1. Assess Asset Business Impact

Select the OVIC-aligned Business Impact Level for Confidentiality, Integrity and Availability.
Dimension
Description
Business Impact Level (OVIC)
C
ConfidentialityBIL-C
The impact to the confidentiality of information.
I
IntegrityBIL-I
The impact to the accuracy and trustworthiness of information.
A
AvailabilityBIL-A
The impact to the availability of systems and information.
Overall BIL (BIL-V) 0
Highest of C0 / I0 / A0
Primary Driver None
Assessment Basis (CIA)
C0N/A
I0N/A
A0N/A
i BIL represents potential business impact. It does not determine how likely a cyber threat is to occur.

2. Asset Exposure

Describe the asset's exposure characteristics. Exposure is used to prioritise threats and also to calculate suggested inherent likelihood for threats selected by the assessor.

Exposure Signals for Threat Prioritisation

All configured threats are shown here so you can see how the asset's exposure profile affects them before threat selection. Exposure does not change the asset's BIL. It is used to prioritise threats in Step 3 and also contributes to the suggested inherent likelihood for threats the assessor later selects.

Help: How exposure affects threat likelihood

Each exposure question is mapped to one or more relevant threats. The selected exposure level contributes the same standard uplift to those mapped threats:

  • Not assessed = no response has been provided yet; this is different from None.
  • None = +0.00
  • Low = +0.25
  • Medium = +0.50
  • High = +0.75
  • Very High = +1.00
Suggested Likelihood = Base Threat Likelihood + applicable exposure uplifts, capped at 5

If several exposure questions affect the same threat, their uplifts are added together. Only exposure questions mapped to that threat are included.

The panel below updates immediately whenever an exposure selection changes, so the assessor can see which threats are being influenced and why.

Threat Base Likelihood Exposure Uplift Suggested Likelihood Exposure Drivers
⚙ Exposure-to-Likelihood Configurator

Configure the exposure questions used in the assessment and identify which threats each question can influence. Every exposure question uses the same five-level scoring scale.

Help: Exposure-to-Likelihood Configurator
  • Purpose: Defines the asset exposure questions that influence suggested inherent likelihood.
  • Standard scoring: None = +0, Low = +0.25, Medium = +0.50, High = +0.75, Very High = +1.00.
  • Threat mapping: Each exposure question is mapped only to the threats that it can reasonably influence.
  • Calculation: Base Threat Likelihood + scores from applicable exposure questions, capped at 5.
  • Example: If Internet Exposure is High (+0.75) and Remote Access is Medium (+0.50), a mapped threat receives +1.25 in total.
  • Question management: You can rename questions, add new questions, remove questions, and change their relevant-threat mappings.
  • Vulnerability Exposure: Consider known vulnerabilities, patching status, exploitability, exposure to attack, and whether effective compensating controls are in place.
  • Cause / Precursor wording: This phrase is used in Inherent Risk statements when the exposure is active for a mapped threat. Up to the three highest active exposure drivers are used.
None+0.00
Low+0.25
Medium+0.50
High+0.75
Very High+1.00
Exposure questions and mappings are configurable and stored in this browser. Assessment selections reset on page reload.

Base Threat Likelihood

Prototype default: 1 – Rare for all threats. Exposure can increase the suggested likelihood from this baseline.
ThreatBase Likelihood

Exposure Questions & Threat Mapping

3. Identify Relevant Threats

Exposure-based prioritisation: Threats are ranked using the asset's exposure profile from Step 2. Threats rated High or Very High under Exposure / Likelihood are automatically selected for risk assessment. The assessor can manually include or exclude any threat, and manual choices override the recommendation for the current assessment session.
Threats with the strongest mapped exposure are shown first. Exposure / Likelihood updates live from Step 2. Cause / Precursor shows the configured exposure conditions driving that threat, rather than repeating the assessment questions. BIL Impact Relevance remains based on BIL and the Threat-to-CIA mapping.
Help: How the Relative Score is calculated

The Relative Score is used to rank threats according to how strongly each threat could affect the asset's assessed Confidentiality, Integrity and Availability impact.

