Full Report
Andrew Ginter shares a proposed IEC 62443-3-2 Appendix C: consequence-based risk matrices that replace likelihood with credibility for high-impact OT cyber attacks. The post Consequence-Based Risk Matrices for IEC 62443-3-2 appeared first on Waterfall Security Solutions.
Analysis Summary
# Regulation/Compliance: Proposed IEC 62443-3-2 Appendix C (Consequence-Based Risk)
## Overview
This proposal seeks to update the **IEC 62443-3-2 (Risk Assessment)** standard by introducing a "Consequence-Based Risk Matrix." The core thesis is that for high-impact Operational Technology (OT) cyber-attacks, the traditional formula of **Risk = Likelihood x Impact** is flawed because sophisticated attacks are deterministic rather than random. The proposal advocates for replacing "likelihood" with "credibility" for high-consequence scenarios.
## Key Details
- **Issuing Authority:** International Electrotechnical Commission (IEC) / ISA SP99 Working Group
- **Effective Date:** TBD (Proposal stage; article dated October 6, 2026)
- **Jurisdiction:** International / Industrial Automation and Control Systems (IACS)
- **Status:** Proposed (Under review by the ISA SP99 working group)
## Requirements
### Mandatory Requirements (Proposed)
1. **Likelihood Floor for Unacceptable Impacts:** If a potential cyber impact is deemed "unacceptable," the likelihood must be set to 1 (100%) for risk modeling purposes, regardless of perceived probability.
2. **Security Level 4 (SL4) Default:** Systems where cyber risk cannot be eliminated by non-cyber means (e.g., mechanical valves) must be protected by the strongest practicable cyber measures (SL4).
3. **Residual Risk Documentation:** Organizations must document all residual risks and formally communicate them to authorities responsible for risk management.
4. **Common Cause Failure Analysis:** Assessments must account for attacks that can compromise both primary and secondary controls simultaneously (e.g., identical redundant relays on the same network).
### Recommended Practices
1. **Shift to "Credibility":** Replace "Likelihood" with "Credibility" (what is reasonable to believe regarding attacker intent and capability).
2. **Deterministic Mitigations:** Prioritize engineering-based, non-cyber mitigations (manual fall-backs, overpressure-relief valves) to render consequences "acceptable."
3. **Conservative Modeling:** Use consequence-based modeling specifically for high-end threats where "qualitative likelihood" may confuse business decision-makers.
## Affected Organizations
- **Industries:** Oil and Gas, Power Utilities, Manufacturing, Water/Wastewater, and any sector utilizing Industrial Automation and Control Systems (IACS).
- **Organization Size:** Applicable to all sizes, but primarily impacts those managing Critical Infrastructure.
- **Geographic Scope:** Global (wherever IEC 62443 is adopted).
## Compliance Timeline
- **October 2026:** Submission of the Appendix C proposal to the ISA SP99 working group.
- **TBD:** Formal review and balloting period by IEC/ISA members.
- **Final deadline:** Compliance becomes mandatory only upon the publication and adoption of the revised 62443-3-2 standard by regional regulators.
## Implementation Guidance
### Assessment Phase
- Identify all "Unacceptable Consequences" (e.g., loss of life, permanent environmental damage).
- Evaluate if current risk assessments rely on "low probability" to justify high-impact risks.
- Audit for "Cyber Common Cause Failures" where one exploit could bypass multiple layers of defense.
### Implementation Phase
- Deploy Security Level 4 (SL4) controls for critical zones.
- Integrate **Cyber-Informed Engineering (CIE)** to implement physical/mechanical failsafes that function independently of the network.
### Validation Phase
- Verify that safety engineering mitigations are truly independent of the cyber infrastructure.
- Ensure risk matrices used for board-level reporting reflect "Credibility" rather than "Probability."
## Technical Requirements
- **SL4 Protections:** Implementation of the most rigorous technical controls defined in IEC 62443 (e.g., hardware-enforced isolation, multi-factor authentication, deep packet inspection).
- **Non-Cyber Failsafes:** Electro-mechanical devices that prevent physical damage even if the control software is fully compromised.
## Penalties & Enforcement
- **Fines:** Non-compliance does not carry direct IEC fines, but regional regulators (e.g., NERC CIP in the US, NIS2 in the EU) often mandate IEC 62443 compliance, leading to potential multi-million dollar penalties.
- **Other Consequences:** Loss of "Social License to Operate," increased insurance premiums, and legal liability in the event of a catastrophic failure.
- **Enforcement:** Via third-party certification bodies and national infrastructure regulators.
## Related Standards
- **NIST CSF / SP 800-82:** Alignment on OT security controls.
- **Cyber-Informed Engineering (CIE):** The methodology used to design deterministic engineering mitigations.
- **Appendix B (IEC 62443-3-2):** Existing likelihood-based matrices (which would remain for low-consequence risks).
## Resources
- **Official Documentation:** [https://www.iec.ch](https://www.iec.ch) (IEC Webstore)
- **Guidance Documents:** ISA-62443 Series Overview
- **Tools:** Waterfall Security "Credibility vs. Likelihood" Webinar
## Practical Recommendations
- **Stop Predicting the "Unpredictable":** Cease trying to assign a percentage probability to zero-day exploits or nation-state attacks.
- **Assume Compromise:** For high-consequence systems, assume the cyber defense *will* fail and ensure the physical process remains safe through non-cyber means.
- **Update Risk Matrices:** Begin transitioning internal risk reporting to separate random/low-impact threats from deterministic/high-impact threats.