIL NEEDED

You will not be asked for site names, network details or vulnerabilities. Your choices stay in this browser.

Prefer to talk first? Contact ICP

// WHAT THIS CHECK ASKS

  1. What digital condition are we testing?

    • Loss of communications
    • Bad or misleading input
    • Unauthorised command
    • Loss of visibility
    • Not sure
  2. What could operations experience?

    • Loss of control
    • Degraded operation
    • Uncertain state
    • Unsafe transition
    • Not sure
  3. Where could resilience sit?

    • Physical safeguard
    • Control fallback
    • Architecture boundary
    • Operating procedure
    • Not sure

A way of reasoning about consequence. It is not a HAZOP, a formal safety assessment, engineering approval or a cyber-risk assessment.