CyHAZOP System Drill-Down: Node Registers for Power, Cooling, and Safety
J. McKenney
This paper is part of the WG-07-TM Threat Modeling body of work, taking the CyHAZOP methodology down to the level of individual industrial protocol registers. It sits alongside WG-07-TM-CyHAZOP-Methodology, which sets out the CyHAZOP guide-word methodology this paper applies, and WG-05-CAD-IEC62443-SFAIRP-SecRACS, which addresses the equivalent hazard register at a facility-wide programme level; where those papers work at the level of the method and the programme, this paper works at the level of the specific Modbus, BACnet and Redfish registers that carry a facility's physical hazards.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Hazard analysis usually stops at the diagram: a box for a cooling loop, an arrow for a power feed. In a high-density facility the real point of failure sits one level below, in the specific network commands that tell equipment what to do, because that command is where an attacker's software input becomes a physical action.
The paper works through four parts of a high-density compute facility, the liquid cooling loop, the electrical power train, the building management system, and the chip-level management hardware, documenting the registers and commands that control each. Most carry no built-in protection against forgery by an attacker who can reach the network.
It closes with what stops a forged command from becoming physical damage: hardware that checks and authenticates commands independently of the software that sends them, and mechanical or analog interlocks that act as a last line of defense when software cannot be trusted. It then examines what a facility holding this evidence should expect from its insurers.
Abstract#
While high-level hazard analyses set the conceptual frame for cyber-physical safety, real industrial sabotage executes at the register and byte level. In megawatt AI data centers and mission-critical plants, Variable Frequency Drives (VFDs), Coolant Distribution Units (CDUs), Static Transfer Switches (STS), and Baseboard Management Controllers (BMCs) expose their physical operating envelope across legacy operational technology (OT) protocols. Modbus TCP holding registers, BACnet/IP analog output objects, and Redfish JSON payloads govern motor speeds, valve positions, trip thresholds, and power capping. In over 95 percent of deployed facilities, these protocols lack cryptographic authentication, message integrity, or replay protection. An adversary with visibility on a supervisory VLAN can forge one unauthenticated Modbus write (Function Code 06 or 16) to alter a pump speed reference or bypass a safety interlock, and can spoof input registers on the same conduit to blind engineers until physical destruction occurs. This paper gives a register-level drill-down for the four primary CyHAZOP nodes: the Liquid Cooling Loop, the Electrical Power Train, the Building Management System, and the Silicon Management Plane. It documents the exact Modbus holding registers, BACnet object IDs, and Redfish REST endpoints that govern physical operation, and formulates the dynamics of register step-changes, quantization drift, and inductive kickback. It then sets the assurance requirements for hardware cryptographic bumps-in-the-wire, Caliptra Silicon Root of Trust attestation, and catastrophe loss models under the state-backed cyber-attack exclusion that Lloyd's Market Bulletin Y5381 requires.
1. The Anatomy of Unauthenticated Industrial Protocols#
Operational technology protocols were conceived in an era when physical air gaps were assumed to provide absolute perimeter security. Consequently, their protocol designs prioritize deterministic execution and low compute overhead over cryptographic security.
1.1 Modbus TCP (IEC 61158) Vulnerability Mechanics#
Modbus TCP encapsulates the classical Modbus serial Application Protocol inside standard TCP packets on port 502. It contains no authentication headers, no digital signatures, and no payload encryption. Any device on the subnet can issue read and write requests to any connected PLC:
- Function Code 03 (Read Holding Registers): Retrieves 16-bit analog operational data (pressures, temperatures, flow rates, voltage measurements).
- Function Code 06 (Write Single Register): Modifies a single 16-bit analog setpoint (such as commanding a VFD speed reference from to ).
- Function Code 16 (Write Multiple Registers): Rewrites entire blocks of operational parameters, such as recalibrating proportional-integral-derivative (PID) tuning constants or thermal trip limits.
