CyHAZOP: Cyber-Physical Hazard Analysis for Hyperscale Infrastructure
J. McKenney
This paper is a standalone treatise in the WG-07 Threat Modeling and TACAM Matrix working group rather than an entry in a numbered series. It establishes the CyHAZOP methodology that the working group's CyHAZOP Node Registers paper, a confirmed working-group sibling, applies node by node.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Oil refining, nuclear power, and rail have long run a formal process to find physical hazards before a facility is built: a Hazard and Operability study, which asks what happens when a pressure, flow, or temperature departs from its design value. Data centres and large AI computing facilities have not applied that discipline to their own equipment, treating cybersecurity as an IT-only concern, though these facilities are full of networked controllers, pumps, and cooling systems whose failure is a physical event, not only a digital one.
This paper adapts that process to cyber-physical failures directly. It links a facility's physical engineering drawings to the same component lists cybersecurity teams keep for software, firmware, and hardware. That link lets one analysis trace how a cyberattack on a specific controller propagates into a specific physical failure, such as a cooling malfunction or an electrical fault.
Applied to four critical systems in a large compute facility, the method works out how a cyberattack translates into a physical outcome, what hardwired safeguards prevent the worst results whatever the software does, and how insurers and regulators can reason about financial exposure and required safety controls.
Abstract#
In petrochemical refineries, nuclear power plants, and rail networks, engineers never commission physical infrastructure without a formal Hazard and Operability (HAZOP) study under IEC 61882 and the EN 50126 RAMS lifecycle, applying guide words (NO, LESS, MORE, REVERSE, AS WELL AS, PART OF, OTHER THAN) to find how deviations in pressure, flow, temperature, and voltage induce physical catastrophe. Hyperscale data centers and megawatt AI facilities have treated cybersecurity as an IT perimeter discipline divorced from process safety, though they deploy hundreds of networked PLCs, VFDs, coolant distribution units (CDUs), and automatic transfer switches (ATS) across 400V power trains and liquid cooling loops. A compromised cooling controller commands the same physical failure as a sheared pump shaft, but across redundant nodes at once within sub-second timescales. This paper formalizes CyHAZOP: the extension of IEC 61882 hazard analysis to cyber-physical operational technology. By linking DEXPI 2.0 piping schematics, classed against ISO 15926-4, to CycloneDX 1.6+ multi-BOM catalogs (HBOM, SBOM, CBOM, OBOM), it bridges digital exploits and physical damage. We analyze four nodes: the CDU Secondary Liquid Cooling Loop, Distributed Block UPS Power Train, BMS Supervisory Bus, and Out-of-Band BMC Fabric; formulate the transfer functions mapping cyber command injections to thermodynamic and hydraulic excursions; model Safety Instrumented System (SIS) probability of failure on demand under cyber stress; and present actuarial loss formulations for Probable Maximum Loss (PML) and the war and state-backed cyber-attack exclusions Lloyd's Market Bulletin Y5381 requires.
1. The Methodological Void in Megawatt Compute Facilities#
Forty years of industrial safety practice rest on a premise that networked control planes break: that a hazard reached only through a physical failure path can be engineered out mechanically. Once a control plane carries traffic, an attacker reaches the same hazard without touching the mechanism. High-reliability mechanical engineering remains necessary and stops being sufficient. That is the gap this paper addresses, and it is an engineering argument from the structure of the failure paths, not a claim about a measured accident record.
1.1 The Practitioner's Field Observation#
In industrial automation assessments conducted across rail corridors, water treatment plants, and data centers on four continents, a consistent engineering vulnerability emerges. Mechanical engineers design extreme hardware redundancy: N+1 or 2N centrifugal pumps, plate heat exchangers, chilled water loops, and dual-infeed power feeds. However, the supervisory control network orchestrating these redundant mechanical elements shares a common Ethernet switch fabric, unauthenticated Modbus TCP protocols, identical PLC firmware revisions, and shared vendor administrative credentials.
Logical common-cause failure defeats mechanical physical redundancy.
