The Cyber Digital Twin Eight-Layer Architecture: Mathematical Formalization, Inter-Layer Transition Physics, and Quantitative Process Zone Hardening
J. McKenney
This paper belongs to the Digital Twin Architecture working group and to no series of its own. A companion paper in the same group sets out the same eight-layer graph beside the McKenney-Lacan calculus that occupies its human layer, and states the four dynamical equations run over it. Two others take single sections of this one further: one treats the decision latency that section 5.1 states as an asymmetry, against a thermal cliff measured in tens of seconds, and one treats tier classification, redundancy topologies and common-mode failure. The five-part Fooled by Best Practice series in the same group argues in ordinary language why a distribution rather than a score is the right thing to report.
Licence: CC BY 4.0. 14 June 2026.
Executive Abstract#
The Cyber Digital Twin models critical infrastructure as one coupled dynamical system on a multi-relational knowledge graph, binding equipment thermodynamics, network conduits, firmware, operator cognition and economic signals. Its eight layers read the same for an executive, an auditor, an underwriter and a graph engine, and the foundational split between plant and controllers is load-bearing.
The architecture is built for the traversal between layers: an attack is a path across layers, its probability the product of each step. Two numbers place the facility, whether lateral code dies out or sustains itself and whether the plant rests in a stable basin or at the edge of a fold.
The paper runs this on a chemical process zone modeled twice, once as commonly built and once with a one-way optical link and write-dropping conduit, a pneumatic line from transmitter to blowdown valve bypassing software, and cold-boot firmware attestation. End-to-end probability falls from 45.04 percent to two parts in ten million. Severity does not move, the same equipment destroyed and the same 45-day outage; only frequency does, and annual loss expectancy falls from thirteen point two million dollars a year to single dollars, against a three-year cost under six hundred fifteen thousand dollars.
Abstract#
The Cyber Digital Twin is formalized as a coupled dynamical system over a multi-relational knowledge graph in eight layers: L1 facility and equipment catalog, L2 equipment, systems and networks, L3 software, SBOM and exposure surface, L4 threats and adversary manifold, L5 human and psychometric dynamics, L6 telemetry and geopolitical drivers, L7 economic and actuarial, and L8 predictive and temporal dynamics by Hawkes point processes. Transitions follow a calibrated Markov chain, so an attack path of length k carries an end-to-end probability equal to the product of its conditional transitions. Two parameters are tracked: the network reproduction number, the adjacency spectral radius times the transmission-to-recovery ratio, and the Seldon Crisis Parameter, a normal-form bifurcation whose sign decides stability. Applied to an autoclave polymerization zone at ATQ 88.4, the baseline composes to 45.04 percent at spectral radius 2.74. With the two external transitions fixed, applying unidirectional telemetry, a read-only hardware conduit, a hardwired pneumatic interlock and cold-boot attestation, it falls to 2.227x10^-7 at spectral radius 0.29. Single loss expectancy holds at $24.5 million while annual loss expectancy falls from $13.2 million to single dollars, the rational spend bounded by Gordon-Loeb. Three constraints close the paper: the physics-cognitive latency asymmetry (a 12-45 s runaway against a 65-180 s operator), heuristic reconstruction of legacy drawings with per-node confidence, and an air-gapped island mode under four invariants.
1. Platform Taxonomy: The L1-L8 Layer Model#
The model organizes facility operations into eight functional layers for risk governance, audit reporting, and executive decision-making:
- L1 Facility & Equipment Catalog: Physical plant topology, piping, vessels, rotating machinery, and containment envelopes, held against the reference model of the same plant so that the designed facility and the operating facility are separate objects. Ingests computer-aided design artifacts, including DEXPI 2.0 and ISO 15926-4 Proteus XML exports.
- L2 Equipment, Systems & Networks: Industrial control networks, routing tables, fieldbuses (Modbus, OPC-UA, DNP3, PROFINET), firewalls, VLANs and jumpboxes, and the controllers on them: PLCs, RTUs, distributed control systems (DCS), safety instrumented systems, and human-machine interfaces, each carried at serial-number granularity.
- L3 Software, SBOM & Exposure Surface: CycloneDX 1.6+ software bills of materials and their transitive dependencies, firmware images, and VEX and CSAF advisory streams, together with the active exposures across the software and hardware stack, continuously updated with 30-day Exploit Prediction Scoring System (EPSS) velocity vectors and CISA Known Exploited Vulnerabilities (KEV) catalogs without active scanning.
