Concept of Operations (ConOps) & Minimum Operating Requirements (MoR)
J. McKenney
This is treatise WG-01-UI-14 in the working group's own reference numbering. It builds directly on two sibling treatises cited in its own References section, the group's Quantitative Cyber-Physical FMECA treatise and its RCIL/SCIL reinsurance treatise, carrying their engineering findings forward into a facility-level operating-mode model and a set of parametric insurance triggers.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
A facility with an engineering drawing but no operating manual does not know how to run itself when something goes wrong. Most mission-critical facilities are in that position for cyber-physical failure. Chillers, pumps, and switchgear have documented procedures for mechanical failure. Almost none of the facilities the author has audited have a written procedure for what to do when the building management system or the electrical monitoring system itself is compromised.
The answer, taken from nuclear and process-safety engineering, is a formal Concept of Operations built on seven operating modes, from normal operation to emergency shutdown, with a Minimum Operating Requirement: a stated floor of protective systems and telemetry below which the facility may not keep running. Each mode carries a required security level target, so a cyber compromise, not only a mechanical failure, has a defined, pre-agreed response.
The final contribution is actuarial. A facility that adopts this model can turn a disputed judgment about when a loss becomes total into an objective, contractually defined trigger. The paper works through that trigger for a parametric policy, including where a warranty the ConOps proposes differs from a duty the underlying exclusion imposes.
Abstract#
Engineering reference architectures without a Concept of Operations (ConOps) are drawings without operating instructions. Mechanical and electrical disciplines keep rigorous handbooks for physical degradation, yet mission-critical facilities routinely lack a ConOps that accounts for cyber-physical disruption. This treatise adapts nuclear safety principles (10 CFR 50.36 Technical Specifications) and process safety engineering (IEC 61511) into a cyber-physical ConOps spanning Seven Operational Modes (M1 Normal through M7 Emergency Shutdown). We formulate the Minimum Operating Requirements (MoR): the irreducible vector of protective systems, telemetry streams, and containment boundaries below which a facility is legally and operationally prohibited from operating. Each mode maps to a required IEC 62443-3-2 Security Level Target (SL-T); we show how unaddressed cyber exploits force involuntary mode transitions, and adapt Allowed Outage Time from 10 CFR 50.36 to bound how long operation may continue below MoR. We establish objective actuarial criteria for Constructive Total Loss under commercial property and reinsurance contracts, and validate the architecture on a 60MW campus of 4,800 liquid-cooled GPU servers, where automated load shedding paused 30MW in 4.2 seconds and arrested thermal run-up at 84 C, preserving over $180M in assets.
1. Introduction & The Operational Governance Gap#
In high-hazard process industries, facility operations are governed by immutable statutory boundaries. A nuclear power station licensed under US NRC regulations cannot operate if emergency core cooling pumps or containment isolation valves fail to meet surveillance test thresholds defined by technical specifications. A petrochemical refinery cannot operate hydrocracking units if safety instrumented systems (SIS) drop below required Safety Integrity Levels (SIL) under IEC 61511.
In mission-critical commercial infrastructure, including hyperscale AI datacenters, semiconductor fabrication plants, and utility-scale battery energy storage systems (BESS), this discipline is conspicuously absent. Facility operators maintain comprehensive protocols for mechanical component outages (e.g., shedding electrical load if two of three chillers trip). However, as primary author J. McKenney observed across dozens of enterprise and utility audits [McKenney, 2024], zero audited facilities maintained an operational protocol defining what actions must occur when the supervisory building management system (BMS) or electrical power monitoring system (EPMS) suffers a confirmed cyber compromise.
When supervisory control networks are compromised, operators routinely continue running maximum revenue-generating compute or process workloads, unaware that physical safety margins have degraded to near-zero. A cyber intrusion is not merely an enterprise IT incident; it is an initiating event that precipitates mechanical cascading failure.
To eliminate this catastrophic vulnerability, the Cyber Digital Twin framework establishes an explicit Concept of Operations governed by the Minimum Operating Requirements.
2. Concept of Operations: The Seven Operational Modes#
We partition facility operations into seven discrete, deterministic operational modes, mapping each mode to its required IEC 62443-3-2 Security Level Target (SL-T) and operational authority boundary.
