An Integrated Cyber-Risk–Based Process Safety Framework for Cybersecurity Risk Assessment in Chemical Process Industries
Abstract
Although industrial control systems are crucial for enhancing safety and reliability in the chemical process industries (CPI), they also introduce cybersecurity vulnerabilities. This article presents a comprehensive method for prioritizing and exploring these vulnerabilities in CPI process control systems, offering structured strategies for assessing and mitigating cyber risks. Our approach, namely an integrated cyber-risk-based process safety (RBPS) framework, integrates the cybersecurity RBPS management system with cyber process hazard analysis, layer of protection analysis, common vulnerability scoring system, and exploit prediction scoring system. To demonstrate the effectiveness of this method, we assessed the cybersecurity risks associated with a distillation column and its overhead receiver in a refinery. In this case study, we evaluated four threat vectors: data manipulation, denial of service (DoS), privilege escalation, and credential stuffing using the cyber-RBPS framework. The results indicated that privilege escalation posed the highest risk in this specific example. These findings underscore the necessity of a robust defense-in-depth strategy encompassing advanced technological safeguards, continuous monitoring, and workforce training.