- L4 Threats & Adversary Manifold: Adversary registry profiling 389 state and criminal groups. Ingests the TACAM 7-dimensional spectral matrix (77,279 relational edges) and computes a cardinal Actor Threat Quotient () measuring adversary tool weaponization and sector affinity.
- L5 Human & Psychometric Dynamics: Operator and defender state under load: cognitive load, arousal, and decision latency on the recognition-primed model, together with the organizational governance and policy frameworks that set who may act and how quickly. Section 5.1 states the constraint this layer exists to measure.
- L6 Telemetry & Geopolitical Drivers: Sensor time series, Modbus registers, and alarm and event streams, correlated against external risk drivers: regional conflict datasets (ACLED), geopolitical tension indices, supply chain bottlenecks, and energy market stress indicators that alter adversary campaign frequency.
- L7 Economic & Actuarial: Bottom-up physical vulnerability coupled with top-down adversarial pressure. Executes 50,000 Monte Carlo runs to produce Annual Loss Expectancy (ALE), Value at Risk (), Loss Exceedance Curves, and Gordon-Loeb investment boundaries [2].
- L8 Predictive & Temporal Dynamics: Forward-looking risk projections computed via self-exciting Hawkes point processes, identifying temporal clustering in campaign preparation up to 90 days before execution.
2. Database Ontological Schema: The L1-L8 Graph Engine#
Under the hood of the Seldon graph engine, the Neo4j knowledge graph (comprising 3.2 million nodes and 85 million edges) carries the same eight layers as a registry, splitting the physical asset at the foundation from the equipment and controllers that act on it:
| Graph Layer | Domain | Core Entities | Ingestion Standards |
|---|---|---|---|
| L1 | Facility & Equipment Catalog | Buildings, reactors, pumps, heat exchangers, pipes | DEXPI 2.0 XML, ISO 15926-4, P&ID [4] |
| L2 | Equipment, Systems & Networks | Firewalls, VLANs, jumpboxes, network interfaces, PLCs, RTUs, SIS safety logic, HMIs, DCS loops | PCAP, NetBox, LLDP, ARP tables |
| L3 | Software, SBOM & Exposure Surface | Firmware images, packages, transitive dependencies, active exposures | CycloneDX 1.6, SPDX, CSAF 2.0 |
| L4 | Threats & Adversary Manifold | State and criminal groups, campaigns, techniques, weaponized exploits | TACAM cluster tables, MITRE ATT&CK for ICS |
| L5 | Human & Psychometric Dynamics | Operator cognitive load, alert fatigue, stress response, suppliers, contractors, policy frameworks | Sweller CLT, Klein RPD Model [1], IEC 62443-2-1, NIS2 Article 21 [3] |
| L6 | Telemetry & Geopolitical Drivers | Sensor series, alarm streams, state actors, sanctions, critical resource flows | ACLED, GPR Index, trade data |
| L7 | Economic & Actuarial | ALE, single loss expectancy, insurance deductibles | Lloyd's Bull. Y5381, SEC 8-K [5] |
| L8 | Predictive & Temporal Dynamics | Hawkes arrival rates, EPSS velocity, degradation curves | Time-series materialized views |
3. Inter-Layer Causal Transition Dynamics#
The core differentiator of the CDT architecture is that layers do not operate as isolated silos. Attack trajectories traverse between layers following calibrated Markov transition probabilities.
The causal chain links external tension directly to physical hardware failure and corporate capital impairment:
The end-to-end traversal probability across an attack path of length is given by:
The system measures global network stability through two parameters:
- Network Epidemic Threshold (): The network reproduction number , where is the spectral radius, the maximum eigenvalue, of the network adjacency matrix , is the pathogen's transmission rate per exposed connection, and is its recovery rate, the rate at which infected nodes are patched, isolated or otherwise cleared [6]. If , the network is in a supercritical state where lateral malware propagation is self-sustaining. If , outbreaks are strictly sub-epidemic and decay exponentially.
- Seldon Crisis Parameter (): The normal-form bifurcation parameter governing phase transitions in control stability: When , the operational system resides within a stable basin of attraction. When , the equilibrium vanishes via a saddle-node bifurcation, resulting in a sudden transition to unconstrained physical damage.
4. Quantitative Process Zone Conduit Hardening (What-If Study)#
To demonstrate the multi-layer causal engine, we evaluate a simulated attack on Process Zone PZ-04 (Autoclave Polymerization Reactor & Mechatronic Exotherm Loop) in a continuous chemical processing facility.
