What Cyber Risk Really Means in Critical Infrastructure
Cyber risk in a critical infrastructure operator is not the same thing as cyber risk in a typical IT business, and treating it that way is the single most common mistake GRC teams make.
In IT, the dominant concern is usually confidentiality: protecting data from being stolen or exposed. In a substation, a water treatment plant, a rail signaling system, or an airport baggage network, the dominant concern flips. Availability and integrity almost always outrank confidentiality, because the consequence of a successful attack is not a data breach notice -- it is a train that cannot safely stop, a pump that will not shut off, or a control room that loses visibility into what the plant is actually doing.
A useful working definition: cyber risk is the combination of a credible threat, an exploitable weakness, and a consequence that matters to the business or to public safety. All three parts have to be present. A theoretical vulnerability with no realistic threat actor and no operational consequence is not a risk worth spending your organization's limited attention on -- it is noise. Good risk programs spend their effort filtering signal from noise, not cataloguing every possible weakness with equal urgency.
This is also why risk in OT environments has to be engineered, not guessed. You cannot reason about consequence without understanding the physical process behind the system: what happens if this PLC receives a bad command, what happens if this HMI loses its feed, what happens if this remote access path is abused at 3am on a weekend. Risk assessment that is disconnected from the actual engineering reality of the facility produces a document, not a defensible risk position.
Reading
6 minutes