← Home

IEC 62443-3-2 Risk Equation

The cyber risk equation is the teaching model behind ISA/IEC 62443-3-2 risk thinking: risk rises when a capable threat can exploit a weakness and produce a harmful outcome. Part 3-2 does not invent a proprietary formula; it expects organisations to combine likelihood and consequence (impact) consistently — usually on the corporate risk matrix illustrated in Annex B — through the Clause 4 ZCRs.

Teaching note: This page paraphrases ISA/IEC 62443-3-2:2020 concepts and common IACS training practice for learning. It is not a verbatim extract of the standard — always refer to the published text for normative wording and assessment.

Reference: ISA/IEC 62443-3-2:2020 (Clause 4; Annex B risk matrix examples)
Related: Cyber Risk Concepts | Understand Risk | Threats | Vulnerabilities | Consequence | Mitigated Likelihood and Residual Risk | Bowtie Diagrams | ZCR 2 – Initial Risk | ZCR 5 – Detailed Risk


Three-factor form

Conceptually:

Risk = Threat × Vulnerability × Consequence

If any factor is effectively zero (no realistic threat path, no exploitable weakness, or no meaningful consequence), risk collapses. In practice none of the factors are binary; they are scaled and combined through the organisation’s matrix.


Two-factor engineering form

Engineering assessments usually fold threat and vulnerability into likelihood, then combine with consequence (impact):

Likelihood = Threat × Vulnerability
Risk = Likelihood × Consequence

That matches how Part 3-2 works in the detailed assessment: ZCR 5.3 scores consequence/impact, ZCR 5.4 scores unmitigated likelihood, and ZCR 5.5 combines them into unmitigated cybersecurity risk (typically via the corporate matrix).


Frequency vs probability (likelihood)

ZCR 5.4 requires each identified threat to be evaluated for the likelihood that it will materialise. Likelihood may be quantitative (probability) or qualitative (for example low / medium / high). Two related ideas help the workshop score it consistently:

Likelihood is often evaluated twice in the detailed assessment:

  1. Unmitigated — without credit for existing cybersecurity countermeasures (establishes inherent exposure for ZCR 5.4–5.5).
  2. Mitigated — after identifying existing controls and judging their effectiveness, yielding Mitigated Threat Likelihood (MTL) and residual risk (ZCR 5.8–5.10).

Unmitigated vs residual

Part 3-2 separates inherent exposure from exposure after controls:

Both results are compared with tolerable risk (ZCR 4 early on; ZCR 5.7 and ZCR 5.11 in detail; recorded in the CRS under ZCR 6.8).


Risk matrix

Low ConsequenceMediumHigh
LikelyMediumHighExtreme
PossibleLowMediumHigh
UnlikelyLowLowMedium

Illustrative only — Annex B of Part 3-2 shows matrix styles; organisations should use the scales already used for process and enterprise risk so cyber results are comparable with other decisions.


What each factor buys you in treatment


Key Takeaways