Treatise 13: Quantitative Cyber-Physical FMECA: Failure Mode Analysis for Underwriting
J. McKenney
This paper belongs to the WG-01-UI underwriter-insurance working group alongside WG-01-UI-Physics-Grounded-Cyber-Underwriting, which derives Single Loss Expectancy and Annualized Loss Expectancy from a unified physical and cyber asset graph rather than, as this paper does, from component-level failure-mode scoring; the two are companion treatments of the same underwriting problem rather than entries in a numbered series, and neither names an unpublished sibling.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Reliability engineers rank equipment failure risk with FMECA: for each way a part can fail, they rate its severity, its likelihood, and the chance of catching it in time, then multiply the three into a Risk Priority Number. The method assumes a part fails the way metal and bearings do, gradually, with warning signs a maintenance team can read.
Once a cooling pump or isolation valve joins a network, that assumption breaks. An attacker who can send a command makes the part fail instantly, with no wear and no warning, and can falsify the sensor readings that would otherwise catch the failure early. This paper reworks the scoring and shows, across eighteen pieces of equipment in a modeled data centre, that the cyber version of a failure scores many times higher than its mechanical equivalent. That multiplier comes from expert judgment applied consistently, not from a database of real failures.
The paper then carries the scores through to money: a Risk Priority Number becomes an annual expected loss and a return-on-investment case for a specific fix, such as a hardwired safety interlock a network attacker cannot reach. The loss figures behind that return are the working group's own estimates, not measured losses.
Abstract#
Failure Mode, Effects, and Criticality Analysis (FMECA) under IEC 60812 is the foundational method of industrial reliability engineering, calculating Risk Priority Numbers (RPN) as the product of Severity, Occurrence, and Detection. Traditional FMECA assumes physical components fail through predictable stochastic mechanisms: bearing fatigue, thermal cycling, corrosion, seal wear. This paper establishes the Cyber-Physical Extension to FMECA. When Coolant Distribution Unit pumps, motorized isolation valves, building management controllers, and automatic transfer switches join operational technology networks, they become open to deliberate digital manipulation. An adversary commanding a pump stop or valve closure over unauthenticated Modbus TCP executes the failure instantaneously and spoofs telemetry registers to report nominal states, so Detection drops. Across a modeled eighteen-component register for a 100 MW high-density compute facility, cyber-induced failure modes carry RPNs 4.0x to 40.0x higher than their mechanical equivalents. The multiplier is modeled, not measured: Severity, Occurrence and Detection are analyst-assigned ordinal scores per IEC 60812, scored by the working group rather than drawn from a fleet failure database. The CDU isolation valve escalates from an RPN of 36 to 486. We formulate the Cyber Multiplier Gap, model adversarial Poisson injection failure densities, and give CFOs, reinsurance syndicates, and catastrophe underwriters an actuarial bridge from component RPNs to Annualized Loss Expectancy (ALE), Probable Maximum Loss (PML), and Return on Security Investment (ROSI).
1. The Methodological Limits of Classical FMECA#
Reliability engineers have used FMECA to design offshore oil platforms, aerospace flight control systems, and high-speed rail corridors. The methodology assigns quantitative ratings from 1 to 10 across three independent dimensions:
- Severity (S): The magnitude of physical damage, life-safety hazard, or business disruption resulting from the failure mode.
- Occurrence (O): The statistical frequency or probability of the failure mode occurring during the operational lifetime of the asset.
- Detection (D): The likelihood that existing monitoring systems, sensor alarms, or maintenance inspections will detect the failure condition before catastrophic damage manifests. In classical reliability scales, a rating of 1 represents instantaneous automated detection, while a rating of 10 represents complete undetectable latency.
This is not the only hazard analysis in this programme and the two should not be confused. The Threat Modeling working group's CyHAZOP Methodology extends IEC 61882 rather than IEC 60812, and the difference is the direction of the study: CyHAZOP starts from a node and a deviation guide word, NO, LESS, MORE, REVERSE and the rest, and asks what deviations the node can suffer, while this paper starts from a component and asks how that component fails and what the failure costs. A guide-word study finds deviations that no single component failure produces, and a criticality study ranks components for a budget, which a guide-word study cannot do because it does not produce a per-component number. Neither substitutes for the other, and a facility that has run only one of them has an analysis with a known-shaped hole in it.
