Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
RCIL & SCILCyber Risk Underwriting

Treatise 15: Reliability & Safety Critical Items Lists (RCIL / SCIL) for Reinsurance

100% Complete & Untruncated 15 min read
Return to Research Tracks

J. McKenney

This is a working-group treatise in WG-01-UI (Underwriter & Insurance), cited by the group's Concept of Operations and Minimum Operating Requirements treatise as one of the two engineering foundations it builds on. It shares its Gordon-Loeb capital allocation approach and its worked financial figures with the group's ALE/ROSI decision-framework treatise.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

Knowing that equipment can fail is not the same as knowing what to stock, buy, or insure against that failure. This paper sorts every asset in a hyperscale facility into two registers: a Reliability Critical Items List for equipment whose failure degrades uptime, and a stricter Safety Critical Items List whose members can destroy hardware, start a fire, or cause an environmental release. The second register is non-negotiable, requiring physical, hardwired safety interlocks that keep working even if every piece of software in the facility is compromised at once.

The financial argument turns on spare parts and lead times rather than purchase price. A pump that costs little to replace can still be a multi-million-dollar liability when it takes months to obtain and the facility loses revenue daily, and business interruption, not the hardware, dominates the loss. The standard spares math also breaks in a specific way: the usual model assumes each unit fails independently, and a coordinated cyber attack that takes out several redundant units at once violates that assumption by construction, not because of fitted data.

The paper translates both registers into reinsurance treaty language: what a facility with an audited RCIL and SCIL can expect in retention deductibles, business interruption terms, and probable maximum loss against one without either, while stating which of those terms Lloyd's Market Bulletin Y5381 constrains and which it does not.

Abstract#

FMECA and HAZOP identify failure modes but do not procure equipment, establish inventory buffers, or underwrite business interruption policies. The bridge between engineering risk analysis and balance-sheet resilience is formal classification of components into the Reliability Critical Items List (RCIL) and the Safety Critical Items List (SCIL). This paper establishes both registers for hyperscale compute infrastructure, drawing the boundary between reliability-critical components (whose failure degrades availability below contractual SLAs) and safety-critical components (whose failure produces irreversible hardware destruction, arc-flash explosions, or environmental catastrophes). SCIL items are Table B (Extremistan) assets requiring independent, hardwired SIL-3 analog interlocks that operate outside software networks. The paper formalizes the actuarial relationship between long-lead replacement timelines, such as 52-week substation transformer queues and 30-week custom Coolant Distribution Unit (CDU) lead times, and unhedged business interruption exposure. Modeling adversarial common-cause cyber interdictions that destroy redundant units simultaneously, the paper shows where classical Poisson spares models break: the failure is structural, since Poisson sizing assumes independent unit failures and a common-cause interdiction violates that by construction, outside the model's stated domain. We formulate the dynamics of cyber-physical spares optimization, derive optimal capital inventory buffers under Gordon-Loeb constraints, and establish reinsurance treaty structuring criteria that account for Lloyd's Y5381.


1. The Operational Divide Between Reliability and Safety#

Industrial facility managers frequently conflate reliability with safety:

  • Reliability Engineering Focus: Reliability aims to maximize Mean Time Between Failures (MTBF) and minimize unplanned downtime. A component is reliability-critical if its degradation drops facility availability below four-nines (99.99%99.99\%).
  • Safety Engineering Focus: Safety aims to prevent catastrophic physical destruction, fire, personnel injury, and environmental release. A component is safety-critical if its unmitigated failure creates an irreversible physical hazard.

The Structural Taxonomy: RCIL vs. SCIL#

The total industrial facility asset inventory (pumps, valves, switchgear, relays, BMS controllers, inverters, breakers) passes through two successive filters, each of which yields a register:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram
DimensionReliability Critical Items List (RCIL)Safety Critical Items List (SCIL)
Selection filterFailure drops availability below design SLA (99.99%)Failure causes hardware destruction, fire, or injury
Security mandateIEC 62443 Security Level Target (SL-T 2 or SL-T 3)Table B Extremistan asset classification
Procurement / architectural mandateCycloneDX SBOM/HBOM, cryptographic signingIndependent hardwired SIL-3 safety functions
Strict prohibitionNone at this tierSoftware/network can NEVER hold exclusive trip
ExamplesEPMS power meters, chiller PLCs, CRAH fans, UPS NMC cardsCDU direct-to-chip valves, transformer arc relays, gas panel

1.1 The Fundamental Rule of Critical Items Hierarchy#

Every SCIL item is inherently an RCIL item, but not all RCIL items are SCIL items. While an EPMS power monitor failure degrades energy optimization (RCIL), it does not physically rupture high-pressure piping. In contrast, commanding a CDU motorized isolation valve closed while compute silicon dissipates 100 kW100\text{ kW} per rack destroys millions of dollars of compute hardware within seconds (SCIL).