During an operational technology assessment of a 40 MW high-density colocation facility, the engineering team applied the guide word OTHER THAN to the Building Management System (BMS) to fire suppression interface. The controls engineer confirmed that the facility BMS issued a pre-action hold command to the clean-agent gas suppression panel via an unauthenticated BACnet/IP write command across the local facility subnet. When asked what physical safeguard prevented an adversary from injecting a forged release command, the room fell silent.
The fire safety vendor assumed the BMS network was isolated and trustworthy. The BMS integrator assumed the fire suppression system performed independent physical interlock verification. Neither assumption was tested. A single network command could trigger full Emergency Power Off (EPO), discharging gaseous suppression agents, corrupting storage arrays, and inducing 48 to 72 hours of total facility downtime with direct financial losses exceeding 2,500,000 USD. The physical remediation; a hardwired electrical dry-contact interlock bypassing the software bus; required less than 15,000 USD in copper wiring.
1.2 Traditional HAZOP versus CyHAZOP#
Standard HAZOP under IEC 61882 considers three root-cause categories: mechanical component failure, electrical power loss, and human operator error. In modern hyper-dense AI facilities, we must integrate a mandatory fourth root-cause category: cyber-induced operational deviation.
A cyber-induced deviation is the deliberate or accidental manipulation of a sensor value, setpoint register, actuator state, or firmware parameter across a digital communication conduit. Cyber-induced deviations exhibit four characteristics that make them far more destructive than mechanical failures:
- Non-Random Simultaneity: Mechanical failures occur as stochastic Poisson processes distributed across independent operating hours. Cyber attacks execute coordinated, multi-node manipulations simultaneously, defeating parallel N+1 redundancies in a single execution step.
- Telemetry Spoofing (Silent Drift): While mechanical failures trigger physical alarms on monitoring screens, a cyber exploit can spoof sensor telemetry registers (such as transmitting nominal temperature reports while throttling flow valves), blinding operators until physical damage occurs.
- Speed of Propagation: Network commands propagate at line rate across Ethernet conduits (sub-millisecond latency), vastly outpacing manual human operator reaction times or facility shift inspection rounds.
- Geographic Distribution: A single remote access vulnerability or compromised firmware update server allows an adversary to execute simultaneous physical sabotage across multiple campuses worldwide.
There is a second hazard analysis in this programme covering the same facilities, and I want the division of labor stated rather than left to be discovered. The Underwriting working group's Quantitative Cyber-Physical FMECA extends IEC 60812 instead of IEC 61882, and it runs bottom-up: it takes one component at a time, scores severity, occurrence and detection, and produces a risk priority number that can be sorted, which is what a capital budget needs. This paper runs top-down from a node and a guide word, and it finds the deviations that arise from combinations no single component failure produces, which a component-by-component study structurally cannot reach. Use CyHAZOP to find what can go wrong across a node, and the FMECA register to decide which component gets the money first.
2. Integrating DEXPI 2.0 and CycloneDX Multi-BOM into CyHAZOP#
Traditional HAZOP fails in computing environments because engineers lack a unified data structure connecting physical piping to digital silicon. CyHAZOP resolves this by binding DEXPI 2.0 plant piping models, whose equipment classes come from ISO 15926-4, with CycloneDX 1.6+ multi-BOM catalogs:
CyHAZOP unified asset delineation
| Layer | Element | Content bound into the unified model |
|---|---|---|
| DEXPI 2.0 P&ID (ISO 15926-4) | Heat Exchanger HEX-201, Pump P-101, Manifolds | ISO 15926-4 fluid property classes: PG25 coolant, volumetric flow rate, bar |
| CycloneDX 1.6+ | HBOM | OCP ORV3 trays, Samtec connectors, ASIC silicon dies |
| SBOM | Caliptra Silicon RoT, OpenSIL initializers, Linux kernels | |
| CBOM | DICE cryptographic certificates, post-quantum ML-DSA keys | |
| OBOM | Operational limits, voltage setpoints, line-rate egress caps | |
| VEX | Real-time Vulnerability Exploitability eXchange feeds |
By cross-referencing CycloneDX VEX vulnerability feeds with DEXPI mechanical equipment tags, CyHAZOP teams immediately determine whether a newly disclosed CVE in an operational technology controller can induce a physical hydraulic cavitation or electrical arc flash hazard.