1.1 The Mechanical Baseline Assumption#
Classical FMECA calculates Occurrence from Mean Time Between Failure (MTBF) tables derived from decades of operational field data. A centrifugal pump impeller bearing wears out after 50,000 to 80,000 operating hours. This degradation is preceded by measurable physical warning signs: elevated acoustic vibration, temperature rise across bearing housings, and lubricating oil particulate accumulation. Standard supervisory SCADA systems detect these anomalies weeks before mechanical seizure occurs, yielding low Occurrence ratings () and favorable Detection ratings (). The resulting mechanical RPN remains comfortably below 60.
1.2 The Cyber-Physical Reality#
When the same centrifugal pump is orchestrated by a Variable Frequency Drive connected to an unauthenticated facility network, the reliability model fractures:
- Occurrence Inversion: The failure is no longer constrained by mechanical wear physics. A remote threat actor with network access can command the pump to stop at any arbitrary second ().
- Detection Blindness: A skilled adversary does not simply send a stop command; they exploit the two-way nature of the industrial protocol to overwrite holding registers, spoofing nominal rotational speed and normal fluid flow back to the operator console ().
- Common-Cause Synchronicity: While mechanical bearing seizures are uncorrelated stochastic events, a single malicious script can command all redundant CDU pumps across an entire data hall to trip simultaneously, completely defeating parallel N+1 and 2N redundancy architectures.
2. Multi-BOM and DEXPI Structural Mapping#
To execute automated cyber-physical FMECA within the Cyber Digital Twin, every failure mode is cross-referenced between the DEXPI 2.0 plant schematic, classed against the ISO 15926-4 reference data library, and the CycloneDX 1.6+ multi-BOM catalog:
Cyber-Physical FMECA Graph Topology#
| Graph Layer | Bound Entities | Attributes Carried on the Node |
|---|---|---|
| DEXPI 2.0 mechanical asset | CDU-PUMP-01, VALVE-V102, MANIFOLD-R04 | Hydraulic properties: PG25 coolant, design flow , head loss |
| Industrial control conduit | Modbus TCP port 502, BACnet/IP UDP 47808 | Registers 40101 (state), 40102 (speed), 40104 (valve), 30201 (flow) |
| CycloneDX 1.6+ multi-BOM specification | HBOM, SBOM, CBOM, OBOM, VEX | Itemized in the table below |
| Multi-BOM | Catalogd Contents |
|---|---|
| HBOM | OCP ORV3 trays, Samtec connectors, Caliptra silicon RoT |
| SBOM | OpenBMC Linux kernel, Caliptra mask ROM, OpenSIL firmware |
| CBOM | DICE cryptographic certificates, post-quantum ML-DSA keys |
| OBOM | Hardware rate limits (), thermal trip limits () |
| VEX | Machine-readable vulnerability disclosures (CVE status) |
By linking active CycloneDX VEX vulnerability feeds to physical DEXPI asset nodes, the digital twin automatically recalculates component RPNs when a new unpatched remote code execution vulnerability is discovered in an operational technology controller.
3. The Quantitative Cyber-Physical FMECA Matrix#
The following comprehensive table documents eighteen critical infrastructure components across cooling, electrical distribution, building management, and compute silicon. It compares traditional mechanical failure modes against cyber-induced vectors, exposing the massive Cyber Multiplier Gap:
The Eigenia Dual-RPN Cyber-Physical FMECA Master Table#
| Component | Physical Failure Mode | Traditional Mechanical Cause | Cyber-Physical Attack Vector | S | Cyber Multiplier | ||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| CDU Pump Assembly | Catastrophic flow cessation | Bearing seizure; VFD DC-bus capacitor failure | Unauthenticated Modbus write forces pump stop register 40101 | 9 | 3 | 7 | 2 | 9 | 54 | 567 | 10.5x |
| CDU Motorized Valve | Valve fails fully closed | Actuator motor burn; mechanical stem binding | Attacker commands 15% position via BMS while spoofing open status | 9 | 2 | 6 | 2 | 9 | 36 | 486 | 13.5x |
| CDU Temp Transmitter | False low reading during runaway | Thermocouple calibration drift; open wire | Modbus offset register overwritten; false reported | 7 | 2 | 6 | 3 | 8 | 42 | 336 | 8.0x |
