Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
Cyber FMECACyber Risk Underwriting

Treatise 13: Quantitative Cyber-Physical FMECA: Failure Mode Analysis for Underwriting

100% Complete & Untruncated 17 min read
Return to Research Tracks

J. McKenney

This paper belongs to the WG-01-UI underwriter-insurance working group alongside WG-01-UI-Physics-Grounded-Cyber-Underwriting, which derives Single Loss Expectancy and Annualized Loss Expectancy from a unified physical and cyber asset graph rather than, as this paper does, from component-level failure-mode scoring; the two are companion treatments of the same underwriting problem rather than entries in a numbered series, and neither names an unpublished sibling.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

Reliability engineers rank equipment failure risk with FMECA: for each way a part can fail, they rate its severity, its likelihood, and the chance of catching it in time, then multiply the three into a Risk Priority Number. The method assumes a part fails the way metal and bearings do, gradually, with warning signs a maintenance team can read.

Once a cooling pump or isolation valve joins a network, that assumption breaks. An attacker who can send a command makes the part fail instantly, with no wear and no warning, and can falsify the sensor readings that would otherwise catch the failure early. This paper reworks the scoring and shows, across eighteen pieces of equipment in a modeled data centre, that the cyber version of a failure scores many times higher than its mechanical equivalent. That multiplier comes from expert judgment applied consistently, not from a database of real failures.

The paper then carries the scores through to money: a Risk Priority Number becomes an annual expected loss and a return-on-investment case for a specific fix, such as a hardwired safety interlock a network attacker cannot reach. The loss figures behind that return are the working group's own estimates, not measured losses.

Abstract#

Failure Mode, Effects, and Criticality Analysis (FMECA) under IEC 60812 is the foundational method of industrial reliability engineering, calculating Risk Priority Numbers (RPN) as the product of Severity, Occurrence, and Detection. Traditional FMECA assumes physical components fail through predictable stochastic mechanisms: bearing fatigue, thermal cycling, corrosion, seal wear. This paper establishes the Cyber-Physical Extension to FMECA. When Coolant Distribution Unit pumps, motorized isolation valves, building management controllers, and automatic transfer switches join operational technology networks, they become open to deliberate digital manipulation. An adversary commanding a pump stop or valve closure over unauthenticated Modbus TCP executes the failure instantaneously and spoofs telemetry registers to report nominal states, so Detection drops. Across a modeled eighteen-component register for a 100 MW high-density compute facility, cyber-induced failure modes carry RPNs 4.0x to 40.0x higher than their mechanical equivalents. The multiplier is modeled, not measured: Severity, Occurrence and Detection are analyst-assigned ordinal scores per IEC 60812, scored by the working group rather than drawn from a fleet failure database. The CDU isolation valve escalates from an RPN of 36 to 486. We formulate the Cyber Multiplier Gap, model adversarial Poisson injection failure densities, and give CFOs, reinsurance syndicates, and catastrophe underwriters an actuarial bridge from component RPNs to Annualized Loss Expectancy (ALE), Probable Maximum Loss (PML), and Return on Security Investment (ROSI).


1. The Methodological Limits of Classical FMECA#

Reliability engineers have used FMECA to design offshore oil platforms, aerospace flight control systems, and high-speed rail corridors. The methodology assigns quantitative ratings from 1 to 10 across three independent dimensions:

  1. Severity (S): The magnitude of physical damage, life-safety hazard, or business disruption resulting from the failure mode.
  2. Occurrence (O): The statistical frequency or probability of the failure mode occurring during the operational lifetime of the asset.
  3. Detection (D): The likelihood that existing monitoring systems, sensor alarms, or maintenance inspections will detect the failure condition before catastrophic damage manifests. In classical reliability scales, a rating of 1 represents instantaneous automated detection, while a rating of 10 represents complete undetectable latency.
RPN=Severity×Occurrence×Detection\text{RPN} = \text{Severity} \times \text{Occurrence} \times \text{Detection}

This is not the only hazard analysis in this programme and the two should not be confused. The Threat Modeling working group's CyHAZOP Methodology extends IEC 61882 rather than IEC 60812, and the difference is the direction of the study: CyHAZOP starts from a node and a deviation guide word, NO, LESS, MORE, REVERSE and the rest, and asks what deviations the node can suffer, while this paper starts from a component and asks how that component fails and what the failure costs. A guide-word study finds deviations that no single component failure produces, and a criticality study ranks components for a budget, which a guide-word study cannot do because it does not produce a per-component number. Neither substitutes for the other, and a facility that has run only one of them has an analysis with a known-shaped hole in it.

