Treatise 15: Reliability & Safety Critical Items Lists (RCIL / SCIL) for Reinsurance
J. McKenney
This is a working-group treatise in WG-01-UI (Underwriter & Insurance), cited by the group's Concept of Operations and Minimum Operating Requirements treatise as one of the two engineering foundations it builds on. It shares its Gordon-Loeb capital allocation approach and its worked financial figures with the group's ALE/ROSI decision-framework treatise.
Licence: CC BY 4.0. 17 September 2026.
Executive Abstract#
Knowing that equipment can fail is not the same as knowing what to stock, buy, or insure against that failure. This paper sorts every asset in a hyperscale facility into two registers: a Reliability Critical Items List for equipment whose failure degrades uptime, and a stricter Safety Critical Items List whose members can destroy hardware, start a fire, or cause an environmental release. The second register is non-negotiable, requiring physical, hardwired safety interlocks that keep working even if every piece of software in the facility is compromised at once.
The financial argument turns on spare parts and lead times rather than purchase price. A pump that costs little to replace can still be a multi-million-dollar liability when it takes months to obtain and the facility loses revenue daily, and business interruption, not the hardware, dominates the loss. The standard spares math also breaks in a specific way: the usual model assumes each unit fails independently, and a coordinated cyber attack that takes out several redundant units at once violates that assumption by construction, not because of fitted data.
The paper translates both registers into reinsurance treaty language: what a facility with an audited RCIL and SCIL can expect in retention deductibles, business interruption terms, and probable maximum loss against one without either, while stating which of those terms Lloyd's Market Bulletin Y5381 constrains and which it does not.
Abstract#
FMECA and HAZOP identify failure modes but do not procure equipment, establish inventory buffers, or underwrite business interruption policies. The bridge between engineering risk analysis and balance-sheet resilience is formal classification of components into the Reliability Critical Items List (RCIL) and the Safety Critical Items List (SCIL). This paper establishes both registers for hyperscale compute infrastructure, drawing the boundary between reliability-critical components (whose failure degrades availability below contractual SLAs) and safety-critical components (whose failure produces irreversible hardware destruction, arc-flash explosions, or environmental catastrophes). SCIL items are Table B (Extremistan) assets requiring independent, hardwired SIL-3 analog interlocks that operate outside software networks. The paper formalizes the actuarial relationship between long-lead replacement timelines, such as 52-week substation transformer queues and 30-week custom Coolant Distribution Unit (CDU) lead times, and unhedged business interruption exposure. Modeling adversarial common-cause cyber interdictions that destroy redundant units simultaneously, the paper shows where classical Poisson spares models break: the failure is structural, since Poisson sizing assumes independent unit failures and a common-cause interdiction violates that by construction, outside the model's stated domain. We formulate the dynamics of cyber-physical spares optimization, derive optimal capital inventory buffers under Gordon-Loeb constraints, and establish reinsurance treaty structuring criteria that account for Lloyd's Y5381.
1. The Operational Divide Between Reliability and Safety#
Industrial facility managers frequently conflate reliability with safety:
- Reliability Engineering Focus: Reliability aims to maximize Mean Time Between Failures (MTBF) and minimize unplanned downtime. A component is reliability-critical if its degradation drops facility availability below four-nines ().
- Safety Engineering Focus: Safety aims to prevent catastrophic physical destruction, fire, personnel injury, and environmental release. A component is safety-critical if its unmitigated failure creates an irreversible physical hazard.
The Structural Taxonomy: RCIL vs. SCIL#
The total industrial facility asset inventory (pumps, valves, switchgear, relays, BMS controllers, inverters, breakers) passes through two successive filters, each of which yields a register:
| Dimension | Reliability Critical Items List (RCIL) | Safety Critical Items List (SCIL) |
|---|---|---|
| Selection filter | Failure drops availability below design SLA (99.99%) | Failure causes hardware destruction, fire, or injury |
| Security mandate | IEC 62443 Security Level Target (SL-T 2 or SL-T 3) | Table B Extremistan asset classification |
| Procurement / architectural mandate | CycloneDX SBOM/HBOM, cryptographic signing | Independent hardwired SIL-3 safety functions |
| Strict prohibition | None at this tier | Software/network can NEVER hold exclusive trip |
| Examples | EPMS power meters, chiller PLCs, CRAH fans, UPS NMC cards | CDU direct-to-chip valves, transformer arc relays, gas panel |
1.1 The Fundamental Rule of Critical Items Hierarchy#
Every SCIL item is inherently an RCIL item, but not all RCIL items are SCIL items. While an EPMS power monitor failure degrades energy optimization (RCIL), it does not physically rupture high-pressure piping. In contrast, commanding a CDU motorized isolation valve closed while compute silicon dissipates per rack destroys millions of dollars of compute hardware within seconds (SCIL).
