1. Assess Asset Business Impact
Exposure Signals for Threat Prioritisation
All configured threats are shown here so you can see how the asset's exposure profile affects them before threat selection. Exposure does not change the asset's BIL. It is used to prioritise threats in Step 3 and also contributes to the suggested inherent likelihood for threats the assessor later selects.
Help: How exposure affects threat likelihood
Each exposure question is mapped to one or more relevant threats. The selected exposure level contributes the same standard uplift to those mapped threats:
- Not assessed = no response has been provided yet; this is different from None.
- None = +0.00
- Low = +0.25
- Medium = +0.50
- High = +0.75
- Very High = +1.00
If several exposure questions affect the same threat, their uplifts are added together. Only exposure questions mapped to that threat are included.
The panel below updates immediately whenever an exposure selection changes, so the assessor can see which threats are being influenced and why.
| Threat | Base Likelihood | Exposure Uplift | Suggested Likelihood | Exposure Drivers |
|---|
⚙ Exposure-to-Likelihood Configurator
Configure the exposure questions used in the assessment and identify which threats each question can influence. Every exposure question uses the same five-level scoring scale.
Help: Exposure-to-Likelihood Configurator
- Purpose: Defines the asset exposure questions that influence suggested inherent likelihood.
- Standard scoring: None = +0, Low = +0.25, Medium = +0.50, High = +0.75, Very High = +1.00.
- Threat mapping: Each exposure question is mapped only to the threats that it can reasonably influence.
- Calculation: Base Threat Likelihood + scores from applicable exposure questions, capped at 5.
- Example: If Internet Exposure is High (+0.75) and Remote Access is Medium (+0.50), a mapped threat receives +1.25 in total.
- Question management: You can rename questions, add new questions, remove questions, and change their relevant-threat mappings.
- Vulnerability Exposure: Consider known vulnerabilities, patching status, exploitability, exposure to attack, and whether effective compensating controls are in place.
- Cause / Precursor wording: This phrase is used in Inherent Risk statements when the exposure is active for a mapped threat. Up to the three highest active exposure drivers are used.
Base Threat Likelihood
| Threat | Base Likelihood |
|---|
Exposure Questions & Threat Mapping
| Priority | Threat / Hazard | Exposure / Likelihood | Cause / Precursor | Threat Impact | BIL Impact Relevance |
|---|
⚙ Threat-to-CIA Matrix Configurator
Configure how strongly each threat affects Confidentiality, Integrity and Availability. Values: 0 = no material relationship, 1 = secondary, 2 = significant, 3 = primary. Changes are saved in this browser and immediately affect threat ranking.
Help: Threat-to-CIA Configurator
- Purpose: Defines which CIA dimensions each threat can affect.
- Scale: 0 = none, 1 = secondary, 2 = significant, 3 = primary.
- Effect: The mapping is combined with BIL-C, BIL-I and BIL-A to calculate the threat impact for the asset.
- Guideline: Use the strongest reasonably expected business effect of the threat, not the likelihood of occurrence.
- Example: Denial of Service would normally have a strong Availability relationship and little or no Confidentiality relationship.
| Threat | Confidentiality | Integrity | Availability |
|---|
| Priority | Risk Statement | Threat Impact | Suggested Likelihood | Assessed Likelihood | Inherent Risk Score | Notes |
|---|
⚙ Inherent Risk to SL-T Mapping Configurator
The highest Inherent Risk determines the Resulting SL-T using this organisational mapping. This mapping is configurable and does not alter the IEC 62443-3-3 requirement applicability imported from the control library.
How control priority is determined
First: the Resulting SL-T determines which IEC 62443-3-3 requirements are applicable.
Then: requirements mapped to selected threats are prioritised using Inherent Risk × Threat Effectiveness, with a bounded Cause / Precursor context boost.
The default Risk Treatment View groups requirements beneath each risk, highest Inherent Risk first. The optional Control Portfolio View consolidates requirements across multiple risks.
⚙ IEC 62443-3-3 Requirement, Threat & Cause Mapping Configurator
Select an IEC requirement from the list, then edit its metadata and risk mappings in the workspace. Changes are saved automatically.
Help: IEC 62443-3-3 Requirement, Threat & Cause Mapping Configurator
- Purpose: Maintains the IEC 62443-3-3 requirement metadata and the existing Threat, Effectiveness, Control Type and Cause / Precursor mappings.
- SL-T filtering: Only requirements marked applicable to the Resulting SL-T from Step 4 are shown in Prioritised Controls and the Checklist.
- Cause / Precursor match: Active mapped exposure conditions provide a bounded control-priority boost of up to 25%. This does not change Inherent Risk and avoids treating exposure as a second risk score.
- Effectiveness scale: 1 = Low, 2 = Moderate, 3 = High, 4 = Very High.
- Control type: Preventive reduces likelihood; Detective, Corrective and Recovery reduce residual impact.
- Guideline: Effectiveness belongs to the Control-to-Threat relationship, not to the control globally.
- Example: MFA may be Very High against insecure credentials, High against unauthorised access, and only Moderate against ransomware.
- Multi-type controls: If a control has more than one type, the prototype splits its effect across those types to avoid double counting.
| Priority | IEC 62443-3-3 Requirement | Control Type | Relevant Threats | Cause / Precursor Addressed | Effectiveness | Assessment | Comments |
|---|
| Risk Statement | Inherent Risk | Likelihood Mitigation | Residual Likelihood | Impact Mitigation | Residual Impact | Residual Risk | Notes |
|---|
| Frequency / Likelihood ↓ | S0 | S1 | S2 | S3 | S4 | S5 |
|---|