1.1 The Mechanical Baseline Assumption#

Classical FMECA calculates Occurrence from Mean Time Between Failure (MTBF) tables derived from decades of operational field data. A centrifugal pump impeller bearing wears out after 50,000 to 80,000 operating hours. This degradation is preceded by measurable physical warning signs: elevated acoustic vibration, temperature rise across bearing housings, and lubricating oil particulate accumulation. Standard supervisory SCADA systems detect these anomalies weeks before mechanical seizure occurs, yielding low Occurrence ratings (O=2 to 3O = 2 \text{ to } 3) and favorable Detection ratings (D=2 to 3D = 2 \text{ to } 3). The resulting mechanical RPN remains comfortably below 60.

1.2 The Cyber-Physical Reality#

When the same centrifugal pump is orchestrated by a Variable Frequency Drive connected to an unauthenticated facility network, the reliability model fractures:

  • Occurrence Inversion: The failure is no longer constrained by mechanical wear physics. A remote threat actor with network access can command the pump to stop at any arbitrary second (O→7O \to 7).
  • Detection Blindness: A skilled adversary does not simply send a stop command; they exploit the two-way nature of the industrial protocol to overwrite holding registers, spoofing nominal rotational speed and normal fluid flow back to the operator console (D→9D \to 9).
  • Common-Cause Synchronicity: While mechanical bearing seizures are uncorrelated stochastic events, a single malicious script can command all redundant CDU pumps across an entire data hall to trip simultaneously, completely defeating parallel N+1 and 2N redundancy architectures.

2. Multi-BOM and DEXPI Structural Mapping#

To execute automated cyber-physical FMECA within the Cyber Digital Twin, every failure mode is cross-referenced between the DEXPI 2.0 plant schematic, classed against the ISO 15926-4 reference data library, and the CycloneDX 1.6+ multi-BOM catalog:

Cyber-Physical FMECA Graph Topology#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram
Graph LayerBound EntitiesAttributes Carried on the Node
DEXPI 2.0 mechanical assetCDU-PUMP-01, VALVE-V102, MANIFOLD-R04Hydraulic properties: PG25 coolant, design flow 122 L/min122\text{ L/min}, head loss
Industrial control conduitModbus TCP port 502, BACnet/IP UDP 47808Registers 40101 (state), 40102 (speed), 40104 (valve), 30201 (flow)
CycloneDX 1.6+ multi-BOM specificationHBOM, SBOM, CBOM, OBOM, VEXItemized in the table below
Multi-BOMCatalogd Contents
HBOMOCP ORV3 trays, Samtec connectors, Caliptra silicon RoT
SBOMOpenBMC Linux kernel, Caliptra mask ROM, OpenSIL firmware
CBOMDICE cryptographic certificates, post-quantum ML-DSA keys
OBOMHardware rate limits (64 kbps64\text{ kbps}), thermal trip limits (94∘C94^\circ\text{C})
VEXMachine-readable vulnerability disclosures (CVE status)

By linking active CycloneDX VEX vulnerability feeds to physical DEXPI asset nodes, the digital twin automatically recalculates component RPNs when a new unpatched remote code execution vulnerability is discovered in an operational technology controller.


3. The Quantitative Cyber-Physical FMECA Matrix#

The following comprehensive table documents eighteen critical infrastructure components across cooling, electrical distribution, building management, and compute silicon. It compares traditional mechanical failure modes against cyber-induced vectors, exposing the massive Cyber Multiplier Gap:

