Bowtie diagrams help teams visualise how threats can lead to a loss of
control (the “top event”) and then to consequences — with
preventative barriers on the left and recovery
barriers on the right. They are a simplified relative of fault-tree thinking and are
widely used in process industries; for cyber risk they make countermeasure conversations
concrete during detailed assessment.
Teaching note: Paraphrased for learning from IACS risk-assessment practice
and related ISA/IEC 62443 concepts. Not a verbatim extract of ISA publications or the
standard — always refer to published text for normative wording.
Figure – Overview: threats on the left, preventative controls, top event (loss of
confidentiality, integrity or availability), recovery controls, then consequences.
Elements
Threats — events or attacker actions that can lead to the top event
(for digital risk, typically actions by threat actors).
Hazard / risk source — an activity the organisation performs that can
cause damage if control is lost (for example, remote SCADA commands to field equipment).
Top event — loss of control: typically loss of confidentiality, integrity
or availability for cyber scenarios.
Control (preventative) barriers — reduce the likelihood that a threat
becomes the top event.
Control (recovery) barriers — reduce impact or restore stability after
the top event (detection, isolation, backup/restore, incident response).
Barrier colouring in workshop tools often encodes quality or confidence (strong vs needs
attention) — treat that as a facilitation aid, not a Part 3-2 normative requirement.
Figure – Worked bowtie example (teaching): threats such as unauthorized WAN access
feed preventative barriers; the hazard is SCADA commands to a substation; the top
event is loss of integrity; recovery barriers aim to limit consequences such as a
large electricity outage. Barrier colour indicates facilitation quality (strong vs
needs attention), not a normative Part 3-2 scale.
Selecting barriers with Part 3-3
ISA/IEC 62443-3-3 system requirements are a practical catalogue of
countermeasures that can sit as barriers on the bowtie. Preventative
examples include awareness training, software/firmware integrity (e.g. digitally signed
updates), and network segmentation / zone boundary protection. Recovery examples include
host- or network-based intrusion detection and restore capabilities.
When documenting existing or proposed barriers, record effectiveness so the team can
re-evaluate likelihood and impact
(mitigated likelihood,
ZCR 5.8–5.10).
Uses beyond design
Planning and detailed risk workshops (ZCR 5.1 threats through 5.12 additional controls)
Explaining defence-in-depth to non-specialists
Incident analysis — reconstructing which barriers failed or were missing
Key takeaways
Bowties show threats → preventative barriers → top event → recovery barriers → consequences.
They complement (do not replace) Part 3-2 scoring and zone/conduit models.
Part 3-3 requirements are a useful source of named barriers with SL capability context.