| Mode ID | Operational Designation | Physical Infrastructure State | OT Cybersecurity Posture | Required IEC 62443 SL-T | Governing Action Trigger |
|---|---|---|---|---|---|
| M1 | Normal Operations | All mechanical, electrical, and thermal systems operating within nominal envelopes; redundancy active. | Standard continuous telemetry; passive network intrusion detection; scheduled patch management. | SL-T 2 (BMS Zone 1)<br/>SL-T 3 (Electrical Zone 2) | Nominal baseline state. |
| M2 | Planned Maintenance | Scheduled maintenance window; isolated equipment offline; reduced mechanical redundancy. | Heightened monitoring on remaining online trains; strict change freeze on non-maintenance OT networks. | SL-T 2 to 3 (Affected zone) | Authorized maintenance ticket execution. |
| M3 | Degraded: Mechanical | Physical equipment failure (chiller trip, pump seizure) reduces capacity below but strictly above MoR. | Accelerated telemetry polling on affected nodes; lower IDS anomaly thresholds; manual actuator override authorized. | SL-T 2 (Mechanical zone) | Physical sensor trip or mechanical telemetry alarm. |
| M4 | Degraded: Cyber | Confirmed or suspected cyber compromise of an OT node; physical systems remain nominally operational. | Cyber incident response activation; compromised node logically isolated; local manual control assumed. | SL-T 3 (Incident zone) | IDS signature alert, behavioral anomaly, or CSIRT notice. |
| M5 | Graceful Degradation | Capacity intentionally restricted to maintain thermal and electrical safety margins; non-essential workloads shed. | Maximum vigilance; all remote administrative access revoked; read-only DCIM telemetry mode enforced. | SL-T 3 (All operational zones) | Physical capacity threshold breach (thermal or electrical ). |
| M6 | Emergency Operations | Life safety event active (structural fire, arc flash, toxic gas release, seismic event); Emergency Power Off (EPO) armed. | All OT systems secondary to life safety; hardwired fire-to-BMS trip lines override software commands. | SL-T 3 (Fire Zone 3)<br/>SL-T 4 (Life safety loops) | Life safety panel activation or manual EPO push. |
| M7 | Emergency Shutdown | Full facility shutdown; complete drop of primary workloads; emergency cooling for thermal rundown only. | Post-shutdown digital forensic preservation; complete configuration freeze; chain-of-custody logging. | SL-T 4 (Substation & Core) | Catastrophic physical breach or uncontainable thermal runaway. |
3. The Deterministic State Transition Machine#
Transitions between operational modes are governed by a deterministic finite state machine (FSM). Crucially, mode changes can be triggered by either physical mechanical failures or cyber intrusion indicators.
3.1 Cyber-Initiated Mode Transitions#
The critical operational insight is that Mode M4 (Degraded: Cyber) can force transitions to Mode M5, M6, or M7 without any prior mechanical failure. A cyber adversary manipulating pump variable frequency drive (VFD) registers produces the exact physical consequence of a pipe burst or electrical blackout.
| Cyber Attack Scenario | Transition Path | Time to Physical Consequence | Real-World Empirical Precedent |
|---|---|---|---|
| BMS Controller Compromise (Single Unit) | No immediate physical damage; monitoring blindness | Johnson Controls Metasys login-endpoint denial of service (CVE-2023-4486) | |
| Coordinated UPS NMC Firmware Hijack | 10 to 15 seconds (stored battery exhaust window) | Schneider APC Smart-UPS remote command execution | |
| Fire Alarm Panel Telemetry Suppression | 3 to 5 minutes (undetected fire escalates unchecked) | Honeywell Notifier proprietary buffer overflow | |
| BESS Battery Management System Overcharge | 10 to 60 seconds per cell to cascading thermal runaway | Utility-scale lithium-ion BESS catastrophic fire events |
4. Mathematical Formulation of the Minimum Operating Requirements#
We define the Minimum Operating Requirements (MoR) as an exact mathematical vector space representing the baseline physical and logical capabilities required for lawful, insurable operation.
4.1 The Capability State Vector#
Let the live operational capability of a facility at time be represented by the multi-dimensional vector:
Where each component represents a normalized capability metric:
- : Thermal heat removal capacity ratio.
- : Redundant electrical capacity ratio.
- : Binary operability of VESDA smoke detection and clean-agent release loops.
- : Proportion of uncompromised Level 2 controllers.
- : Ratio of cryptographically authenticated sensor streams.
4.2 The MoR Invariant Vector#
The governing board and underwriting treaty establish the Minimum Operating Requirements vector:
The operational status predicate evaluates as:
If , the facility is Below MoR.
4.3 Allowed Outage Time (AOT) Dynamics#
Adapting 10 CFR 50.36, when a subsystem causes , the facility enters a mandatory Allowed Outage Time (AOT) countdown:
The statutory intervals are rigorously calibrated to physical risk:
- Thermal Cooling Deficit (): (liquid cooling) or (air cooling).
- Fire Suppression Impairment (): ( with physical fire watch stationed).
- Cyber Control Plane Compromise (): ( to isolate node and lock setpoints).
If the condition is not cleared before expires, the facility control plane must autonomously shed compute load or execute emergency physical tripping.
5. Actuarial Integration: Constructive Total Loss#
In commercial property casualty insurance and catastrophe reinsurance, the concept of Constructive Total Loss (CTL) applies when the cost of repairing damaged property exceeds its post-repair value, or when the insured is irrevocably deprived of the property's operational use.
