2025 Spring Meeting and 21st Global Congress on Process Safety
(32cy) Applying Inherently Safer Design Techniques to Cybersecurity
Author
Patrick O'Brien - Presenter, Exida
In process safety the hierarchy of controls has been used as an effective method for prioritizing the most effective risk reduction measures to bring process safety risk to tolerable levels. A similar approach should be applied to cybersecurity risks as well to ensure that organizations design cyber-resiliency into the process control network as opposed to adding cybersecurity as an afterthought. Often when cybersecurity is added late in the process there is a heavy reliance on administrative measures compared to more effective risk reduction techniques. This paper will provide a methodology for applying the hierarchy of controls for cybersecurity with an emphasis on practical examples for inherently more secure design, which can be applied at the site, system, and device level.