Consequence is the undesirable result of an incident — usually described in terms of health and safety effects, environmental impacts, loss of property and business interruption. In cybersecurity risk work it is often stated as the worst-case scenario if the threat occurs. Part 3-2 requires consequence and impact to be determined for each threat scenario in the detailed assessment (ZCR 5.3).
Reference: ISA/IEC 62443-3-2:2020, Clause 4.6.4
Related:
Cyber Risk Concepts
|
Risk Equation
|
Threats
|
Vulnerabilities
|
Criticality Assessment
|
ZCR 2
|
ZCR 5
| Meaning | Example | |
|---|---|---|
| Consequence | What undesirable thing happens | The consequence of the incident was a spill |
| Impact | Measure of the ultimate loss or harm associated with that consequence (injuries/fatalities, extent of damage, financial loss, IP loss, lost production, market share, recovery cost, and similar) | The impact of the spill was a $100,000 fine and $25,000 in clean-up expense |
Part 3-2 language in ZCR 5.3 asks for both consequence and impact. Scoring usually lands on the organisation’s impact scale so results fit the corporate risk matrix (risk equation).
When stating worst-case consequence for unmitigated risk, assume cybersecurity countermeasures are not in place (aligned with unmitigated likelihood in ZCR 5.4). That reveals inherent exposure before credit is taken for firewalls, access control, monitoring and similar measures. Non-cyber independent protection layers may still be recognised where the method allows.
Categories are set by the asset owner / senior management so cyber risk ranks alongside other enterprise risk. Common categories include:
Scenarios are typically scored per category, but only the highest category score is used in risk ranking for that scenario. Example consequence scales differ between organisations; reuse the scale already used for process hazards and enterprise risk wherever possible.