- Function Code 05 (Write Single Coil): Toggles discrete binary states (forcing a pump emergency stop, opening a circuit breaker, or discharging a chemical valve).
Because Modbus TCP packets lack sequence counter validation, replay attacks can be executed using trivial shell tools without requiring advanced exploitation frameworks.
1.2 BACnet/IP (ANSI/ASHRAE Standard 135)#
Building Automation and Control networks operate across UDP port 47808. While modern revisions define optional BACnet Secure Connect (BACnet/SC), the vast majority of installed facility chillers, air handlers, and life-safety panels rely on legacy unencrypted BACnet/IP.
BACnet organizes control points into standardized object identifiers:
ANALOG_INPUT (AI): Physical sensor telemetry (such as ambient hall humidity or primary loop chilled water return temperature).ANALOG_OUTPUT (AO): Modulated control outputs (such as secondary cooling distribution manifold proportional valve angle).BINARY_OUTPUT (BO): Discrete physical actuations (such as fire pre-action solenoid release or emergency ventilation fan start).
An adversary issuing a WriteProperty request to an exposed BINARY_OUTPUT object can override physical interlocks without authentication.
1.3 Out-of-Band Redfish REST / IPMI Interfaces#
Baseboard Management Controllers (BMCs) operate an independent out-of-band management network connected directly to server hardware. Modern platforms implement the DMTF Redfish standard; a RESTful HTTPS API serving structured JSON payloads. While Redfish incorporates TLS transport encryption, common-cause failure occurs through shared administrative credentials, factory default passwords, and unpatched web server vulnerabilities. A compromised BMC possesses unrestricted register-level access to host hardware via PCIe sideband (MCTP over SMBus), I2C, and SPI flash buses.
2. Multi-BOM and DEXPI Integration#
To prevent disconnected analysis, every industrial register documented in this CyHAZOP drill-down is mapped directly to its physical DEXPI 2.0 equipment tag, classed against ISO 15926-4 reference data, and its CycloneDX 1.6+ multi-BOM component reference:
3. Register Maps across Four Critical Nodes#
This section sets out the register mappings, their physical engineering interpretation, and the consequence of manipulating each one, across the four core infrastructure nodes. The register numbers, object identifiers and endpoints are taken from the published protocol maps of the equipment classes named in each table. The engineering interpretations and the consequences beside them are this working group's analysis of what a write to that address does to the plant, and they are reasoned from the physics of the node rather than observed on a specific site.
3.1 Node 1#
Secondary Cooling Loop (CDU & Manifold Registers)
The Coolant Distribution Unit (CDU) manages heat rejection from compute trays to the primary facility water loop:
Node 1: CDU Modbus TCP holding register map.
| Modbus Register | DEXPI Equipment Tag | Data Type & Scale | Engineering Parameter | Nominal Baseline | Malicious Setpoint Override | Physical Consequence | Severity |
|---|---|---|---|---|---|---|---|
| 40101 | CDU-PUMP-01 | 16-bit uint (0-1) | Pump Operating State | 1 (Running) | 0 (Emergency Stop) | Immediate cessation of flow (). Silicon surges at . | Catastrophic |
| 40102 | CDU-VFD-01 | 16-bit uint () | VFD Inverter Speed Setpoint | 600 () | 120 () | Volumetric delivery drops to . Heat transfer coefficient drops . | Major |
| 40104 | VALVE-V102 | 16-bit uint () | 3-Way Mixing Valve Position | 1000 ( Open) | 150 ( Open) | Darcy head loss increases from to . Severe pump cavitation. | Catastrophic |
| 30201 | FT-101 | 16-bit uint () | Secondary Flow Telemetry | 1220 () | Spoofed to 1220 (True: 18.4) | Telemetry deception blinds SCADA monitors; hardware safety trips suppressed. | Catastrophic |
| 30202 | TT-101 | 16-bit int () | Supply Fluid Temperature | 300 () | Spoofed to 300 (True: 58.0) | Operators unaware of thermal runaway; facility alarms blinded until fire. | Catastrophic |
| 40110 | CDU-SAFETY | 16-bit uint () | Hardware Thermal Trip Setpoint | 850 () | 1200 () | Overwrites internal safety cutoff, allowing compute dies to overheat to physical destruction. | Catastrophic |
3.2 Node 2#
400V/48V Power Train & Static Transfer Switch
The electrical power train delivers three-phase utility power through distributed block UPS modules:
Node 2: STS and UPS Modbus / BACnet register map.