The Eigenia Dual-RPN Cyber-Physical FMECA Master Table#

ComponentPhysical Failure ModeTraditional Mechanical CauseCyber-Physical Attack VectorSOmO_mOcO_cDmD_mDcD_cRPNm\text{RPN}_mRPNc\text{RPN}_cCyber Multiplier
CDU Pump AssemblyCatastrophic flow cessationBearing seizure; VFD DC-bus capacitor failureUnauthenticated Modbus write forces pump stop register 40101937295456710.5x
CDU Motorized ValveValve fails fully closedActuator motor burn; mechanical stem bindingAttacker commands 15% position via BMS while spoofing open status926293648613.5x
CDU Temp TransmitterFalse low reading during runawayThermocouple calibration drift; open wireModbus offset register overwritten; false 30∘C30^\circ\text{C} reported72638423368.0x
Chiller CompressorCompressor shutdownRefrigerant leak; motor thermal overloadBACnet shutdown command injected to chiller PLC82527322808.75x
Cooling Tower Fan VFDFan locked at minimum speedVFD gate driver failure; motor bearing wearVFD maximum frequency register set to 5 Hz5\text{ Hz} via Modbus63638542885.3x
Static Transfer SwitchBoth infeed breakers forced openSolenoid failure; logic board lockupWeb interface exploit commands force-open on both feeds1015181040040.0x
Block UPS ModuleInverter bridge shutdownIGBT thermal breakdown; DC capacitor shortCloud management firmware update bricks inverter DSP926283643212.0x
Substation TransformerDielectric breakdown / fireOil contamination; insulation agingSynchrocheck phase spoofing forces out-of-phase closure1014292036018.0x
48V DC Busbar RectifierOutput voltage collapsePower diode short; over-temperature tripPMBus over-voltage injection causes internal crowbar shutdown82527322808.75x
Facility BMS ControllerSupervisory logic lockupMemory leak in firmware; power glitchRansomware encrypts central BACnet supervisory server827263233610.5x
Gas Suppression PanelInadvertent clean-agent releaseFalse smoke sensor reading; lightning strikeBACnet write command asserts manual discharge solenoid915271831517.5x
Smoke Purge DamperDamper fails closed in fireActuator spring break; pneumatic pressure lossBMS override forces smoke damper closed during fire event82538483206.7x
Water Treatment DosingCoolant chemical foulingDosing pump blockage; chemical reservoir emptyAttacker disables biocide dosing via facility PLC interface63648722884.0x
Server BMC (AST2600)Chassis power kill / brickingSPI flash solder fatigue; VRM overheatingUnauthenticated Redfish API flashes corrupted firmware image927283650414.0x
Silicon VRM ControllerOver-voltage gate oxide punchSMT capacitor cracking; PWM loop driftI2C command overrides VcoreV_{\text{core}} voltage limit to +40%+40\%1015292045022.5x
Grid-Tie BESS InverterUncontrolled utility backfeedInverter sync loss; contactor mechanical weldModbus command disables anti-islanding safety routine914291832418.0x
Cold Plate QD FittingO-ring seal rupture / leakElastomer degradation; mechanical misalignmentRapid pump start water hammer surges pressure to 25 bar25\text{ bar}83638723845.3x
CRAH Air Handling FanTotal airflow lossBelt snap; motor winding shortBACnet group command forces all air handling fans to 0 RPM0\text{ RPM}73627422947.0x

4. Quantitative Formulations Governing Cyber-Physical Risk#

To ground cyber-physical FMECA in rigorous applied physics and financial actuarial science, the methodology is governed by five mathematical formulations.

4.1 The Dual-RPN Formulation and Cyber Multiplier Gap#

For any given physical asset kk, the classical mechanical Risk Priority Number RPNm\text{RPN}_m and the cyber-induced Risk Priority Number RPNc\text{RPN}_c are defined as:

RPNm(k)=S(k)⋅Om(k)⋅Dm(k)\text{RPN}_m(k) = S(k) \cdot O_m(k) \cdot D_m(k)
RPNc(k)=S(k)⋅Oc(k)⋅Dc(k)\text{RPN}_c(k) = S(k) \cdot O_c(k) \cdot D_c(k)

The Cyber Multiplier Gap μcyber(k)\mu_{\text{cyber}}(k), representing the relative risk expansion factor, is formulated as:

μcyber(k)=RPNc(k)RPNm(k)=Oc(k)⋅Dc(k)Om(k)⋅Dm(k)\mu_{\text{cyber}}(k) = \frac{\text{RPN}_c(k)}{\text{RPN}_m(k)} = \frac{O_c(k) \cdot D_c(k)}{O_m(k) \cdot D_m(k)}

Across the critical infrastructure nodes scored in this paper, μcyber\mu_{\text{cyber}} ranges from 4.04.0 (Water Treatment Dosing, 288/72288/72) to 40.040.0 (Static Transfer Switch, 400/10400/10). That range is the ratio of two sets of assigned ordinal scores, so it is a modeled spread rather than a measured one. It carries a clear implication: allocating maintenance budgets on mechanical MTBF data alone misallocates capital and leaves the primary attack vectors undefended.

