How do you measure cyber risk? The pat answer is likelihood X impact, but in reality neither of these variables are very well understood. Most cyber incident databases are inadequate due to a lack of reporting or, more often, a lack of recognition of an incident. A control system that falls offline or mis-behaves is often repaired or replaced as soon as it is discovered. That is the mandate of high availability systems. Cyber forensics or event analysis (in most trivial cases) are never part of operational uptime.

The other challenge in understanding risk and impact is in the question of how do you measure how you are doing if nothing happens? I often joke that if you follow all of my recommendations for optimum security then nothing will happen! This is over-simplified and not at all true, but we can’t simply throw our hands up and say it can’t be measured.

OT cyber security is one of the fastest growing concerns with literally thousands of products, services and vendors promising the moon when it comes to how you should be protecting yourself.

That is why I love this latest podcast from Ron Brash. Ron and Andrew Ginter sat down with our friends at Waterfall to talk about how you measure or quantify risk and remediation.

Related Resources

Blog

Quantifying Risk in OT Cyber Security

An initial process on Risk management and vulnerability management in terms of probabilities of successful cyber attacks on Operational Technology (OT).

Learn More
Blog

The Value of Empirical Evidence to Quantify OT Cyber Risk

Providing OT or system-specific context to true, ICS Cyber Security Risk

Learn More
Blog

The Balance of Risk Reduction vs. Cost, and The Question of Exposure

Pragmatically examining exposure as part of the risk reduction process to prevent and mitigate risks without fear-uncertainty-and-doubt (FUD).

Learn More

Subscribe to stay in the loop

Subscribe now to receive the latest OT cyber security expertise, trends and best practices to protect your industrial systems.