Lumiar
Home/ Services/ Risk assessment and barrier analysis
SERVICE

Risk assessment and barrier analysis

A documented picture of cyber risk to production and safety functions, in a language operations, security and management all understand. The analysis is carried out together with your own specialists.

Typical situations

If one of these sounds familiar, a structured risk assessment is usually the right next step.

An authority audit or internal review has questioned your barrier management against cyber threats.
You are prequalifying a new SAS/ICS/OT vendor or adopting a new control system solution.
A digitalisation project is connecting your OT systems more tightly to IT and external services.
An insurer or contract counterparty requires a documented risk assessment of the control systems.

Delivery and method

The analysis is run as a workshop series with your key personnel. Established barrier methodology (HAZOP, LOPA, bow-tie and others) is combined with interviews with the people who know the systems, and with risk assessment according to IEC 62443‑3‑2. Threats to control and safety systems are assessed in the same framework as process safety, so the result feeds straight into your barrier management. For high-consequence scenarios we assess threats by credibility rather than likelihood alone, in line with the consequence focus of IEC 62443-3-2: we start with the worst case for the essential functions, and tackle likelihood afterwards, or base it primarily on national threat assessments or your company's own assessments of threats and likelihood. Where likelihood or probability matters to your company's methods and processes, we adapt an approach aligned with IEC 62443-3-2 for addressing likelihood with limited information sources, historic data and uncertainty.

01Report with a documented risk picture and assumptions
02Bow-tie barrier maps for the most important event chains
03Prioritised measures with rationale and standard references
04Review with management and specialists, so the knowledge stays with you
05Development and adaptation of methods, processes, management systems, tools and checklists, new and old
BOW-TIE, THE PRINCIPLE
Threats on the left, consequences on the right, the top event in the middle. The gold points are the barriers the analysis assesses and strengthens.
METHODOLOGICAL BASIS
IEC 62443-3-2 (risk, zones)
HAZOP · LOPA · bow-tie

Scope and format

DURATION
3 to 5 working days
for a defined facility or system, report included. Larger scopes are agreed in the scoping phase.
WAY OF WORKING
On site or remote
Workshops are held wherever works best for you; a site visit is recommended for the first analysis.
PREREQUISITES
Key personnel + documentation
2 to 4 people from operations or automation in workshops, and access to system documentation under NDA.

Frequently asked questions

Can the analysis be done without downtime?
Yes. The analysis is document and workshop based, with no intervention in running systems.
How is confidential facility information handled?
All information is handled under NDA, and the report is delivered through the channel you decide.
Do we need to have adopted IEC 62443 already?
No. The standard serves as method and reference in the analysis; the results can be reused later if you choose to adopt it more broadly.
What do we need to bring?
Key people from operations and automation in the workshops, and system documentation at whatever level you have. Missing documentation is a finding, not a blocker.

Not sure this is the right analysis for you?

Book an introductory call
ANDRE SERVICES
Security architecture and IEC 62443 Audit and compliance assessment Training and competence