4.2 Adversarial Non-Random Failure Probability Density#

Traditional reliability engineering assumes component time-to-failure follows an exponential or Weibull distribution governed by a constant hazard rate λmech\lambda_{\text{mech}}. In the presence of targeted cyber attacks, the total failure probability density function ftotal(t)f_{\text{total}}(t) becomes a bimodal mixture distribution:

ftotal(t)=(1−pattack)⋅λmechexp⁡(−λmecht)+pattack⋅δ(t−texploit)f_{\text{total}}(t) = (1 - p_{\text{attack}}) \cdot \lambda_{\text{mech}} \exp\left(-\lambda_{\text{mech}} t\right) + p_{\text{attack}} \cdot \delta\left(t - t_{\text{exploit}}\right)

Where:

  • pattack∈[0,1]p_{\text{attack}} \in [0, 1] is the probability that an adversary targets the facility OT network during operating interval TT.
  • δ(t−texploit)\delta(t - t_{\text{exploit}}) is the Dirac delta function representing an instantaneous, non-random failure triggered at the attacker's chosen time texploitt_{\text{exploit}}.

Because texploitt_{\text{exploit}} is correlated across multiple redundant units, the probability of simultaneous multi-unit failure PsimultaneousP_{\text{simultaneous}} ceases to be the product of independent failure probabilities (PmechN≈0P_{\text{mech}}^N \approx 0). Instead, it scales directly with adversary capability:

Psimultaneous≈pattack⋅∏j=1N1{shared_vulnerabilityj}P_{\text{simultaneous}} \approx p_{\text{attack}} \cdot \prod_{j=1}^N \mathbf{1}_{\{\text{shared\_vulnerability}_j\}}

4.3 Transient Thermal Dissipation Collapse under Valve Throttling#

When a motorized isolation valve (FMECA Row 2) is commanded closed via Modbus TCP, the volumetric liquid flow rate Q˙(t)\dot{Q}(t) collapses. The transient temperature rise of the accelerator silicon die Tj(t)T_j(t) is governed by:

dTj(t)dt=Pdie−hconv(Q˙(t))⋅Acontact⋅(Tj(t)−Tcoolant)Cthermal\frac{dT_j(t)}{dt} = \frac{P_{\text{die}} - h_{\text{conv}}(\dot{Q}(t)) \cdot A_{\text{contact}} \cdot (T_j(t) - T_{\text{coolant}})}{C_{\text{thermal}}}
hconv(Q˙)=Nu⋅kfluidDh,Nu≈7.5h_{\text{conv}}(\dot{Q}) = \text{Nu} \cdot \frac{k_{\text{fluid}}}{D_h}, \qquad \text{Nu} \approx 7.5

Where:

  • Pdie=1,200 WP_{\text{die}} = 1{,}200\text{ W} compute dissipation per accelerator package, the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU.
  • Q˙\dot{Q} collapses from nominal 122 L/min122\text{ L/min} PG25 to 0.0 L/min0.0\text{ L/min}. The channel Reynolds number at design flow is approximately 380, so the cold plate runs laminar and Nu\text{Nu} is the laminar rectangular-duct value, not a turbulent correlation.
  • Cthermal=800 J/KC_{\text{thermal}} = 800\text{ J/K} thermal capacitance of the stagnant cold plate assembly, dominated by the coolant retained in the channels once flow stops.

Within 14.8 seconds14.8\text{ seconds}, silicon junction temperature rises at 1.46∘C/s1.46^\circ\text{C/s} from a nominal 72.5∘C72.5^\circ\text{C} to the 94.0∘C94.0^\circ\text{C} emergency hardware shutdown trip point, and the protection removes power from the tray before human operators can verify alarm authenticity.

4.4 Actuarial Consequence & Annualized Loss Expectancy (ALE)#

To translate FMECA RPN scores into insurance capital requirements, the Annualized Loss Expectancy (ALE\text{ALE}) for each failure mode is formulated as:

ALE(k)=SLE(k)×AROc(k)\text{ALE}(k) = \text{SLE}(k) \times \text{ARO}_c(k)
SLE(k)=Creplacement(k)+Ccollateral(k)+∫0Trestore(k)L˙BI(t) dt\text{SLE}(k) = C_{\text{replacement}}(k) + C_{\text{collateral}}(k) + \int_0^{T_{\text{restore}}(k)} \dot{L}_{\text{BI}}(t) \, dt

Where:

  • SLE\text{SLE} is the Single Loss Expectancy.
  • AROc(k)=α⋅RPNc(k)1,000\text{ARO}_c(k) = \alpha \cdot \frac{\text{RPN}_c(k)}{1{,}000} is the calibrated Annualized Rate of Occurrence derived from the cyber RPN score.
  • CreplacementC_{\text{replacement}} is the capital equipment replacement cost (such as $120,000 per ruined accelerator compute tray).
  • L˙BI(t)\dot{L}_{\text{BI}}(t) is the unserved SLA revenue loss rate ($18,500 per hour).
  • TrestoreT_{\text{restore}} is the supply-chain restoration lead time governed by the Reliability Critical Items List (RCIL).

4.5 Return on Security Investment (ROSI) Prioritized by RPN Delta#

The financial justification for implementing engineering safeguards is determined by the net reduction in Annualized Loss Expectancy divided by control cost:

ROSI(k)=(ALEunmitigated(k)−ALEhardened(k))−Ccontrol(k)Ccontrol(k)\text{ROSI}(k) = \frac{\left(\text{ALE}_{\text{unmitigated}}(k) - \text{ALE}_{\text{hardened}}(k)\right) - C_{\text{control}}(k)}{C_{\text{control}}(k)}

For the CDU isolation valve (Row 2), implementing a hardwired mechanical limit switch and cryptographic Modbus MAC verification (Ccontrol=12,500 USDC_{\text{control}} = 12{,}500\text{ USD}) reduces RPNc\text{RPN}_c from 486486 to 3636, lowering annual loss expectancy from $1,450,000 to $18,000, giving a modeled ROSI=11,356%\text{ROSI} = 11{,}356\% (modeled: both loss expectancies and the control cost are working-group estimates, and the calibration constant α\alpha linking RPNc\text{RPN}_c to AROc\text{ARO}_c is not stated anywhere in this paper).


5. Failure Case Studies#

One Named Incident and One Anonymous Report

The high cyber RPNs documented in this paper follow from vulnerability mechanics that are separately attested in two case studies of unequal strength. Section 5.2 names the vendor, the researcher and three CVE identifiers, so a reader can check it. Section 5.1 names no operator, no date beyond the year and no public report, so a reader cannot; it is retained as an illustrative account, not as evidence:

5.1 The 2024 High-Density AI Colocation Colling Incident#

A 40 MW high-density compute facility in the Asia-Pacific region experienced a cluster-wide thermal shutdown when an adversary used unauthenticated BACnet write commands to manipulate chilled water setpoints. The attack exploited FMECA Row 4 (Chiller Compressor Controller) and Row 18 (CRAH Fan), commanding chillers to elevate supply water temperature while reducing fan speeds. Over 1,200 GPUs1{,}200\text{ GPUs} throttled compute execution simultaneously, halting distributed foundation model training runs and inflicting 3.8M USD3.8\text{M USD} in contractual SLA downtime penalties.

5.2 The 2022 Schneider APC UPS Zero-Day (TLStorm)#

Armis Security demonstrated three critical vulnerabilities (CVE-2022-22805, CVE-2022-22806, CVE-2022-0715) affecting Schneider Electric APC Smart-UPS devices. The flaws allowed remote, unauthenticated adversaries to flash malicious firmware over the network management card (NMC). Attackers could manipulate internal inverter gating registers (FMECA Row 7), creating sustained electrical arcing that melted internal lead-acid battery enclosures and physically destroyed the power equipment without tripping upstream circuit breakers.

5.3 CrashOverride / Industroyer (IEC 61850 / IEC 60870-5-104)#

Adversaries in Ukraine deployed custom malware engineered to speak native electrical substation protocols. The malware directly mapped substation circuit breaker objects (FMECA Row 6 and Row 8), forcing rapid cyclic tripping that exhausted transformer insulating oil and drained substation backup battery banks, executing coordinated blackout across regional transmission grids.


6. Systems Assurance#

Engineering Remediations and Quality Gates

To drive cyber RPNs back toward manageable mechanical baselines, systems assurance leads mandate four architectural quality gates:

Four-Stage FMECA Engineering Quality Gates#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram
GateControlEngineering Requirement
1Cryptographic protocol enforcement (IEC 62443-4-2 SL-3)Deprecate cleartext Modbus TCP and BACnet. Enforce TLS 1.3 mutual authentication.
2Hardwired analog safety interlocks (SIL-3)Bi-metallic thermal cutouts and pressure relief bypass all software buses.
3Unidirectional optical telemetry diodesSensor telemetry exported via Tx-only optical diodes (Crev=0.00 bpsC_{\text{rev}} = 0.00\text{ bps}).
4Immutable hardware roots of trustCaliptra 2.0 silicon RoT, DICE device identity, dual-flash recovery.