| Chiller Compressor | Compressor shutdown | Refrigerant leak; motor thermal overload | BACnet shutdown command injected to chiller PLC | 8 | 2 | 5 | 2 | 7 | 32 | 280 | 8.75x |
| Cooling Tower Fan VFD | Fan locked at minimum speed | VFD gate driver failure; motor bearing wear | VFD maximum frequency register set to via Modbus | 6 | 3 | 6 | 3 | 8 | 54 | 288 | 5.3x |
| Static Transfer Switch | Both infeed breakers forced open | Solenoid failure; logic board lockup | Web interface exploit commands force-open on both feeds | 10 | 1 | 5 | 1 | 8 | 10 | 400 | 40.0x |
| Block UPS Module | Inverter bridge shutdown | IGBT thermal breakdown; DC capacitor short | Cloud management firmware update bricks inverter DSP | 9 | 2 | 6 | 2 | 8 | 36 | 432 | 12.0x |
| Substation Transformer | Dielectric breakdown / fire | Oil contamination; insulation aging | Synchrocheck phase spoofing forces out-of-phase closure | 10 | 1 | 4 | 2 | 9 | 20 | 360 | 18.0x |
| 48V DC Busbar Rectifier | Output voltage collapse | Power diode short; over-temperature trip | PMBus over-voltage injection causes internal crowbar shutdown | 8 | 2 | 5 | 2 | 7 | 32 | 280 | 8.75x |
| Facility BMS Controller | Supervisory logic lockup | Memory leak in firmware; power glitch | Ransomware encrypts central BACnet supervisory server | 8 | 2 | 7 | 2 | 6 | 32 | 336 | 10.5x |
| Gas Suppression Panel | Inadvertent clean-agent release | False smoke sensor reading; lightning strike | BACnet write command asserts manual discharge solenoid | 9 | 1 | 5 | 2 | 7 | 18 | 315 | 17.5x |
| Smoke Purge Damper | Damper fails closed in fire | Actuator spring break; pneumatic pressure loss | BMS override forces smoke damper closed during fire event | 8 | 2 | 5 | 3 | 8 | 48 | 320 | 6.7x |
| Water Treatment Dosing | Coolant chemical fouling | Dosing pump blockage; chemical reservoir empty | Attacker disables biocide dosing via facility PLC interface | 6 | 3 | 6 | 4 | 8 | 72 | 288 | 4.0x |
| Server BMC (AST2600) | Chassis power kill / bricking | SPI flash solder fatigue; VRM overheating | Unauthenticated Redfish API flashes corrupted firmware image | 9 | 2 | 7 | 2 | 8 | 36 | 504 | 14.0x |
| Silicon VRM Controller | Over-voltage gate oxide punch | SMT capacitor cracking; PWM loop drift | I2C command overrides voltage limit to | 10 | 1 | 5 | 2 | 9 | 20 | 450 | 22.5x |
| Grid-Tie BESS Inverter | Uncontrolled utility backfeed | Inverter sync loss; contactor mechanical weld | Modbus command disables anti-islanding safety routine | 9 | 1 | 4 | 2 | 9 | 18 | 324 | 18.0x |
| Cold Plate QD Fitting | O-ring seal rupture / leak | Elastomer degradation; mechanical misalignment | Rapid pump start water hammer surges pressure to | 8 | 3 | 6 | 3 | 8 | 72 | 384 | 5.3x |
| CRAH Air Handling Fan | Total airflow loss | Belt snap; motor winding short | BACnet group command forces all air handling fans to | 7 | 3 | 6 | 2 | 7 | 42 | 294 | 7.0x |
4. Quantitative Formulations Governing Cyber-Physical Risk#
To ground cyber-physical FMECA in rigorous applied physics and financial actuarial science, the methodology is governed by five mathematical formulations.
4.1 The Dual-RPN Formulation and Cyber Multiplier Gap#
For any given physical asset , the classical mechanical Risk Priority Number and the cyber-induced Risk Priority Number are defined as:
The Cyber Multiplier Gap , representing the relative risk expansion factor, is formulated as:
Across the critical infrastructure nodes scored in this paper, ranges from (Water Treatment Dosing, ) to (Static Transfer Switch, ). That range is the ratio of two sets of assigned ordinal scores, so it is a modeled spread rather than a measured one. It carries a clear implication: allocating maintenance budgets on mechanical MTBF data alone misallocates capital and leaves the primary attack vectors undefended.
4.2 Adversarial Non-Random Failure Probability Density#
Traditional reliability engineering assumes component time-to-failure follows an exponential or Weibull distribution governed by a constant hazard rate . In the presence of targeted cyber attacks, the total failure probability density function becomes a bimodal mixture distribution:
Where:
- is the probability that an adversary targets the facility OT network during operating interval .