Relative Score = MAX(BIL-C × C Weight, BIL-I × I Weight, BIL-A × A Weight)

Threat-to-CIA weights are configured on a 0–3 scale and are normalised before calculation:

  • 0 – None: no meaningful relationship to that CIA dimension.
  • 1 – Secondary: limited relationship.
  • 2 – Significant: meaningful relationship.
  • 3 – Primary: strongest relationship.

The normalised weights are therefore 0, 0.33, 0.67 and 1.00. The calculation uses the highest resulting CIA value, because the threat is prioritised according to its strongest business-impact pathway.

Example
Assume the asset is assessed as C2 / I4 / A5 and a threat is mapped as C1 / I2 / A3.

Confidentiality = 2 × 0.33 = 0.66
Integrity = 4 × 0.67 = 2.68
Availability = 5 × 1.00 = 5.00

Relative Score = 5.00

Important: Relative Score represents potential impact relevance, not likelihood. Likelihood is assessed later using Asset Exposure and the inherent-likelihood model.

0 relevant threats
Priority Threat / Hazard Exposure / Likelihood Cause / Precursor Threat Impact BIL Impact Relevance
⚙ Threat-to-CIA Matrix Configurator

Configure how strongly each threat affects Confidentiality, Integrity and Availability. Values: 0 = no material relationship, 1 = secondary, 2 = significant, 3 = primary. Changes are saved in this browser and immediately affect threat ranking.

Help: Threat-to-CIA Configurator
  • Purpose: Defines which CIA dimensions each threat can affect.
  • Scale: 0 = none, 1 = secondary, 2 = significant, 3 = primary.
  • Effect: The mapping is combined with BIL-C, BIL-I and BIL-A to calculate the threat impact for the asset.
  • Guideline: Use the strongest reasonably expected business effect of the threat, not the likelihood of occurrence.
  • Example: Denial of Service would normally have a strong Availability relationship and little or no Confidentiality relationship.
Configuration scale: 0–3
Threat Confidentiality Integrity Availability

4. Inherent Risk & Target Security Level

Suggested inherent likelihood is derived from the Asset Exposure assessment. The assessor can override the suggested value where justified.
How Inherent Risk is derived

Inherent Risk is the level of cyber risk before considering the effectiveness of the controls assessed later in the process.

Inherent Risk = Assessed Inherent Likelihood × Threat Impact

The two inputs are derived as follows:

  1. Threat Impact
    The asset's BIL-C, BIL-I and BIL-A values are combined with the configured Threat-to-CIA relationship. The strongest CIA result becomes the threat's impact.
    Threat Impact = MAX(BIL-C × C Weight, BIL-I × I Weight, BIL-A × A Weight)
  2. Assessed Inherent Likelihood
    Each threat starts with a configurable Base Likelihood. Asset Exposure can increase that likelihood where an exposure question is mapped to the threat.
    Suggested Likelihood = Base Likelihood + applicable Exposure Uplifts, capped at 5
    The assessor may override the suggested likelihood if there is a justified reason.
  3. Risk Matrix
    The assessed likelihood and threat impact are then looked up against the configured Likelihood × Impact risk matrix to produce the Inherent Risk value and colour.
Example
Threat Impact = 4
Assessed Inherent Likelihood = 3
The system looks up Likelihood 3 × Impact 4 in the risk matrix and returns the configured Inherent Risk value.

Cause / Precursor: The generated risk statement uses active Asset Exposure factors mapped to the threat. The system takes up to the three highest exposure drivers and uses the configurable Cause / Precursor wording from Step 3.

Target Security Level: After all selected threats are assessed, the highest Inherent Risk is mapped to the Resulting SL-T. By default, Green/Blue = SL-T 1, Yellow = SL-T 2, Orange = SL-T 3 and Red = SL-T 4. The mapping can be configured below.

Important: Controls are not used when calculating Inherent Risk. Their effect is assessed later and is reflected in Residual Risk.