2. Multi-BOM and DEXPI Asset Topology Integration#

To establish an auditable supply-chain and reliability graph, every RCIL and SCIL component is cross-referenced between the DEXPI 2.0 plant piping schematic, classed against the ISO 15926-4 reference data library, and the CycloneDX 1.6+ multi-BOM specification:

Supply Chain and Topology Mapping Graph#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

DEXPI 2.0 physical piping and instrumentation diagram

  • Tag: CDU-PUMP-01A (primary centrifugal variable speed pump)
  • Hydraulic specs: 122 L/min PG25, 4.5 bar head, flanged 316L stainless

CycloneDX 1.6+ multi-BOM component record

BOM layerRecorded content
HBOMVFD inverter silicon, IGBT bridges, microcontroller die
SBOMEmbedded RTOS kernel, Modbus stack, Caliptra silicon RoT
CBOMMutual TLS 1.3 certificates, DICE attestation identity keys
OBOMOperational limits (max 60 Hz, min 15 Hz, max temp rise 2°C/hr)
VEXLive vulnerability tracking feeds (CISA ICS-CERT advisories)

Logistics and reinsurance parameters

  • Replacement lead time: 28 weeks (custom titanium plate heat exchanger)
  • Single-source foundry exposure: TSMC Fab 18 / Infineon Dresden
  • On-site critical spares inventory buffer: 2x complete redundant units

By connecting physical piping nodes to CycloneDX bills of materials, the reliability digital twin identifies supply-chain bottlenecks and component single-source vulnerabilities before procurement contracts are finalized.


3. The Definitive RCIL Register for High-Density Facilities#

The following register documents the critical operational components whose failure threatens facility availability, detailing their target security levels (SL-T) and lead-time replacement exposures:

Table 17.1#

Reliability Critical Items Register (RCIL)

RCIL IDSubsystemComponent NamePrimary Reliability FunctionCyber Attack Failure VectorSL-TLead TimeTypical Vendors
RCIL-P01ElectricalEPMS Power MeterMonitors LV switchgear and phase power balanceRegister spoofing masks phase imbalance, inducing breaker tripSL-216 WksSchneider (ION), Siemens, ABB
RCIL-P02ElectricalSubstation Protection RelayClears medium-voltage utility feeder faultsGOOSE message spoofing delays trip, causing upstream bus arcSL-332 WksSEL, GE Multilin, ABB
RCIL-P03ElectricalUPS Network Card (NMC)Inverter status reporting and remote battery testRansomware flashes corrupted DSP code, dropping inverter bridgeSL-312 WksSchneider (APC), Vertiv, Eaton
RCIL-P04ElectricalAutomatic Transfer SwitchFast source transfer between grid and generatorMalicious transfer command during out-of-phase utility stateSL-224 WksASCO, Cummins, Schneider
RCIL-P05ElectricalBackup Generator ControllerAuto-start and synchronizing on utility collapseRemote stop injection or frequency governor desynchronizationSL-220 WksDEIF, Woodward, ComAp
RCIL-C01CoolingCentral Chiller ControllerStaging centrifugal compressors and VFD speedSetpoint manipulation forces compressor surge or freeze-upSL-242 WksTrane, Carrier, York (JCI)
RCIL-C02CoolingCooling Tower VFDRegulates fan speed for approach temperatureFrequency lock at minimum speed during ambient heatwaveSL-218 WksABB, Danfoss, Siemens
RCIL-C03CoolingSecondary Coolant Flow MeterMeasures primary/secondary heat transfer balanceTelemetry offset spoofing starves cold plates while reporting OKSL-214 WksEndress+Hauser, Krohne
RCIL-C04CoolingCRAH Unit ControllerRegulates fan speed and chilled water valveGroup BACnet command forces CRAH fans to zero RPMSL-216 WksStulz, Vertiv, Schneider
RCIL-M01SupervisoryCentral BMS ServerAggregates all facility SCADA alarms and trendsRansomware encrypts historian and locks operator HMIsSL-24 WksJCI (Metasys), Siemens (Desigo)
RCIL-M02SupervisoryDirect Digital Controller (DDC)Executes local PID control loops on air dampersFirmware overwrite drives actuators against mechanical stopsSL-212 WksDistech, Honeywell, Automated Logic
RCIL-S01SiliconBaseboard Management (BMC)Server power control, thermal telemetry, KVMRedfish API exploit bricks flash ROM across entire clusterSL-326 WksASPEED (AST2600), AMI, OpenBMC