3. The Standardized CyHAZOP Workflow#
The CyHAZOP study is executed by a multidisciplinary team; mechanical process engineers, electrical systems leads, industrial control engineers, and cybersecurity assurance architects; through a 15-step structured lifecycle governed by the EN 50126 V-model. The fifteen steps sit in four phases of three, four, four and four; the table below numbers every one of them:
CyHAZOP lifecycle phases
| Phase | Step | Activity |
|---|---|---|
| Phase 1: System Definition & Node Delineation | 1 | Ingest P&ID Schematics (DEXPI 2.0) & Single-Line Electrical Diagrams |
| 2 | Partition System into Physical Nodes (Process Fluid / Power Infeed) | |
| 3 | Define Exact Design Intent & Quantitative Operational Envelopes | |
| Phase 2: Parameter & Guide Word Matrix Execution | 4 | Select Node Parameter (Flow, Temp, Pressure, Voltage, Frequency) |
| 5 | Apply Guide Word (NO, LESS, MORE, REVERSE, AS WELL AS, OTHER THAN) | |
| 6 | Identify Mechanical & Electrical Root Causes | |
| 7 | Identify Cyber-Induced Conduits, Protocols, & Attack Vectors | |
| Phase 3: Consequence & Safeguard Evaluation | 8 | Model Physical Consequence (Thermodynamics, Heat Flux, Cavitation) |
| 9 | Identify Existing Protective Safeguards (Alarms, BMCs, Trips) | |
| 10 | Evaluate Safeguard Integrity under Cyber Stress (Common-Mode Fail) | |
| 11 | Assign Quantitative Hazard Severity Index (Catastrophic / Critical) | |
| Phase 4: Remediation, SIS Hardening & Verification | 12 | Specify Safety Instrumented Systems (Hardwired Interlocks, SIL) |
| 13 | Map Conduits to IEC 62443 Security Level Targets (SL-T 1 to SL-T 4) | |
| 14 | Establish Physical Verification & Proof Testing Intervals | |
| 15 | Generate Formal CyHAZOP Ledger for Underwriting & Regulatory Proof |
3.1 The Guide Word Lexicon#
In CyHAZOP, the classical IEC 61882 guide words are mapped directly to physical parameters and cyber command primitives:
| Guide Word | Physical Deviation Meaning | Cyber-Physical Attack Mechanism |
|---|---|---|
| NO / NONE | Complete cessation of flow, voltage, or telemetry signal. | Command injection: pump stop, breaker trip, interface shutdown, power cutoff. |
| MORE | Quantitative elevation of pressure, temperature, speed, or voltage. | Register manipulation: VFD overspeed, chiller setpoint inflation, voltage spike. |
| LESS | Quantitative reduction of flow, pressure, cooling, or power capacity. | Flow throttling: valve restriction to 15%, fan speed reduction, power capping. |
| REVERSE | Flow or current opposite to designed physical direction. | Phase inversion on VFD, bi-directional power flow injection from BESS. |
| AS WELL AS | Introduction of foreign elements, contaminants, or harmonic noise. | Sensor packet injection, dirty power harmonics, disabling water treatment. |
| PART OF | Incomplete execution of an essential multi-step safety sequence. | Suppressing interlock verification during bus transfer, partial shutdown. |
| OTHER THAN | Unintended operation, incorrect destination, or spoofed status report. | Telemetry deception: reporting nominal temperature while physical fire burns. |
4. Node Analysis: Four Critical Hyperscale Nodes#
To demonstrate the rigorous application of CyHAZOP, we present detailed analysis tables for four essential nodes of a 100 MW high-density AI campus.
4.1 Node 1#
Secondary Cooling Loop (CDU to GPU Cold Plates)
- Design Intent: Deliver treated 25 percent propylene glycol (PG25) coolant at to 8x AI accelerator cold plates at per tray, a 15 K coolant temperature rise, maintaining silicon junction temperatures under compute dissipation.
