If one of these sounds familiar, a structured risk assessment is usually the right next step.
The analysis is run as a workshop series with your key personnel. Established barrier methodology (HAZOP, LOPA, bow-tie and others) is combined with interviews with the people who know the systems, and with risk assessment according to IEC 62443‑3‑2. Threats to control and safety systems are assessed in the same framework as process safety, so the result feeds straight into your barrier management. For high-consequence scenarios we assess threats by credibility rather than likelihood alone, in line with the consequence focus of IEC 62443-3-2: we start with the worst case for the essential functions, and tackle likelihood afterwards, or base it primarily on national threat assessments or your company's own assessments of threats and likelihood. Where likelihood or probability matters to your company's methods and processes, we adapt an approach aligned with IEC 62443-3-2 for addressing likelihood with limited information sources, historic data and uncertainty.