- is the Dirac delta function representing an instantaneous, non-random failure triggered at the attacker's chosen time .
Because is correlated across multiple redundant units, the probability of simultaneous multi-unit failure ceases to be the product of independent failure probabilities (). Instead, it scales directly with adversary capability:
4.3 Transient Thermal Dissipation Collapse under Valve Throttling#
When a motorized isolation valve (FMECA Row 2) is commanded closed via Modbus TCP, the volumetric liquid flow rate collapses. The transient temperature rise of the accelerator silicon die is governed by:
Where:
- compute dissipation per accelerator package, the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU.
- collapses from nominal PG25 to . The channel Reynolds number at design flow is approximately 380, so the cold plate runs laminar and is the laminar rectangular-duct value, not a turbulent correlation.
- thermal capacitance of the stagnant cold plate assembly, dominated by the coolant retained in the channels once flow stops.
Within , silicon junction temperature rises at from a nominal to the emergency hardware shutdown trip point, and the protection removes power from the tray before human operators can verify alarm authenticity.
4.4 Actuarial Consequence & Annualized Loss Expectancy (ALE)#
To translate FMECA RPN scores into insurance capital requirements, the Annualized Loss Expectancy () for each failure mode is formulated as:
Where:
- is the Single Loss Expectancy.
- is the calibrated Annualized Rate of Occurrence derived from the cyber RPN score.
- is the capital equipment replacement cost (such as $120,000 per ruined accelerator compute tray).
- is the unserved SLA revenue loss rate ($18,500 per hour).
- is the supply-chain restoration lead time governed by the Reliability Critical Items List (RCIL).
4.5 Return on Security Investment (ROSI) Prioritized by RPN Delta#
The financial justification for implementing engineering safeguards is determined by the net reduction in Annualized Loss Expectancy divided by control cost:
For the CDU isolation valve (Row 2), implementing a hardwired mechanical limit switch and cryptographic Modbus MAC verification () reduces from to , lowering annual loss expectancy from $1,450,000 to $18,000, giving a modeled (modeled: both loss expectancies and the control cost are working-group estimates, and the calibration constant linking to is not stated anywhere in this paper).
5. Failure Case Studies#
One Named Incident and One Anonymous Report
The high cyber RPNs documented in this paper follow from vulnerability mechanics that are separately attested in two case studies of unequal strength. Section 5.2 names the vendor, the researcher and three CVE identifiers, so a reader can check it. Section 5.1 names no operator, no date beyond the year and no public report, so a reader cannot; it is retained as an illustrative account, not as evidence:
5.1 The 2024 High-Density AI Colocation Colling Incident#
A 40 MW high-density compute facility in the Asia-Pacific region experienced a cluster-wide thermal shutdown when an adversary used unauthenticated BACnet write commands to manipulate chilled water setpoints. The attack exploited FMECA Row 4 (Chiller Compressor Controller) and Row 18 (CRAH Fan), commanding chillers to elevate supply water temperature while reducing fan speeds. Over throttled compute execution simultaneously, halting distributed foundation model training runs and inflicting in contractual SLA downtime penalties.
5.2 The 2022 Schneider APC UPS Zero-Day (TLStorm)#
Armis Security demonstrated three critical vulnerabilities (CVE-2022-22805, CVE-2022-22806, CVE-2022-0715) affecting Schneider Electric APC Smart-UPS devices. The flaws allowed remote, unauthenticated adversaries to flash malicious firmware over the network management card (NMC). Attackers could manipulate internal inverter gating registers (FMECA Row 7), creating sustained electrical arcing that melted internal lead-acid battery enclosures and physically destroyed the power equipment without tripping upstream circuit breakers.
5.3 CrashOverride / Industroyer (IEC 61850 / IEC 60870-5-104)#
Adversaries in Ukraine deployed custom malware engineered to speak native electrical substation protocols. The malware directly mapped substation circuit breaker objects (FMECA Row 6 and Row 8), forcing rapid cyclic tripping that exhausted transformer insulating oil and drained substation backup battery banks, executing coordinated blackout across regional transmission grids.