- Node Boundary: CDU secondary heat exchanger discharge nozzle distribution manifold flexible stainless steel braided hose quick-disconnect dry-break couplings microchannel cold plates return manifold CDU suction inlet.
Node 1: Secondary Cooling Loop CyHAZOP Matrix#
| Guide Word | Parameter | Deviation | Physical Consequence | Cyber Attack Vector | Severity | Recommended Safeguard |
|---|---|---|---|---|---|---|
| NO | Flow | Complete loss of coolant flow (). | Convective dissipation collapses. Silicon junction surges at , reaching at . Emergency hardware shutdown of the tray. | Modbus TCP function code 05/06 injected to PLC register 40012, asserting pump emergency stop. | Catastrophic | Hardwired pneumatic pressure relief and independent bi-metallic thermal interlock cutting server power. |
| LESS | Flow | Throttled coolant flow (). | Fluid velocity drops below critical Reynolds number (). Heat transfer coefficient drops . Accelerators throttle inference . | Attacker overwrites VFD speed reference register from to via unauthenticated BACnet conduit. | Major | Cryptographically authenticated VFD command signing (IEC 62443-4-2 SL-3) and minimum speed hardware jumper. |
| MORE | Temperature | Supply coolant exceeds . | Loss of thermal logarithmic mean temperature difference (). Chiller compressor stalls. Rack thermal trip engaged within 180 seconds. | Attacker tampers with primary plate heat exchanger proportional valve setpoint via BMS Redfish API. | Major | Out-of-band analog thermocouple loop bypassing the IP network, wired directly to chiller local control. |
| OTHER THAN | Telemetry | Frozen nominal temperature () while true temperature rises. | Facility operators receive nominal dashboards while silicon cooks. Hardware safety trips disabled by spoofed BMC registers. | Man-in-the-middle ARP spoofing injecting forged Modbus telemetry packets into supervisory SCADA server. | Catastrophic | Cryptographic payload attestation (DICE/Caliptra) on sensor telemetry nodes and independent analog gauge audits. |
4.2 Node 2#
400V/48V Distributed Block UPS Power Train
- Design Intent: Continuous delivery of clean, three-phase 480V/400V AC power through a 4-to-3 Catcher UPS topology to rack-mounted busbars, stepping down to 48V DC via high-efficiency rectifiers, sustaining per rack without voltage sag or harmonic distortion ( THD).
- Node Boundary: 11 kV switchgear output unit substation step-down transformer Static Transfer Switch (STS) distributed block UPS modules (1.25 MW each) power distribution unit (PDU) busway tap-off boxes.
Node 2: Power Distribution CyHAZOP Matrix#
| Guide Word | Parameter | Deviation | Physical Consequence | Cyber Attack Vector | Severity | Recommended Safeguard |
|---|---|---|---|---|---|---|
| NO | Voltage | Instantaneous bus drop to . | Uncontrolled server drop. Data loss in DRAM buffers, corrupted database state, storage array crash. | Remote exploitation of SNMP/web interface on LayerZero STS, commanding force-open on both feeds. | Catastrophic | Hardwired mechanical interlock preventing simultaneous open commands; disable remote firmware updates on STS. |
| MORE | Frequency | AC frequency surge to . | Core saturation in facility transformers, overheating magnetics, harmonic resonance causing capacitor bank explosion. | Tampering with inverter DSP control firmware via compromised JTAG or optical maintenance port. | Catastrophic | Hardware-calibrated over-frequency protection relay (IEC 61850 SIPROTEC) tripping within . |
| AS WELL AS | Harmonics | Severe harmonic distortion (). | Neutral conductor overheating, eddy current losses, erratic tripping of downstream electronic circuit breakers. | Modulating load patterns via synchronized GPU kernel execution, matching the resonant frequency of power filters. | Major | Active power factor correction filters with autonomous analog feedback, isolated from host OS control. |
| PART OF | Synchronization | Out-of-phase transfer across asynchronous utility feeds. | Massive mechanical torque shock across generator shafts, high-voltage flashover, catastrophic switchgear destruction. | Spoofing synchrocheck relay voltage phase angle telemetry via IEC 61850 GOOSE network manipulation. | Catastrophic | Hardwired analog synchrocheck relay with optical isolation, mechanically blocking out-of-phase closure. |
4.3 Node 3#
BMS Supervisory Control Plane & Fire Suppression
- Design Intent: Centralized monitoring of environmental parameters, ventilation louvers, smoke detection sensors, and life-safety systems, maintaining positive room air pressure and executing orderly zoning during emergency events.
- Node Boundary: BMS BACnet/IP Ethernet backbone field programmable controllers (JCI, Schneider, Honeywell) pre-action sprinkler valves, clean-agent (NOVEC 1230 / Inergen) release solenoids, smoke purge dampers.
Node 3: BMS and Life Safety CyHAZOP Matrix#
| Guide Word | Parameter | Deviation | Physical Consequence | Cyber Attack Vector | Severity | Recommended Safeguard |
|---|---|---|---|---|---|---|
| OTHER THAN | State | False gas discharge into populated data hall. | Full Emergency Power Off (EPO) tripped. High-pressure acoustic shock from discharge nozzles shatters spinning hard drives. | Exploiting CVE in BMS supervisory server (such as default BACnet broadcast credentials) to force solenoid trigger. | Catastrophic | Dual-custody, hardwired cross-zoned optical smoke and ionization detection requiring manual physical abort switch. |
| NO | Ventilation | Total shutdown of data hall air economizers. | Heat accumulation in upper rack exhaust zones. Ambient hall temperature rises to , degrading power supplies. | Ransomware encrypts BMS central controller, forcing all damper actuators into fail-closed default state. | Major | Spring-return mechanical damper actuators that fail open on loss of signal; dedicated local thermostat loops. |
4.4 Node 4#
Out-of-Band Baseboard Management Controller (BMC) Fabric
- Design Intent: Dedicated out-of-band management network providing Redfish REST telemetry, KVM over IP, firmware flashing, and hardware power cycling for all compute blades without interfering with production traffic.
- Node Boundary: Dedicated 1 GbE management switch fabric ASPEED AST2600 BMC chip PCIe sideband (MCTP over SMBus) host processor power rail and voltage regulators.
Node 4: Out-of-Band BMC CyHAZOP Matrix#
| Guide Word | Parameter | Deviation | Physical Consequence | Cyber Attack Vector | Severity | Recommended Safeguard |
|---|---|---|---|---|---|---|
| MORE | Voltage | Over-voltage command injected to VRM (). | Electrical overstress across silicon gate oxides. Instantaneous hardware destruction across 8x accelerator packages. | Exploiting unauthenticated BMC Redfish endpoint to flash modified OpenBMC kernel that disables I2C VRM limits. | Catastrophic | Hardware voltage clamping circuit (crowbar diode) on compute tray motherboard that shunts over-voltage to ground. |
| NO | Boot | Permanent bricking of host firmware (Denial of Service). | Entire compute tray rendered non-bootable. Physical board replacement or desoldering required; weeks of downtime. | Attacker transmits corrupted SPI flash image via BMC web interface without cryptographically validating RoT. | Catastrophic | Dual-flash Caliptra 2.0 Silicon Root of Trust enforcing recovery from immutable golden image on SPI failure. |
5. Quantitative Physics: The Cyber-Physical Transfer Function#
To move beyond qualitative hazard checklists, CyHAZOP formalizes the exact physical response of an infrastructure node to digital command manipulation.
5.1 Cyber-Physical Jacobian Transfer Function#
When an adversary manipulates a vector of cyber control variables (such as valve positions, pump rotational speeds, or inverter setpoints), the deviation in physical state variables (such as fluid pressure, flow rate, temperature, or voltage) is governed by the system Jacobian matrix :
Where is the network transmission and parsing matrix, accounting for protocol delays, register quantization, and controller execution loop latency.
