← Home
IEC 62443-3-2 Risk Equation
The cyber risk equation is the teaching model behind ISA/IEC 62443-3-2 risk
thinking: risk rises when a capable threat can exploit a weakness and produce a harmful
outcome. Part 3-2 does not invent a proprietary formula; it expects organisations to combine
likelihood and consequence (impact) consistently — usually
on the corporate risk matrix illustrated in Annex B — through the Clause 4 ZCRs.
Teaching note: This page paraphrases ISA/IEC 62443-3-2:2020 concepts and
common IACS training practice for learning. It is not a verbatim extract of the standard —
always refer to the published text for normative wording and assessment.
Reference: ISA/IEC 62443-3-2:2020 (Clause 4; Annex B risk matrix examples)
Related:
Cyber Risk Concepts
|
Understand Risk
|
Threats
|
Vulnerabilities
|
Consequence
|
Mitigated Likelihood and Residual Risk
|
Bowtie Diagrams
|
ZCR 2 – Initial Risk
|
ZCR 5 – Detailed Risk
Three-factor form
Conceptually:
Risk = Threat × Vulnerability × Consequence
- Threat — who or what can cause harm, and how (source, capability, vector).
See Threats.
- Vulnerability — a weakness that can be exploited.
See Vulnerabilities.
- Consequence — the undesirable result if exploitation succeeds (before scoring impact).
See Consequence.
If any factor is effectively zero (no realistic threat path, no exploitable weakness, or no
meaningful consequence), risk collapses. In practice none of the factors are binary; they are
scaled and combined through the organisation’s matrix.
Two-factor engineering form
Engineering assessments usually fold threat and vulnerability into
likelihood, then combine with consequence (impact):
Likelihood = Threat × Vulnerability
Risk = Likelihood × Consequence
That matches how Part 3-2 works in the detailed assessment:
ZCR 5.3
scores consequence/impact,
ZCR 5.4
scores unmitigated likelihood, and
ZCR 5.5
combines them into unmitigated cybersecurity risk (typically via the corporate matrix).
Frequency vs probability (likelihood)
ZCR 5.4
requires each identified threat to be evaluated for the likelihood that it will materialise.
Likelihood may be quantitative (probability) or qualitative
(for example low / medium / high). Two related ideas help the workshop score it consistently:
-
Frequency — how often the threat arises. Influenced by how attractive the
target is and how large the attack surface is (exposure of access points, remote paths,
wireless, portable media, and so on).
-
Probability of success — given that the threat arises, how likely is a
successful compromise? Influenced by threat-actor capability and intent, and by known
vulnerabilities on the path (access points, LAN, end devices — see
discovery questions).
Likelihood is often evaluated twice in the detailed assessment:
-
Unmitigated — without credit for existing cybersecurity countermeasures
(establishes inherent exposure for ZCR 5.4–5.5).
-
Mitigated — after identifying existing controls and judging their
effectiveness, yielding
Mitigated Threat Likelihood (MTL)
and residual risk (ZCR 5.8–5.10).
Unmitigated vs residual
Part 3-2 separates inherent exposure from exposure after controls:
- Unmitigated risk — treat existing cybersecurity countermeasures as
temporarily removed when scoring likelihood (ZCR 5.4–5.5). Non-cyber IPLs (physical
security, mechanical safeguards, emergency procedures) may still be recognised.
- Residual risk — put existing (and later additional) countermeasures back
and re-score (ZCR 5.8–5.10). Likelihood is often evaluated twice: first without cyber
controls (unmitigated), then with them credited as
Mitigated Threat Likelihood (MTL).
Both results are compared with tolerable risk
(ZCR 4 early on;
ZCR 5.7
and
ZCR 5.11
in detail; recorded in the CRS under
ZCR 6.8).
Risk matrix
| Low Consequence | Medium | High |
| Likely | Medium | High | Extreme |
| Possible | Low | Medium | High |
| Unlikely | Low | Low | Medium |
Illustrative only — Annex B of Part 3-2 shows matrix styles; organisations should use the
scales already used for process and enterprise risk so cyber results are comparable with
other decisions.
What each factor buys you in treatment
- Reduce threat exposure — limit who can reach the SUC (segmentation,
access control, supplier governance, physical barriers).
- Reduce vulnerability — patch, harden, remove insecure protocols,
fix policy/procedure gaps, improve configuration management.
- Limit consequence — safety systems, redundancy, graceful degradation,
backup/recovery, spill and emergency response (often non-cyber IPLs).
Key Takeaways
- Teaching model: Risk = Threat × Vulnerability × Consequence.
- Practice: Likelihood = Threat × Vulnerability; Risk = Likelihood × Consequence.
- Likelihood blends frequency (how often) with probability of success (capability, intent, vulns).
- Part 3-2 applies that via unmitigated then residual (MTL) scoring against tolerable risk.
- Use one consistent matrix from initial assessment through detailed assessment and CRS.