6.1 Cryptographic Protocol Enforcement (IEC 62443-4-2 SL-3)#

All field controllers, VFDs, and smart sensors must enforce cryptographic message authentication. Unauthenticated Modbus TCP port 502 must be terminated. Where legacy field equipment cannot support native TLS 1.3, deploy hardware bump-in-the-wire FPGA gateways that validate HMAC-SHA256 signatures on all write registers before physical actuation.

6.2 Hardwired Analog Safety Interlocks (SIL-3)#

Software logic ladders must never hold exclusive authority over physical trip envelopes:

  • Bi-Metallic Thermal Cutouts: Snap-action thermal switches mounted directly on cold plate copper heat spreaders, hardwired to server power supply shutoff lines.
  • Pneumatic Pressure Relief: Mechanical spring-loaded relief valves calibrated to 5.5 bar5.5\text{ bar}, mechanically venting fluid before pipe burst limits are reached.
  • Physical Direction Jumpers: VFD motor rotation locked by physical motherboard solder bridges, preventing reverse rotation commands.

7. Actuarial and Underwriting Implications: Catastrophe Risk & PML#

Integrating cyber-physical FMECA into catastrophe models provides reinsurance syndicates with the first quantitative mechanism to underwrite megawatt infrastructure:

Underwriting DimensionTraditional Mechanical UnderwritingCyber-Physical FMECA UnderwritingActuarial & Financial Consequence
Common-Cause AccumulationAssumes N+1 pumps fail independently; low portfolio correlation.Identifies shared PLC firmware and unauthenticated Modbus conduits.Eliminates hidden systemic tail-risk; avoids correlated portfolio insolvency.
Probable Maximum Loss (PML)Based on single component replacement ($50,000 to $150,000).Models coordinated cluster-wide failure cascades ($50,000,000+).Reinsurance capital requirements accurately sized; uncertainty loadings removed.
Lloyd's Y5381 ComplianceDisputed claims during nation-state attacks; severe litigation exposure.Attested SIL-3 hardwired interlocks bound the exploit in hardware, which is an argument a syndicate can inspect rather than a loss statistic.The mandatory state-backed cyber-attack exclusion under Y5381 still applies; the attested evidence gives a syndicate objective grounds to test a disputed attribution claim rather than accept or reject it on assertion.
Deductibles & Sub-LimitsPunitive deductibles ($25M) and restrictive business interruption sub-limits.Dynamic deductibles indexed to continuous FMECA compliance; full replacement cost.Working capital unlocked; affirmative consequential loss coverage preserved.
Parametric TriggersSubjective damage adjusters requiring weeks of onsite surveys.Parametric settlement triggered automatically by cryptographically signed digital twin telemetry.Claims settled in business days; working capital preserved.

8. Summary of Engineering Principles#

Quantitative cyber-physical FMECA establishes five immutable engineering principles:

  1. Cyber Overrides Mechanical Age: A brand-new pump fails instantly when an unauthenticated network command forces it to stop. Operating hours do not measure cyber risk.
  2. Detection Blindness Drives Criticality: The most dangerous exploit is not the one that breaks the machine; it is the one that spoofs telemetry to hide the break while damage accumulates.
  3. Common-Cause Failure Defeats Redundancy: Multiple parallel pumps sharing a single Modbus subnet are not redundant; they are a single distributed point of failure.
  4. Hardware Must Bound Software: Software must never be the sole guardian against software failure. High-consequence hazards must be constrained by analog, hardwired mechanics.
  5. Actuarial Grounding Demands Quantitative Rigor: Risk transfer, insurance underwriting, and capital allocation must be driven by deterministic RPN formulations rather than qualitative compliance checklists.

9. References#

The method applies IEC 60812 for the FMECA procedure. The vulnerability data are the three Armis-disclosed CVE identifiers for the Schneider Electric APC Smart-UPS, given in section 5.2, and the state-backed cyber-attack exclusion applied is Lloyd's Market Bulletin Y5381. The per-accelerator power figure in section 4 is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet.

Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 27,546 chars