| Register / Point | Electrical Asset Tag | Protocol & Type | Engineering Parameter | Nominal Baseline | Malicious Setpoint Override | Physical Consequence | Severity |
|---|---|---|---|---|---|---|---|
| 40001 | STS-FEED-SEL | Modbus uint (0-2) | Active Supply Infeed Selector | 1 (Primary Feed A) | 0 (Force Both Open) | Instantaneous bus blackout (). Uncontrolled power loss across 100 MW campus. | Catastrophic |
| 40015 | UPS-INV-FREQ | Modbus uint () | Inverter Output Frequency | 5000 / 6000 () | 6500 () | Transformer core saturation, severe eddy currents, capacitor bank acoustic explosion. | Catastrophic |
| AO:12 | PDU-VOLT-TRIP | BACnet Float (V) | Under-Voltage Trip Threshold | 360.0 V | 440.0 V | Erroneous spurious tripping of all PDU branch circuits during minor line fluctuations. | Major |
| 40032 | BESS-INVERTER | Modbus uint (0-1) | Grid-Tie Anti-Islanding Protection | 1 (Enabled) | 0 (Disabled) | Uncontrolled back-feeding into dead utility grid; lethal electrocution hazard for line crews. | Catastrophic |
3.3 Node 3#
Building Management System & Fire Suppression
The facility BMS oversees life safety, smoke purge systems, and clean-agent release:
Node 3: BMS BACnet life safety object map.
| BACnet Object ID | Life Safety Tag | Object Type | Engineering Parameter | Nominal Baseline | Malicious Command Override | Physical Consequence | Severity |
|---|---|---|---|---|---|---|---|
| BINARY_OUTPUT:1 | SOL-NOVEC-R04 | Binary Output | Gas Discharge Solenoid | 0 (Inactive) | 1 (Active Release) | Full clean-agent release into data hall. Acoustic shock shatters mechanical storage. | Catastrophic |
| BINARY_OUTPUT:4 | EPO-MAIN-HALL | Binary Output | Emergency Power Off Trip | 0 (Normal) | 1 (Trip EPO) | Hard facility electrical de-energization. 48 to 72 hours of total business downtime. | Catastrophic |
| ANALOG_OUTPUT:5 | DAMPER-SMOKE | Analog Output () | Smoke Purge Damper Position | 0 ( Closed) | 100 ( Open) | Breaches fire compartmentation; draws outside toxic smoke into occupied spaces. | Major |
| BINARY_INPUT:2 | PULL-STATION | Binary Input | Manual Fire Alarm Input | 0 (Normal) | Spoofed to 0 during true fire | Suppresses evacuation alarms and automatic fire suppression response. | Catastrophic |
3.4 Node 4#
Baseboard Management Controller & Silicon Sideband
The BMC provides out-of-band server management via DMTF Redfish REST APIs and I2C/SMBus sideband:
Node 4: Redfish REST and I2C silicon register map.