0 threats assessed
Resulting Target Security Level
Pending
Determined by highest Inherent Risk
Select threats and assess Inherent Risk to determine SL-T.
Priority Risk Statement Threat Impact Suggested Likelihood Assessed Likelihood Inherent Risk Score Notes
⚙ Inherent Risk to SL-T Mapping Configurator

The highest Inherent Risk determines the Resulting SL-T using this organisational mapping. This mapping is configurable and does not alter the IEC 62443-3-3 requirement applicability imported from the control library.

5. IEC 62443-3-3 Controls

Review the IEC 62443-3-3 requirements applicable to the Resulting SL-T. Requirements linked to the selected risks are shown first, with a simple explanation of why they are prioritised.
SL-T pending
Resulting SL-T
Derived from Step 4 Inherent Risk
Applicable IEC Requirements
0
Filtered by the resulting SL-T
Risk-Prioritised
0
Mapped to selected threats
How control priority is determined

First: the Resulting SL-T determines which IEC 62443-3-3 requirements are applicable.

Then: requirements mapped to selected threats are prioritised using Inherent Risk × Threat Effectiveness, with a bounded Cause / Precursor context boost.

The default Risk Treatment View groups requirements beneath each risk, highest Inherent Risk first. The optional Control Portfolio View consolidates requirements across multiple risks.

⚙ IEC 62443-3-3 Requirement, Threat & Cause Mapping Configurator

Select an IEC requirement from the list, then edit its metadata and risk mappings in the workspace. Changes are saved automatically.

Help: IEC 62443-3-3 Requirement, Threat & Cause Mapping Configurator
  • Purpose: Maintains the IEC 62443-3-3 requirement metadata and the existing Threat, Effectiveness, Control Type and Cause / Precursor mappings.
  • SL-T filtering: Only requirements marked applicable to the Resulting SL-T from Step 4 are shown in Prioritised Controls and the Checklist.
  • Cause / Precursor match: Active mapped exposure conditions provide a bounded control-priority boost of up to 25%. This does not change Inherent Risk and avoids treating exposure as a second risk score.
  • Effectiveness scale: 1 = Low, 2 = Moderate, 3 = High, 4 = Very High.
  • Control type: Preventive reduces likelihood; Detective, Corrective and Recovery reduce residual impact.
  • Guideline: Effectiveness belongs to the Control-to-Threat relationship, not to the control globally.
  • Example: MFA may be Very High against insecure credentials, High against unauthorised access, and only Moderate against ransomware.
  • Multi-type controls: If a control has more than one type, the prototype splits its effect across those types to avoid double counting.
Effectiveness: 1 Low · 2 Moderate · 3 High · 4 Very High

6. Control Checklist

Assess the implementation status of each prioritised control. Preventive controls reduce likelihood, while Detective, Corrective and Recovery controls reduce residual impact.
0 controls assessed
Priority IEC 62443-3-3 Requirement Control Type Relevant Threats Cause / Precursor Addressed Effectiveness Assessment Comments

7. Residual Risk

How Residual Risk is derived

Residual Risk starts from the Inherent Risk values and changes only where assessed controls provide measurable mitigation.

  • Preventive controls can reduce Residual Likelihood.
  • Detective, Corrective and Recovery controls can reduce Residual Impact.
  • Blank, Not Implemented, Not Sure or Not Applicable controls provide no mitigation.
If Likelihood Mitigation = 0% → Residual Likelihood = Assessed Inherent Likelihood
If Impact Mitigation = 0% → Residual Impact = Inherent Impact
If both are 0% → Residual Risk = Inherent Risk

The resulting Residual Likelihood and Residual Impact are then looked up against the same risk matrix used for Inherent Risk.

Residual risk is calculated after considering how implemented controls reduce likelihood and impact.
0 risks calculated
Risk Statement Inherent Risk Likelihood Mitigation Residual Likelihood Impact Mitigation Residual Impact Residual Risk Notes
Rows = Likelihood 1–5 · Columns = Impact 0–5
Severity / Consequence →
Frequency / Likelihood ↓ S0S1S2S3S4S5

8. Report

Review the consolidated assessment report, add recommendations, and download a copy.

Cybersecurity Risk Assessment Report

Generated from the BIL-driven cybersecurity risk assessment prototype.

Recommendations