Risk Register

Program Manager
CreateEditApproveAccept residualRun simulationsEdit EVMCloseExportAudit
Back to register
R-006

Cybersecurity vulnerability in remote access

ActiveControl Center SCADACybersecurityOwner: A. Volkov
Pre-MitigationHigh

$840K

Expected monetary value

Score 10.5

40% likely

ResidualModerate

$242K

Expected monetary value

Score 7.5

22% likely

Mitigation Effect

$598K

EMV reduction from response plan

Mitigation cost $275K50% effective

Cause (because of)

Third-party remote maintenance access to OT network

Uncertain Event (there is a risk that)

Unauthorized access compromises control systems

Consequence (which would lead to)

Operational disruption, regulatory penalties, remediation cost

Root Cause

Third-party remote maintenance access to OT network

Trigger / Threshold

Penetration test finds exploitable path

Early Warning Indicator

Penetration test finds exploitable path

Assumptions

Baseline assumptions per approved project execution plan.