| Redfish JSON URI | Hardware Register | Bus & Protocol | Engineering Function | Nominal Value | Malicious Injection | Physical Consequence | Severity |
|---|---|---|---|---|---|---|---|
/redfish/v1/Chassis/Tray02/Power | PowerLimitWatts | Redfish REST (HTTPS) | Tray Peak Power Cap | 10500 () | 2500 () | Throttles all 8x accelerators to baseline idle clocks; kills active training job. | Major |
/redfish/v1/Chassis/Tray02/Thermal | Fans/0/SpeedSet | Redfish REST (HTTPS) | Chassis Cooling Fan RPM | Dynamic () | 0 () | Loss of auxiliary chassis airflow; VRM power stages overheat and burn out. | Catastrophic |
0x70 / Reg 0x21 (VRM Controller) | VOUT_COMMAND | I2C / PMBus | Core Voltage Rail () | 0.85 V DC | 1.25 V DC () | Gate oxide breakdown across accelerator packages; instant silicon destruction. | Catastrophic |
0x50 / Reg 0x04 (SPI Controller) | FLASH_PROTECT | SPI Sideband | Hardware Flash Write Protect | 1 (Protected) | 0 (Unprotected) | Disables firmware integrity checks, enabling persistent rootkit insertion into BIOS. | Catastrophic |
4. Quantitative Physics of Register-Induced Deviations#
When an adversary alters an operational register, the physical system does not respond instantaneously. It responds according to non-linear physical differential equations governing fluid mechanics, heat transfer, and electromagnetic inductances.
4.1 Transient Hydraulic Response to Modbus VFD Step Change#
When Modbus register 40102 is stepped from () to (), the motor rotational speed and resulting volumetric flow rate follow a first-order lag governed by the VFD deceleration time constant ():
As volumetric flow collapses below , fluid velocity in the microchannels drops from to . The channel Reynolds number drops from to , both laminar, and the convective heat transfer coefficient falls with the thermal entry length:
Within , convective heat transfer collapses by , initiating immediate heat accumulation in the accelerator cold plate.
4.2 Telemetry Quantization & Sensor Deception Dynamics#
When an attacker injects false telemetry to register 30202 (Supply Temperature) while manipulating register 40104 (Valve Position), the perceived temperature diverges from the true physical temperature :
Where remains constant on operator monitoring screens, while reaches the emergency hardware shutdown trip point at . Because supervisory alarms depend on , the control system fails to assert PROCHOT# throttling, and the first the operator knows of it is a tray that has dropped off power.
4.3 High-Voltage Inductive Kickback on Sudden Bus Bar Trips#
When register 40001 forces an instantaneous open command on the main static transfer switch, the interruption of high current () across the rack busway inductance () generates an inductive voltage kickback surge :
Where solid-state breaker opening time . The transient voltage spike is calculated as:
Across medium-voltage distribution switchgear ( feed with and ), an uncoordinated trip generates:
This inductive surge punches through transformer insulation barriers, creating catastrophic arc flash explosion and transformer oil fires.
4.4 Actuarial Consequential Loss Accumulation#
For insurance treaty structuring and property catastrophe modeling, the financial loss resulting from unauthorized manipulation of operational technology registers is formulated as:
Where represents the direct replacement cost of ruined compute trays ($120,000 USD per tray), is the hourly business interruption loss rate ($18,500 USD/hour), and is the supply-chain restoration lead time ( for high-density silicon accelerators).
4.5 Return on Security Investment (ROSI) for Hardware Cryptographic Bumps#
The financial return on deploying hardware-enforced cryptographic message authentication (bump-in-the-wire MAC verification) on Modbus TCP conduits is quantified through:
For an AI cluster with unmitigated catastrophe loss expectancy , deploying bump-in-the-wire FPGA authenticators () blocks unauthenticated writes at the conduit, reducing residual and giving a modeled .
The three inputs are the working group's own. The 45,000 USD is a hardware and installation estimate for FPGA authenticators across the cluster's Modbus conduits. The 4,200,000 USD unmitigated expectancy comes from the consequence model in section 4, which is itself built on assumed tray replacement cost, an assumed hourly interruption rate and an assumed event frequency. The 25,000 USD residual assumes the authenticator removes the unauthenticated write path entirely and leaves only attacks that reach a legitimate key. The quotient is exact to 9,177.78 percent and that exactness carries no evidential weight. What the calculation does support is the ordering: an authenticator costing tens of thousands sits against a consequence measured in millions, so the case for it does not depend on the precise figures.