4.1 Asset Baseline#
- Physical Asset (L1): Autoclave Reactor
R-101, Feed CompressorC-102, Primary Cooling LoopCW-204, Pneumatic Emergency Blowdown ValveXV-101A/B, Mechanical Rupture DiscBD-101(burst rating: 250 bar). Source: DEXPI 2.0 XML [4]. - Control Systems (L2): Siemens S7-1500 PLC (v2.8 firmware) managing PID temperature loops; Schneider Electric Triconex Tricon SIL-3 Safety Instrumented System (SIS) managing high-pressure interlocks. Source: CycloneDX 1.6 SBOM.
- Threat Actor (L4): Advanced persistent threat actor with verified capability against industrial control protocols ().
4.2 Phase 1#
Baseline Architecture (Flat OT / Permissive Conduits)
In the baseline state, enterprise IT communicates with OT Level 3 through a dual-homed jumpbox without hardware conduit enforcement or deep-packet inspection (DPI).
Transition Probabilities:
- (Geopolitical tension elevates targeting)
- (Actor tooling matches exposed facility footprint)
- (Jumpbox compromise and lateral pivot to OT subnet)
- (Unauthenticated Modbus/TCP write commands injected into PLC suppress the cooling jacket setpoint)
- (Thermal runaway follows; disc ruptures and the loss is realized)
Topological and Stability Metrics:
- Adjacency spectral radius: (supercritical epidemic regime)
- Seldon Lyapunov parameter: (unstable saddle-node bifurcation)
Actuarial Baseline (50,000 Monte Carlo Iterations):
- Single Loss Expectancy (SLE):
- Capital equipment destruction (
R-101, piping, catalyst bed): - Environmental remediation and regulatory penalties:
- 45-day unrecoverable plant outage:
- Capital equipment destruction (
- Annual Rate of Occurrence (ARO):
- Annual Loss Expectancy ():
- Value at Risk ():
4.3 Phase 2#
Targeted Countermeasure Run (IEC 62443-3-2 Conduits & SIL-3 Interlocks)
The digital twin tests a virtual architectural intervention prior to capital expenditure:
- IEC 62443-3-2 Conduit Enforcement: Unidirectional optical data diode for outbound telemetry; inline hardware DPI conduit restricting industrial traffic to read-only function codes (
FC 03,FC 04) while dropping all write commands (FC 05,FC 06,FC 16) [3]. - Hardwired Physical Interlock: Analogue pneumatic bypass from transmitter
PT-101directly to blowdown valveXV-101A, bypassing software Ethernet layers entirely. - Cryptographic Silicon Attestation: Hardware root of trust (TPM 2.0 / Caliptra) verifying cold-boot firmware integrity.
Recalibrated Transition Probabilities:
- (External geopolitical tension unchanged)
- (External adversary tooling unchanged)
- (Jumpbox isolated; management paths restricted to out-of-band VLAN)
- (Unauthorized writes dropped by physical DPI conduit)
- (Analogue SIL-3 interlock depressurizes reactor within 400ms)
Topological Transformation:
- Adjacency spectral radius: (sub-epidemic regime; cascades cannot propagate)
- Seldon Lyapunov parameter: (strongly stable fixed-point attractor)
4.4 Phase 3#
Actuarial Comparison and Financial Return
| Risk & Financial Metric | Baseline (Flat OT Topology) | Hardened Conduits (IEC 62443-3-2) | Variance / Delta () |
|---|---|---|---|
| Spectral Radius | (Supercritical) | (Sub-epidemic) | |
| Seldon Bifurcation | (Unstable) | (Stable Attractor) | Phase Transition to Safety |
| End-to-End Breach Probability () | Reduction | ||
| Single Loss Expectancy (SLE) | (Physical consequence static) | ||
| Annual Rate of Occurrence (ARO) | events/yr | events/yr | |
| Annual Loss Expectancy (ALE) | () | ||
| Value at Risk () |
Capital Allocation Optimization (Gordon-Loeb Theorem): The Gordon-Loeb theorem bounds the rational cybersecurity investment budget as [2]:
- Total 3-Year Implementation Cost: (Diode and DPI hardware ; SIL-3 pneumatic actuator retrofit ; engineering attestation ; annual maintenance and cryptographic audit ).
- Return on Security Investment (ROSI):
- Underwriting Realization: The state-backed cyber-attack exclusion that Lloyd's Market Bulletin Y5381 [5] requires stays in the wording; what the evidence package moves is the underwriter's frequency and severity view, which compresses the plant deductible from , and reduces operational interruption insurance premiums by .