5.2 Silicon Junction Critical Runaway Formulation ()#
When coolant flow is arrested (guide word NO FLOW), the transient temperature rise of the accelerator silicon die is governed by lumped thermal capacitance, convective fluid flow, and internal heat flux:
The time available before the emergency hardware shutdown trip ( at ) is formulated as:
Where:
- is the thermal time constant of the stagnant cold plate assembly, . It is long because a stagnant cold plate rejects almost no heat; the trip arrives at 14.8 seconds because the facility is still on the near-linear opening of that ramp.
- is the continuous compute dissipation per accelerator package (), the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU.
- is the package-to-coolant thermal resistance under stagnation, .
- For nominal starting conditions (, ), .
Any protective control that relies on manual operator intervention (which requires minutes to hours) is guaranteed to fail. Protection must be executed via autonomous, hardware-interlocked safety instrumented loops.
5.3 Darcy-Weisbach Hydraulic Manifold Head Loss Spike#
When an adversary transmits Modbus function code 06 to throttle proportional valve V-102 from open to open, the resulting hydraulic head loss across the distribution manifold is formulated as:
Where exhibits non-linear exponential growth as valve angle . Head loss surges from to , exceeding pump deadhead pressure and inducing catastrophic cavitation.
5.4 Safety Instrumented System (SIS) Probability of Failure on Demand under Cyber Stress#
Under IEC 61508 and IEC 61511, the average Probability of Failure on Demand () for a Safety Instrumented Function (SIF) is traditionally calculated solely from mechanical and electrical dangerous undetected failure rates ().
In a networked environment subject to active adversary targeting, the effective failure probability must incorporate the cyber attack compromise rate :
Where:
- is the periodic physical proof test interval (typically 8,760 hours / 1 year).
- is the unpatched vulnerability window (time between CVE publication and patch application).
- is the adversary encounter frequency targeting the facility OT protocol.
- is the effectiveness factor of security control (zone firewalls, cryptographic signing, mutual TLS).
When controllers share an unauthenticated protocol (such as Modbus TCP with ), increases by three orders of magnitude, collapsing an intended SIL-2 or SIL-3 safety loop down to an ineffective SIL-0 state.
5.5 Actuarial Consequence & Risk Matrix Prioritization#
The quantitative CyHAZOP Risk Priority Index for a specific node deviation triggered by threat actor is formulated as:
Where:
- is the modeled likelihood of achieving the unauthorized setpoint override, assigned by the study team from the conduit's exposure, the authentication in front of it and the threat actor's assessed capability. It is an input to the index, not a rate observed at this facility.
- is the direct equipment replacement cost.
- is the unserved SLA penalty rate per hour.
- is the physical recovery time governed by long-lead supply chain components.
- is the Annualized Rate of Occurrence, and is the Annualized Loss Expectancy.
5.6 Return on Security Investment (ROSI) for Hardwired Safety Instrumented Loops#
The financial justification for retrofitting hardwired physical interlocks to prevent cyber-induced facility trips is quantified through Return on Security Investment:
Where replacing software BACnet trips with hardwired dry-contact interlocks () reduces unmitigated catastrophe loss expectancy from to , the modeled exceeds 12,000 percent.
The size of that ratio is a property of the inputs, not evidence for them. A 15,000 USD interlock sits in the denominator, so any large loss reduction divided by it returns a number in the thousands of percent. The working group set all three figures: the interlock cost from vendor list prices for dry-contact relays and wiring, the 1,850,000 USD unmitigated ALE from the node's own consequence model, and the 22,000 USD residual from the assumption that a hardwired trip removes all but the nuisance cases. None is a measured loss. The honest reading is narrow and still useful: for hazards where a mechanical interlock genuinely removes the consequence, the interlock is cheap relative to what it prevents. Do not carry the percentage itself into a board paper.