6. Systems Assurance#
Engineering Remediations and Quality Gates
To drive cyber RPNs back toward manageable mechanical baselines, systems assurance leads mandate four architectural quality gates:
Four-Stage FMECA Engineering Quality Gates#
| Gate | Control | Engineering Requirement |
|---|---|---|
| 1 | Cryptographic protocol enforcement (IEC 62443-4-2 SL-3) | Deprecate cleartext Modbus TCP and BACnet. Enforce TLS 1.3 mutual authentication. |
| 2 | Hardwired analog safety interlocks (SIL-3) | Bi-metallic thermal cutouts and pressure relief bypass all software buses. |
| 3 | Unidirectional optical telemetry diodes | Sensor telemetry exported via Tx-only optical diodes (). |
| 4 | Immutable hardware roots of trust | Caliptra 2.0 silicon RoT, DICE device identity, dual-flash recovery. |
6.1 Cryptographic Protocol Enforcement (IEC 62443-4-2 SL-3)#
All field controllers, VFDs, and smart sensors must enforce cryptographic message authentication. Unauthenticated Modbus TCP port 502 must be terminated. Where legacy field equipment cannot support native TLS 1.3, deploy hardware bump-in-the-wire FPGA gateways that validate HMAC-SHA256 signatures on all write registers before physical actuation.
6.2 Hardwired Analog Safety Interlocks (SIL-3)#
Software logic ladders must never hold exclusive authority over physical trip envelopes:
- Bi-Metallic Thermal Cutouts: Snap-action thermal switches mounted directly on cold plate copper heat spreaders, hardwired to server power supply shutoff lines.
- Pneumatic Pressure Relief: Mechanical spring-loaded relief valves calibrated to , mechanically venting fluid before pipe burst limits are reached.
- Physical Direction Jumpers: VFD motor rotation locked by physical motherboard solder bridges, preventing reverse rotation commands.
7. Actuarial and Underwriting Implications: Catastrophe Risk & PML#
Integrating cyber-physical FMECA into catastrophe models provides reinsurance syndicates with the first quantitative mechanism to underwrite megawatt infrastructure:
| Underwriting Dimension | Traditional Mechanical Underwriting | Cyber-Physical FMECA Underwriting | Actuarial & Financial Consequence |
|---|---|---|---|
| Common-Cause Accumulation | Assumes N+1 pumps fail independently; low portfolio correlation. | Identifies shared PLC firmware and unauthenticated Modbus conduits. | Eliminates hidden systemic tail-risk; avoids correlated portfolio insolvency. |
| Probable Maximum Loss (PML) | Based on single component replacement ($50,000 to $150,000). | Models coordinated cluster-wide failure cascades ($50,000,000+). | Reinsurance capital requirements accurately sized; uncertainty loadings removed. |
| Lloyd's Y5381 Compliance | Disputed claims during nation-state attacks; severe litigation exposure. | Attested SIL-3 hardwired interlocks bound the exploit in hardware, which is an argument a syndicate can inspect rather than a loss statistic. | The mandatory state-backed cyber-attack exclusion under Y5381 still applies; the attested evidence gives a syndicate objective grounds to test a disputed attribution claim rather than accept or reject it on assertion. |
| Deductibles & Sub-Limits | Punitive deductibles ($25M) and restrictive business interruption sub-limits. | Dynamic deductibles indexed to continuous FMECA compliance; full replacement cost. | Working capital unlocked; affirmative consequential loss coverage preserved. |
| Parametric Triggers | Subjective damage adjusters requiring weeks of onsite surveys. | Parametric settlement triggered automatically by cryptographically signed digital twin telemetry. | Claims settled in business days; working capital preserved. |
8. Summary of Engineering Principles#
Quantitative cyber-physical FMECA establishes five immutable engineering principles:
- Cyber Overrides Mechanical Age: A brand-new pump fails instantly when an unauthenticated network command forces it to stop. Operating hours do not measure cyber risk.
- Detection Blindness Drives Criticality: The most dangerous exploit is not the one that breaks the machine; it is the one that spoofs telemetry to hide the break while damage accumulates.
- Common-Cause Failure Defeats Redundancy: Multiple parallel pumps sharing a single Modbus subnet are not redundant; they are a single distributed point of failure.
- Hardware Must Bound Software: Software must never be the sole guardian against software failure. High-consequence hazards must be constrained by analog, hardwired mechanics.
- Actuarial Grounding Demands Quantitative Rigor: Risk transfer, insurance underwriting, and capital allocation must be driven by deterministic RPN formulations rather than qualitative compliance checklists.
9. References#
The method applies IEC 60812 for the FMECA procedure. The vulnerability data are the three Armis-disclosed CVE identifiers for the Schneider Electric APC Smart-UPS, given in section 5.2, and the state-backed cyber-attack exclusion applied is Lloyd's Market Bulletin Y5381. The per-accelerator power figure in section 4 is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet.