← Home

IEC 62443-3-2 – Bowtie Diagrams

Bowtie diagrams help teams visualise how threats can lead to a loss of control (the “top event”) and then to consequences — with preventative barriers on the left and recovery barriers on the right. They are a simplified relative of fault-tree thinking and are widely used in process industries; for cyber risk they make countermeasure conversations concrete during detailed assessment.

Teaching note: Paraphrased for learning from IACS risk-assessment practice and related ISA/IEC 62443 concepts. Not a verbatim extract of ISA publications or the standard — always refer to published text for normative wording.

Related: Threats | Consequence | Mitigated Likelihood and Residual Risk | Vulnerabilities | Risk Equation | ZCR 5 | Part 3-3 Security Levels | Defence in Depth | SP and Risk Assessment

Bowtie diagram: threats, preventative controls, top event, recovery controls, consequences
Figure – Overview: threats on the left, preventative controls, top event (loss of confidentiality, integrity or availability), recovery controls, then consequences.

Elements

Barrier colouring in workshop tools often encodes quality or confidence (strong vs needs attention) — treat that as a facilitation aid, not a Part 3-2 normative requirement.

Bowtie worked example: unauthorized WAN access and other threats, preventative barriers, hazard of SCADA commands to substation, top event loss of integrity, recovery barriers, and consequences including electricity outage
Figure – Worked bowtie example (teaching): threats such as unauthorized WAN access feed preventative barriers; the hazard is SCADA commands to a substation; the top event is loss of integrity; recovery barriers aim to limit consequences such as a large electricity outage. Barrier colour indicates facilitation quality (strong vs needs attention), not a normative Part 3-2 scale.

Selecting barriers with Part 3-3

ISA/IEC 62443-3-3 system requirements are a practical catalogue of countermeasures that can sit as barriers on the bowtie. Preventative examples include awareness training, software/firmware integrity (e.g. digitally signed updates), and network segmentation / zone boundary protection. Recovery examples include host- or network-based intrusion detection and restore capabilities.

When documenting existing or proposed barriers, record effectiveness so the team can re-evaluate likelihood and impact (mitigated likelihood, ZCR 5.8–5.10).


Uses beyond design


Key takeaways