4. The Definitive SCIL Register: High-Consequence Safety Assets#

Components on the Safety Critical Items List are categorized as Table B Extremistan assets. Their failure produces catastrophic loss. Consequently, they are subjected to mandatory hardwired safety invariants:

Table 17.2: Safety Critical Items Register (SCIL)#

SCIL IDNodeComponent NameIrreversible Hazard ConsequenceSoftware Bypass VulnerabilityMandatory Hardwired Safety Invariant
SCIL-01N6CDU Secondary Isolation ValveTotal coolant flow starvation; accelerator silicon reaches its emergency shutdown trip (94∘C94^\circ\text{C})Modbus command injects 0% position while reporting openSpring-return fail-open actuator; mechanical travel stops locked at 40% open.
SCIL-02N6CDU Circulating Pump AssemblyRapid fluid stagnation; water hammer rupture on sudden stopUnauthenticated VFD shutdown drops fluid flow instantaneouslyBi-metallic snap-action thermal cutout switches hardwired to server power supply rails.
SCIL-03N2Block UPS Inverter BridgeElectrical fire; battery DC bus short circuit; explosive arc flashCloud management firmware update corrupts PWM dead-timeFast-acting semiconductor fuses and hardwired mechanical shunt-trip breakers.
SCIL-04N1Substation Synchrocheck RelaySubstation transformer catastrophic explosion (20M+ USD20\text{M+ USD})IEC 61850 SV voltage spoofing forces out-of-phase breaker closureHardwired electromechanical synchrocheck interlock completely isolated from network.
SCIL-05N10Clean Agent Gas SuppressionPremature gas discharge asphyxiates personnel; HVAC shutdownBACnet write command asserts manual discharge solenoidPhysical double-action mechanical pull stations and pneumatic pressure switches.
SCIL-06N14BESS Battery Management SystemThermal runaway propagation; explosive hydrogen releaseModbus command disables cell over-voltage balancing alertsShunt-trip contactor wired directly to analog gas-detection sensors (H2/CO).

5. Mathematical Formulations Governing Critical Spares#

Classical inventory theory models component failure as a Poisson process. However, targeted cyber-physical attacks introduce correlated common-cause failures, breaking classical spares equations.

5.1 Bimodal Failure Probability Density Function#

In an adversarial operating environment, total component failure probability density ftotal(t)f_{\text{total}}(t) is a mixture of stochastic mechanical wear and deterministic cyber exploitation:

ftotal(t)=(1−pattack)⋅λmechexp⁡(−λmecht)+pattack⋅δ(t−texploit)f_{\text{total}}(t) = (1 - p_{\text{attack}}) \cdot \lambda_{\text{mech}} \exp\left(-\lambda_{\text{mech}} t\right) + p_{\text{attack}} \cdot \delta\left(t - t_{\text{exploit}}\right)

Where:

  • λmech\lambda_{\text{mech}} is the constant mechanical failure rate (failures/hour\text{failures/hour}).
  • pattackp_{\text{attack}} is the probability of a targeted cyber campaign against the facility.
  • δ(t−texploit)\delta(t - t_{\text{exploit}}) is the Dirac delta function representing simultaneous failure across all identical devices sharing a common firmware vulnerability.

5.2 Actuarial Business Interruption Single Loss Expectancy (SLEBI\text{SLE}_{\text{BI}})#

When a critical component fails, the Single Loss Expectancy is dominated by the replacement lead time Tlead_timeT_{\text{lead\_time}}:

SLEBI=Chardware+∫0Tlead_timeL˙BI(t) dt\text{SLE}_{\text{BI}} = C_{\text{hardware}} + \int_0^{T_{\text{lead\_time}}} \dot{L}_{\text{BI}}(t) \, dt
SLEBI=Chardware+L˙BI×Tlead_time\text{SLE}_{\text{BI}} = C_{\text{hardware}} + \dot{L}_{\text{BI}} \times T_{\text{lead\_time}}

For a 100 MW high-density AI facility:

  • Unserved compute SLA revenue loss rate: L˙BI=18,500 USD/hour=444,000 USD/day\dot{L}_{\text{BI}} = 18{,}500\text{ USD/hour} = 444{,}000\text{ USD/day}.
  • Custom 4.5 MW chiller compressor lead time: Tlead_time=42 weeks=294 daysT_{\text{lead\_time}} = 42\text{ weeks} = 294\text{ days}.
SLEBI=$1,800,000+($444,000×294)=$1,800,000+$130,536,000=$132,336,000\text{SLE}_{\text{BI}} = \$1{,}800{,}000 + (\$444{,}000 \times 294) = \$1{,}800{,}000 + \$130{,}536{,}000 = \$132{,}336{,}000

The physical asset replacement cost (1.8M USD1.8\text{M USD}) represents only 1.36 percent of the total loss. The remaining 98.64 percent of loss is pure business interruption, demonstrating why managing the RCIL and maintaining on-site strategic spares is the primary actuarial priority.

5.3 Optimal Capital Spares Buffer under Gordon-Loeb Limits#

The optimal capital expenditure dedicated to on-site critical spares inventory Sspares∗S^*_{\text{spares}} is bounded by the Gordon-Loeb theorem:

Sspares∗≤1e⋅(ALEunbuffered−ALEspared)≈0.3679⋅ΔALES^*_{\text{spares}} \le \frac{1}{e} \cdot \left(\text{ALE}_{\text{unbuffered}} - \text{ALE}_{\text{spared}}\right) \approx 0.3679 \cdot \Delta \text{ALE}

Where maintaining on-site cold-standby spares reduces restoration lead time from 42 weeks down to 48 hours (Trestore=2 daysT_{\text{restore}} = 2\text{ days}), slashing Single Loss Expectancy from 132.3M USD132.3\text{M USD} to 2.68M USD2.68\text{M USD}.

5.4 Thermal Catastrophe Velocity Governing Component Trip#

When a CDU pump stops (SCIL-02), the heat transfer rate collapses while high-density accelerator ASICs dissipate intense heat flux:

dTj(t)dt=Pdie−hconv(Q˙(t))⋅Adie⋅(Tj(t)−Tcoolant)Cthermal\frac{dT_j(t)}{dt} = \frac{P_{\text{die}} - h_{\text{conv}}(\dot{Q}(t)) \cdot A_{\text{die}} \cdot (T_j(t) - T_{\text{coolant}})}{C_{\text{thermal}}}

Where:

  • Pdie=1,200 WP_{\text{die}} = 1{,}200\text{ W} per accelerator package, the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU.
  • Volumetric flow collapses from 122 L/min122\text{ L/min} PG25 coolant to zero.
  • Heat flux is 75 W/cm275\text{ W/cm}^2 across the 1,600 mm21{,}600\text{ mm}^2 dual-die package.
  • Cthermal=800 J/KC_{\text{thermal}} = 800\text{ J/K} thermal capacitance of the stagnant cold plate assembly, dominated by the coolant retained in the channels once flow stops.

Junction temperature surges at 1.46∘C/s1.46^\circ\text{C/s} from a nominal 72.5∘C72.5^\circ\text{C}. Within 14.8 seconds14.8\text{ seconds}, silicon junction temperature reaches the 94.0∘C94.0^\circ\text{C} emergency hardware shutdown trip point. Only an analog, hardwired bi-metallic switch operating in <100 milliseconds< 100\text{ milliseconds} can cut electrical power quickly enough to stop the package climbing on toward the 150∘C150^\circ\text{C} organic substrate glass transition region, where irreversible damage begins.

5.5 Return on Security Investment (ROSI) for Strategic Spares#

The financial return on establishing an on-site strategic critical spares depot is quantified as:

ROSIspares=ΔALEspares−CinventoryCinventory×100%\text{ROSI}_{\text{spares}} = \frac{\Delta \text{ALE}_{\text{spares}} - C_{\text{inventory}}}{C_{\text{inventory}}} \times 100\%

For a dedicated spares depot containing two complete CDU pump assemblies and one chiller compressor (Cinventory=650,000 USDC_{\text{inventory}} = 650{,}000\text{ USD}), the annual expected loss reduction is taken as $7,200,000 USD, giving a modeled ROSI=1,007%\text{ROSI} = 1{,}007\% (modeled: the loss reduction and the inventory cost are both working-group estimates, and this paper does not derive the 7,200,0007{,}200{,}000 figure from the registers above; treat it as an assumed input to the ratio).


6. Procurement Assurance and Life-Cycle Quality Gates#

To ensure that components placed on the RCIL and SCIL do not introduce persistent vulnerabilities into the operational plant, procurement teams must enforce four mandatory quality gates:

Four-Stage Procurement Systems Assurance Gates#

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram
GateRequirementMandatory evidence
Gate 1CycloneDX 1.6+ multi-BOM delivery (HBOM / SBOM / CBOM)Machine-readable software and silicon bill of materials
Gate 2Hardware root of trust and attested provenanceCaliptra 2.0 silicon RoT, DICE keys, OpenSIL verified boot chain
Gate 3Independent SIL-3 hardwired analog safety validationThird-party laboratory verification of non-networked physical cutouts
Gate 4Contractual supply chain vulnerability SLAVendor committed 72-hour patch SLA backed by EU CRA Article 13/14 fines

6.1 Gate 1: Mandatory CycloneDX Multi-BOM Ingestion#

Vendors delivering equipment on the RCIL or SCIL must provide certified CycloneDX 1.6+ manifests. The delivery must include an HBOM specifying every microchip, an SBOM listing all firmware libraries, and a CBOM identifying cryptographic certificate algorithms. Equipment delivered without machine-readable BOMs is rejected at the loading dock.

6.2 Gate 2: Silicon Root of Trust Verification#

All programmable controllers and network interface cards must incorporate an immutable hardware root of trust conforming to the OCP S.A.F.E. specification. The controller must execute authenticated firmware verification via Caliptra 2.0 or DICE protocols before initializing network interfaces.

6.3 Gate 3: Physical Safety Function Attestation#

For SCIL assets, the manufacturer must demonstrate physical, non-software fail-safe functionality. Safety interlocks must be verified by an accredited testing laboratory (TUV, UL) under IEC 61508 to achieve Safety Integrity Level 3 (SIL-3) with a Probability of Failure on Demand:

PFDavg∈[10−4,  10−3]\text{PFD}_{\text{avg}} \in [10^{-4}, \; 10^{-3}]

7. Actuarial and Reinsurance Treaty Structuring#

Registers that a syndicate can audit, line by line and against the physical plant, alter the underwriting terms of property catastrophe and business interruption reinsurance treaties. The register is the auditable object; the terms in the table below are a proposed structure for negotiation, and the percentages in the right-hand column are the working group's estimates rather than filed rates:

Treaty Underwriting DimensionFacility Without Formal Critical Items ListsFacility with Audited RCIL / SCIL AssuranceActuarial & Reinsurance Impact
Business Interruption PeriodCalculated against unhedged 42-week OEM lead times; massive rate loadings.Calculated against 48-hour on-site strategic spares replacement window.Premium reduction of 34%; business interruption reserves released.
Systemic Accumulation SurchargeCommon-cause cyber exploit assumed to take down all sister facilities.CycloneDX diversity audit evidences decoupled firmware; conduit isolation is a separate finding and needs a physical network survey.0% portfolio accumulation loading; risk treated as uncorrelated.
Lloyd's Y5381 ComplianceDisputed claims during nation-state campaigns; litigated war exclusions.SIL-3 analog safety interlocks certified by an accredited laboratory bound physical rupture regardless of who issues the command.The state-backed cyber-attack exclusion still applies regardless of hardening; SIL-3 attestation narrows the physical-causation dispute a claim will need, not the coverage determination.
Retention Deductibles & Sub-LimitsPunitive $25,000,000 deductible with strict waiting periods and narrow sub-limits.Dynamic $2,500,000 retention indexed to spares depot audits carried out by the carrier's own surveyor; full replacement cost.Working capital unlocked; affirmative consequential loss coverage preserved.
Probable Maximum Loss (PML)Unhedged PML exceeds $150,000,000 due to unmitigated multi-month lead times.Hardwired SIL-3 limits bound single-event PML below $15,000,000.Treaty capacity unlocked; primary layer attachment rates drop 22%.

8. Summary of Engineering Principles#

Reliability and Safety Critical Items management establishes five immutable engineering principles:

  1. Separate Reliability from Safety: RCIL protects uptime; SCIL protects physical existence. Never treat safety-critical hazards with mere software reliability controls.
  2. Software Must Never Hold Exclusive Safety Authority: Table B assets demand analog, hardwired physical invariants that mechanically enforce safety when software is compromised.
  3. Business Interruption Dwarfs Physical Asset Value: Lead time is the primary driver of loss. An inexpensive pump with a 30-week lead time is a multi-million-dollar financial liability.
  4. Common-Cause Defeats Classical Spares Models: Redundant units that share network firmware are not independent. Spares inventory models must account for simultaneous adversarial interdiction.
  5. Contractual Rigor Drives Balance-Sheet Resilience: Enforcing CycloneDX bills of materials and on-site spares buffers transforms uninsurable cyber-physical tail-risk into an affirmative, underwritten asset class.

9. References#

The method applies IEC 62443-3-2 security level targets, the CycloneDX bill-of-materials specification, the Gordon-Loeb model, and Lloyd's Market Bulletin Y5381. The per-accelerator power figure in section 5 is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet.

Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 24,654 chars