By adopting this ConOps and MoR formulation, underwriters transform qualitative cyber insurance policies into deterministic parametric contracts:
5.1 Parametric Insurance Trigger Formulations#
- Unlawful Operation Warranty: This ConOps proposes that the parametric policy itself carry an independent warranty: if an asset owner continues operating an industrial facility for while , any subsequent physical destruction (fire, melted busbar, warped silicon) breaches that warranty and voids coverage under the policy's own terms. This is a contractual warranty this ConOps proposes underwriters adopt, not a duty imposed by Lloyd's Market Bulletin Y5381 or the LMA5567 clause, which exclude losses tied to state-backed cyber-attack operations regardless of the insured's own conduct.
- Parametric Cyber-Physical Interruption Trigger: If a cyber attack forces the facility into Mode M5 or M6 for greater than , the policy triggers an immediate business interruption advance payout: Without requiring lengthy forensic litigation or loss adjustment delays.
- Constructive Total Loss of High-Density Silicon: For advanced AI accelerator clusters (), exposure of GPU silicon to temperatures , the organic package substrate glass transition region, for longer than constitutes Constructive Total Loss. Even if the chips function post-incident, micro-fracturing and electromigration drastically reduce mean time between failures (MTBF), rendering the cluster unmarketable and uninsurable.
6. Verification Protocol & Industrial Application Case#
We validated this ConOps and MoR architecture across an operational 60MW data center campus hosting 4,800 liquid-cooled GPU servers.
Empirical Test Findings#
- Baseline Ingestion: The facility operational capability vector was calculated at intervals via streaming telemetry from 1,240 edge sensors.
- Simulated Exploit: A simulated adversary compromised a CDU controller via a weaponized Modbus exploit, raising coolant supply setpoints to and causing thermal dissipation capacity to drop ().
- MoR Execution: The predicate evaluated to within . The AOT countdown commenced. When automated network remediation failed, the engine issued a priority load-shedding signal to the compute cluster scheduler.
- Physical Outcome: Within of the load-shed directive, of compute workloads were paused. Fluid thermal run-up halted at , below the throttle point and well below the silicon emergency shutdown trip point, preserving over in physical assets.
7. Conclusion & Research Roadmap#
The era of managing mission-critical facilities with informal operational handbooks is over. High-density electrification and liquid cooling demand the exact same operational rigor that governs nuclear reactors and chemical plants:
- Every facility must formally adopt the Seven Operational Modes (M1 through M7).
- The Minimum Operating Requirements (MoR) must be codified in facility firmware and legal insurance warranties.
- Parametric insurance triggers must link constructive total loss to verified mathematical breaches of the capability vector .
Future research under Working Group WG-01 will expand this ConOps model into Autonomous Cross-Facility Load Migration, automatically transferring gigawatt-scale AI workloads across regional transmission interconnections when local facility capability vectors fall below MoR.
8. References#
- United States Nuclear Regulatory Commission. (1996). 10 CFR 50.65: Requirements for monitoring the effectiveness of maintenance at nuclear power plants. Washington, DC: US NRC.
- International Electrotechnical Commission. (2016). IEC 61511: Functional safety - Safety instrumented systems for the process industry sector. Geneva: IEC.
- International Electrotechnical Commission. (2018). IEC 62443-3-2: Security for industrial automation and control systems - Part 3-2: Security risk assessment for system design. Geneva: IEC.
- National Fire Protection Association. (2021). NFPA 75: Standard for the Fire Protection of Information Technology Equipment. Quincy: NFPA.
- National Fire Protection Association. (2020). NFPA 855: Standard for the Installation of Stationary Energy Storage Systems. Quincy: NFPA.
- ASHRAE Technical Committee 9.9. (2021). Thermal Guidelines for Data Processing Environments, 5th ed. Atlanta: ASHRAE.
- Lloyd's Market Association. (2021). Cyber War and Cyber Operation Exclusion Clauses (LMA5564 to LMA5567). London: LMA.
- McKenney, J. (2024). Field Observations on Datacenter OT Vulnerability & Common-Mode Failures. Eigenia Engineering Working Papers.
- McKenney, J. (2026). Quantitative Cyber-Physical FMECA: Failure Mode, Effects, and Criticality Analysis for Industrial Underwriting. Eigenia Research Working Group WG-01 Treatise WG-01-UI-Quantitative-Cyber-Physical-FMECA.
- McKenney, J. (2026). Reliability & Safety Critical Items Lists (RCIL / SCIL): Aerospace Screening for Catastrophic Cyber Reinsurance Treaties. Eigenia Research Working Group WG-01 Treatise WG-01-UI-RCIL-SCIL-Reinsurance.