5. Industrial Proof: Documented Exploitation Mechanics#
The register manipulations documented in this paper follow the mechanics of publicly reported incidents. The cases below are drawn from published reporting on each event; where this paper describes what an attacker could have done next rather than what was reported, it says so in the text:
5.1 Unitronics Vision PLC Water Sector Compromises (November 2023)#
Nation-state adversaries compromised municipal water boosting stations by connecting directly to port 502 across the public internet. The attackers used default administrative credentials (PIN 1111) to write to holding registers controlling chlorine dosing pumps and pressure regulators. The attack demonstrated that adversaries possess automated tooling to identify and manipulate specific industrial registers.
5.2 INCONTROLLER / Pipedream Malware Framework (CISA 2022)#
CISA published technical advisories on INCONTROLLER, a modular industrial attack framework specifically engineered to manipulate Omron and Schneider Electric PLCs via Modbus TCP and CODESYS protocols. The malware incorporates dedicated modules to scan for holding registers, alter analog setpoints, and overwrite firmware flash blocks, providing point-and-click physical sabotage capabilities against industrial facilities.
5.3 Triton / Trisis Safety System Attack (Schneider Triconex)#
Adversaries deployed custom malware targeting the Triconex Safety Instrumented System (SIS) controllers at a petrochemical refinery. The malware injected malicious machine code directly into the controller memory, attempting to suppress hardware safety trips so that subsequent process deviations (high pressure, extreme temperature) would result in physical refinery explosions.
6. Systems Assurance: Hardening and Verification Blueprint#
To protect critical infrastructure from register-level cyber-physical sabotage, systems assurance leads mandate five engineering controls:
6.1 Cryptographic Protocol Modernization (IEC 62443-4-2 SL-3)#
- Modbus TCP Security (MB-TCP-SEC): Deprecate legacy port 502. Mandate TLS 1.3 encapsulation on TCP port 802 with mutual X.509 certificate authentication.
- BACnet Secure Connect (BACnet/SC): Transition all building management controllers to encrypted WebSockets conduits utilizing TLS 1.3 and centralized hub-and-spoke certificate authorities.
- Bump-in-the-Wire Security Gateways: For legacy field devices incapable of TLS termination, deploy DIN-rail FPGA security appliances that inspect Modbus packets, enforcing HMAC-SHA256 signatures on all write commands (Function Codes 05, 06, 16).
6.2 Hardwired Analog Safety Interlocks (SIL-3)#
Software commands must never hold sole authority over life-safety or catastrophic physical thresholds:
- Physical Thermal Cutouts: Microchannel cold plates must incorporate bi-metallic thermal switches wired directly to server power supply shutoff lines, physically dropping 48V DC power if regardless of BMC register states.
- Pneumatic Pressure Relief: Cooling distribution manifolds must feature mechanical spring-loaded pressure relief valves calibrated to , mechanically venting fluid before pipe burst pressure is reached.
- Hardware Reverse-Direction Jumpers: Variable Frequency Drives must enforce motor direction through physical motherboard solder bridges or hardwired jumpers, rendering remote Modbus direction inversion impossible.
6.3 Open Silicon Roots of Trust & Caliptra 2.0#
Server compute blades must enforce hardware root-of-trust validation across all internal buses:
- Immutable Boot ROM: Caliptra Silicon Root of Trust validates firmware cryptographically before allowing host processor power rail release.
- Dual-Flash Recovery: Automatic hardware failover to an immutable, write-protected golden firmware image if active SPI flash corruption is detected.
- DICE Certificate Hierarchies: Generating unique cryptographic device identities that attest to the exact hardware revision and firmware measurements.