4.5 Graph Database Engine Traversal Query#
// Seldon 8-Layer Multi-Relational Path Traversal Query
MATCH path = (geo:GeopoliticalFactor {zone: "Petrocorridor-EU"})
-[:AMPLIFIES]-> (actor:ThreatActor {archetype: "Volt Typhoon / Sandworm"})
-[:WEAPONIZES]-> (vuln:Vulnerability {cve: "CVE-2024-XXXX"})
-[:CROSSES_BOUNDARY]-> (conduit:NetworkConduit {zone_from: "IT_L3", zone_to: "OT_L2"})
-[:INJECTS_COMMAND]-> (plc:Controller {tag: "PLC-R101-S71500"})
-[:DRIVES_TRANSIENT]-> (equip:PhysicalAsset {tag: "R-101", standard: "DEXPI-2.0"})
-[:TRIGGERS_LOSS]-> (loss:EconomicImpact)
WITH path,
reduce(p = 1.0, r in relationships(path) | p * r.transition_probability) AS cumulative_prob,
loss.direct_damage + loss.business_interruption AS single_loss_expectancy
RETURN
[n in nodes(path) | labels(n)[0] + ":" + coalesce(n.tag, n.cve, n.name, n.archetype)] AS attack_chain,
cumulative_prob AS traversal_probability,
single_loss_expectancy AS sle,
cumulative_prob * single_loss_expectancy * 1.2 AS annual_loss_expectancy;5. Architectural Extensions & Operational Constraints#
To address real-world deployment across legacy brownfield facilities, the CDT framework incorporates three operational constraints:
5.1 The Physics-Cognitive Latency Asymmetry ()#
Industrial safety is governed by physical time constants. In rapid runaway reactions, the physical excursion time constant satisfies:
In contrast, human operators experiencing alarm flood in control rooms exhibit mean decision latencies governed by Gary Klein's Recognition-Primed Decision (RPD) model [1]:
Because , human intervention during an active control-plane attack is mathematically incapable of arresting catastrophic overpressurization. This latency gap proves why software-only security fails and why hardwired, un-routable SIL-3 physical trips are mandatory.
5.2 Heuristic Reconstruction of Legacy Brownfield CAD#
Operating industrial facilities frequently lack pristine DEXPI 2.0 XML exports, relying instead on legacy scanned piping and instrumentation diagrams (P&IDs). The CDT resolves this through computer vision and symbol graph extraction:
- Optical character and glyph recognition extracts equipment tags, flow arrows, and valve types from scanned raster drawings.
- The ingestion pipeline infers conduit boundaries and creates synthetic DEXPI 2.0 graph nodes with a confidence score .
- Missing parameter fields inherit conservative default physics values from standard process engineering reference manuals.
5.3 Sovereign Air-Gapped Operation & Update Invariants#
For nuclear facilities, defense infrastructure, and classified environments where cloud connectivity is prohibited, the CDT runs in Island Mode:
- The digital twin operates entirely on local, on-premise hardware without external network interfaces.
- Threat intelligence updates (TACAM) and vulnerability feeds are transferred periodically via physical, cryptographically signed tokens.
- The system enforces four operational invariants:
- Passive ingestion only: Zero packets sent to operational field networks.
- Write boundary isolation: No automated remote changes to PLC logic or safety interlocks.
- Deterministic replay: Graph simulations must produce identical state transitions from identical input seeds.
- Hardware attestation: Firmware images validated against silicon root of trust signatures on cold boot.
6. References#
- [1] Klein, G. (1998): Sources of Power: How People Make Decisions. MIT Press.
- [2] Gordon, L. A., & Loeb, M. P. (2002): "The economics of information security investment." ACM Transactions on Information and System Security, 5(4), 438-457.
- [3] IEC 62443-3-2 (2020): Security for industrial automation and control systems, Part 3-2: Security risk assessment for system design. International Electrotechnical Commission.
- [4] DEXPI e.V. (2025): DEXPI 2.0 Specification: Process and Plant Model Integration. Data Exchange in the Process Industry.
- [5] Lloyd's (2022): Market Bulletin Y5381: Cyber-attack exclusions. Corporation of Lloyd's, 16 August 2022. The model wordings drafted to meet it are the Lloyd's Market Association's clauses LMA5564 to LMA5567, November 2021.
- [6] Van Mieghem, P., Omic, J., & Kooij, R. (2009): "Virus spread in networks." IEEE/ACM Transactions on Networking, 17(1), 1-14.