6. Industrial Proof#
Case Studies of Physical-Digital Sabotage
The failure scenarios modeled in CyHAZOP are not theoretical possibilities; they reflect documented exploitation mechanics observed in real-world critical infrastructure:
6.1 Johnson Controls Metasys BMS Incident (September 2023)#
A major enterprise facility management provider suffered a catastrophic ransomware breach that penetrated supervisory building management controllers. The attack demonstrated that facility operational networks are directly accessible from enterprise domains. Had the adversaries chosen kinetic sabotage over encryption, the compromised controllers held write access to chilled water bypass valves and exhaust fans across hundreds of mission-critical customer installations.
6.2 TLStorm#
Cloud-Connected UPS Firmware (CVE-2022-22805 / CVE-2022-22806)
Security researchers demonstrated that Schneider Electric APC Smart-UPS units featuring cloud connectivity could be remotely updated with unsigned, malicious firmware. The exploit bypassed all software boundaries, allowing attackers to manipulate internal inverter pulse-width modulation setpoints. This induced extreme physical thermal overstress, melting internal battery enclosures and creating direct electrical fire hazards without triggering upstream utility breakers.
6.3 Stuxnet#
The Archetype of Physical Resonance Manipulation
The physical destruction of uranium centrifuges at Natanz demonstrated the quintessential CyHAZOP deviation: guide word MORE applied to VFD frequency, alternating between , nominal , and . The attack deliberately excited the mechanical harmonic resonance frequencies of the rotor shafts while spoofing nominal telemetry back to supervisory SCADA monitors, causing physical rotor disintegration.
7. Systems Assurance#
Integrating CyHAZOP with IEC 62443 & Caliptra RoT
To translate CyHAZOP findings into engineering defenses, each identified hazard is mapped directly to the IEC 62443 industrial cybersecurity standard and modern open silicon roots of trust.
7.1 Zone and Conduit Partitioning (IEC 62443-3-2)#
CyHAZOP gives an engineering justification for where the zone boundaries fall. Each boundary below is drawn where a deviation stops propagating, which is a judgment made from the node's physics and its conduits rather than a measurement:
- Zone 0 (Physical Silicon & Process): Chiplet die, microchannel cold plate, liquid manifold. Security Level Target: SL-T 4. Enforces Caliptra 2.0 Silicon Root of Trust, immutable boot ROM, DICE certificate provenance, and hardwired physical overrides.
- Zone 1 (Field Control & VFDs): Pump controllers, local valve actuators, power metering chips. Security Level Target: SL-T 3. Enforces cryptographically signed commands and encrypted RS-485 conduits.
- Zone 2 (Supervisory Facility OT): Coolant Distribution Unit PLC, Block UPS supervisory controller, chiller master panel. Security Level Target: SL-T 3. Enforces strict network isolation via unidirectional data diodes and OpenSIL firmware whose signature is checked at every boot against the vendor's enrolled key.
- Zone 3 (Enterprise Facility Network): Central BMS server, EPMS database, DCIM telemetry collectors. Security Level Target: SL-T 2. Enforces multifactor authentication, role-based access control, and machine-readable CycloneDX VEX monitoring.
IEC 62443 zone and conduit partitioning
| Zone | Security Level Target | Control asserted inside the zone |
|---|---|---|
| Zone 3: Enterprise BMS / DCIM Supervisory | SL-T 2 | CycloneDX VEX continuous vulnerability feeds |
| Zone 2: Facility OT / CDU Master PLCs / Switchgear Relays | SL-T 3 | OpenSIL attested firmware, immutable syslog conduits |
| Zone 1: Field Actuators / VFD Motor Controllers / Cold Plates | SL-T 3 | Hardwired proof-tested interlocks (SIL-3) |
| Zone 0: Physical Silicon / Heat Flux / Busbars | SL-T 4 | Caliptra 2.0 RoT, DICE identity, dual-flash gold recovery |
8. Actuarial and Reinsurance Treaty Implications: Catastrophe Risk & PML#
The application of CyHAZOP provides reinsurance syndicates and catastrophe modelers with the first mathematically defensible basis for underwriting cyber-physical infrastructure risk.