7. Actuarial and Underwriting Implications#
The presence of unauthenticated holding registers on cooling and power infrastructure fundamentally alters the insurability of mission-critical facilities:
| Underwriting Dimension | Unauthenticated Legacy OT | Register-Hardened & CyHAZOP-Audited | Underwriting Impact |
|---|---|---|---|
| Common-Cause Exploitability | Single network script can trip all cooling loops simultaneously. | Cryptographic command signing and hardwired interlocks isolate failures. | Portfolio accumulation risk mitigated; eliminates correlated catastrophic losses. |
| PML / MPL Sizing | Unbounded physical damage; potential total loss of compute hardware (). | Physically constrained by autonomous analog interlocks; loss bounded to single rack. | Reinsurance syndicates release capital buffers; rate reductions of 22% to 35%. |
| Lloyd's Y5381 Exclusion | Disputed claims during nation-state attacks; severe litigation risk. | SIL-3 physical interlocks, proof-tested on a stated interval and documented in the hazard ledger, satisfy statutory due diligence standards. | The state-backed cyber-attack exclusion Y5381 requires stays in the wording; what a proof-tested ledger moves is the loss left uninsured behind it, not the exclusion. |
| Parametric Triggers | Subjective damage surveys requiring weeks of onsite inspection. | Parametric claims settlement triggered automatically by digital twin telemetry read from instruments the adjuster can calibrate and re-read. | Claims resolved in days; operational working capital restored rapidly. |
The rate reductions of 22 percent to 35 percent in the impact column are modeled. They express what this working group judges a syndicate will concede once physical interlocks bound the loss to a single rack, and they are reasoned from the size of the accumulation buffer such a syndicate currently carries against unbounded cooling failure. No slip, submission or treaty wording is cited for them.
8. Summary of Engineering Principles#
Securing operational technology registers against cyber-physical sabotage demands five non-negotiable engineering principles:
- Every Register is a Mechanical Lever: A digital write command to a PLC holding register is physically identical to a technician manually wrenching a valve. Treat every control register as a safety-critical hazard.
- Zero Trust for Network Write Commands: Unauthenticated Modbus TCP and BACnet write operations must be prohibited. All command conduits must enforce cryptographic authentication and integrity validation.
- Defense in Depth Demands Analog Independence: Software must never be the sole guardian against software failure. High-consequence failure modes must be arrested by hardwired, analog, or mechanical interlocks.
- Sub-Second Physics Trumps Human Intervention: Silicon thermal runaway executes in seconds; supervisory alarms and manual operating procedures require minutes. Safety loops must be autonomous, local, and immediate.
- Actuarial Argument Requires Quantitative Telemetry: Reinsurance treaty structuring and risk transfer need digital twin models that link register states directly to physical thermodynamic constraints, with every parameter in the model named and its origin stated. A model whose inputs are traceable can be argued over by an underwriter; a model whose inputs are asserted cannot, however exact its arithmetic.
9. References#
The technical claims above rest on the protocol standards applied in the body text (Modbus TCP / IEC 61158, BACnet/IP under ANSI/ASHRAE Standard 135, Redfish, PMBus/I2C), on IEC 62443-4-2 and the Caliptra Silicon Root of Trust specification for the hardening measures in section 6, and on Lloyd's Market Bulletin Y5381 for the state-backed cyber-attack exclusion. Section 5 reads three publicly documented incidents as public record: the Unitronics Vision PLC water-sector compromises (November 2023), the INCONTROLLER / Pipedream malware framework (CISA, 2022), and the Triton / Trisis safety-system attack on a Schneider Triconex controller. CISA's own advisories and incident write-ups carry the primary reporting on each. The 1,200 W accelerator package power figure in the section 3 register map is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet. The financial and actuarial figures in sections 4 and 7 are this working group's own modeled scenarios rather than figures drawn from a claims history, an operator loss run, or a bound placement, and are disclosed as such where they appear.