8.1 Lloyd's Y5381 Compliance & SFAIRP Defense#
Lloyd's Market Bulletin Y5381, issued by the Corporation of Lloyd's on 16 August 2022, requires that stand-alone cyber-attack policies written or renewed from 31 March 2023 exclude losses arising from war and from state-backed cyber attacks that significantly impair the ability of a state to function or that significantly impair the security capabilities of a state. The duty falls on managing agents, and the Lloyd's Market Association's model clauses LMA5564 to LMA5567 (November 2021) are the wordings drafted to meet it. What an underwriter still has to judge at placement is whether facility OT can be driven to unhedged business interruption, and a CyHAZOP ledger is what that judgment can be built from: it names every node, every deviation considered, every safeguard credited and every safeguard found wanting, so the underwriter reviews the reasoning instead of accepting the conclusion.
| Insurance Underwriting Dimension | Traditional Datacenter Underwriting | CyHAZOP-Audited Facility | Actuarial & Financial Benefit |
|---|---|---|---|
| Common-Cause Failures | Assumed independent based on N+1 pump or chiller counts. | Identifies shared PLC firmware and unauthenticated Modbus conduits across parallel loops. | Eliminates hidden systemic tail-risk; prevents correlated portfolio insolvency. |
| Probable Maximum Loss (PML) | Unconstrained subjective estimates exceeding 150,000,000 USD. | Bounded by hardwired safety interlocks whose trip times are measurable on site and by the physical isolation times those trips produce. | Probable Maximum Loss reduced by 35% to 50%; capital release for underwriters. |
| War and State-Backed Cyber-Attack Exclusion | Disputed claims during sovereign cyber warfare events; protracted litigation. | SIL-3 physical safety interlocks, proof-tested at the intervals set at step 14, contain the consequence regardless of attack origin because the trip path carries no network. | The exclusion stands whatever the ledger shows; what the interlocks bound is the loss the insured retains when it applies. |
| Legal Due Diligence (SFAIRP) | Vulnerable to gross negligence lawsuits following physical facility destruction. | Formal CyHAZOP ledger demonstrates risks were reduced So Far As Is Reasonably Practicable. | Absolute statutory and tort liability defense for executive leadership. |
| Deductible Optimization | Rigid, punitive deductibles ($15M to $50M) imposed on high-density facilities. | Parametric deductible schedules keyed to continuous CyHAZOP digital twin telemetry. | Working capital unlocked; premium credits up to 32% secured. |
The benefits column is modeled. The 35 percent to 50 percent reduction in probable maximum loss and the 32 percent premium credit are this working group's estimates of what a syndicate concedes once the hazard register removes the uncertainty it currently prices for. Neither figure comes from a placement, a slip or a treaty wording, and neither is a market rate. They describe the argument a facility can make, not terms anyone has been offered.
9. Summary of Engineering Principles#
The CyHAZOP methodology establishes five non-negotiable engineering principles for megawatt AI compute facilities:
- Logical Connectivity Governs Physical Safety: An air gap that does not exist in software does not exist in reality. Every networked control conduit is a potential physical valve failure.
- Systematic Guide Word Exploration: Safety cannot rely on subjective intuition; it demands the structured application of NO, LESS, MORE, REVERSE, and OTHER THAN across every operational node.
- Hardwired Independence (SIL-3): Never rely on software alone to protect against software failure. High-consequence hazards must be mitigated by hardwired, analog, or pneumatic physical interlocks.
- Sub-Second Physical Realities: Silicon thermal runaway executes in seconds; supervisory alarms and manual operator procedures take minutes. Safety instrumented responses must be autonomous and instantaneous.
- Actuarial Verifiability: Insurance underwriting and regulatory compliance must be anchored in deterministic physics formulations rather than qualitative self-attestation questionnaires.
10. References#
- International Electrotechnical Commission. (2001). IEC 61882: Hazard and operability studies (HAZOP studies) - Application guide. IEC.
- CENELEC. (1999). EN 50126: Railway applications - The specification and demonstration of reliability, availability, maintainability and safety (RAMS). CENELEC.
- NVIDIA Corporation. (n.d.). Datasheet for NVIDIA Blackwell Architecture. NVIDIA. Cited for the per-accelerator power figure in section 5.2.