2. Multi-BOM and DEXPI Asset Topology Integration#
To establish an auditable supply-chain and reliability graph, every RCIL and SCIL component is cross-referenced between the DEXPI 2.0 plant piping schematic, classed against the ISO 15926-4 reference data library, and the CycloneDX 1.6+ multi-BOM specification:
Supply Chain and Topology Mapping Graph#
DEXPI 2.0 physical piping and instrumentation diagram
- Tag: CDU-PUMP-01A (primary centrifugal variable speed pump)
- Hydraulic specs: 122 L/min PG25, 4.5 bar head, flanged 316L stainless
CycloneDX 1.6+ multi-BOM component record
| BOM layer | Recorded content |
|---|---|
| HBOM | VFD inverter silicon, IGBT bridges, microcontroller die |
| SBOM | Embedded RTOS kernel, Modbus stack, Caliptra silicon RoT |
| CBOM | Mutual TLS 1.3 certificates, DICE attestation identity keys |
| OBOM | Operational limits (max 60 Hz, min 15 Hz, max temp rise 2°C/hr) |
| VEX | Live vulnerability tracking feeds (CISA ICS-CERT advisories) |
Logistics and reinsurance parameters
- Replacement lead time: 28 weeks (custom titanium plate heat exchanger)
- Single-source foundry exposure: TSMC Fab 18 / Infineon Dresden
- On-site critical spares inventory buffer: 2x complete redundant units
By connecting physical piping nodes to CycloneDX bills of materials, the reliability digital twin identifies supply-chain bottlenecks and component single-source vulnerabilities before procurement contracts are finalized.
3. The Definitive RCIL Register for High-Density Facilities#
The following register documents the critical operational components whose failure threatens facility availability, detailing their target security levels (SL-T) and lead-time replacement exposures:
Table 17.1#
Reliability Critical Items Register (RCIL)
| RCIL ID | Subsystem | Component Name | Primary Reliability Function | Cyber Attack Failure Vector | SL-T | Lead Time | Typical Vendors |
|---|---|---|---|---|---|---|---|
| RCIL-P01 | Electrical | EPMS Power Meter | Monitors LV switchgear and phase power balance | Register spoofing masks phase imbalance, inducing breaker trip | SL-2 | 16 Wks | Schneider (ION), Siemens, ABB |
| RCIL-P02 | Electrical | Substation Protection Relay | Clears medium-voltage utility feeder faults | GOOSE message spoofing delays trip, causing upstream bus arc | SL-3 | 32 Wks | SEL, GE Multilin, ABB |
| RCIL-P03 | Electrical | UPS Network Card (NMC) | Inverter status reporting and remote battery test | Ransomware flashes corrupted DSP code, dropping inverter bridge | SL-3 | 12 Wks | Schneider (APC), Vertiv, Eaton |
| RCIL-P04 | Electrical | Automatic Transfer Switch | Fast source transfer between grid and generator | Malicious transfer command during out-of-phase utility state | SL-2 | 24 Wks | ASCO, Cummins, Schneider |
| RCIL-P05 | Electrical | Backup Generator Controller | Auto-start and synchronizing on utility collapse | Remote stop injection or frequency governor desynchronization | SL-2 | 20 Wks | DEIF, Woodward, ComAp |
| RCIL-C01 | Cooling | Central Chiller Controller | Staging centrifugal compressors and VFD speed | Setpoint manipulation forces compressor surge or freeze-up | SL-2 | 42 Wks | Trane, Carrier, York (JCI) |
| RCIL-C02 | Cooling | Cooling Tower VFD | Regulates fan speed for approach temperature | Frequency lock at minimum speed during ambient heatwave | SL-2 | 18 Wks | ABB, Danfoss, Siemens |
| RCIL-C03 | Cooling | Secondary Coolant Flow Meter | Measures primary/secondary heat transfer balance | Telemetry offset spoofing starves cold plates while reporting OK | SL-2 | 14 Wks | Endress+Hauser, Krohne |
| RCIL-C04 | Cooling | CRAH Unit Controller | Regulates fan speed and chilled water valve | Group BACnet command forces CRAH fans to zero RPM | SL-2 | 16 Wks | Stulz, Vertiv, Schneider |
| RCIL-M01 | Supervisory | Central BMS Server | Aggregates all facility SCADA alarms and trends | Ransomware encrypts historian and locks operator HMIs | SL-2 | 4 Wks | JCI (Metasys), Siemens (Desigo) |
| RCIL-M02 | Supervisory | Direct Digital Controller (DDC) | Executes local PID control loops on air dampers | Firmware overwrite drives actuators against mechanical stops | SL-2 | 12 Wks | Distech, Honeywell, Automated Logic |
| RCIL-S01 | Silicon | Baseboard Management (BMC) | Server power control, thermal telemetry, KVM | Redfish API exploit bricks flash ROM across entire cluster | SL-3 | 26 Wks | ASPEED (AST2600), AMI, OpenBMC |
4. The Definitive SCIL Register: High-Consequence Safety Assets#
Components on the Safety Critical Items List are categorized as Table B Extremistan assets. Their failure produces catastrophic loss. Consequently, they are subjected to mandatory hardwired safety invariants:
Table 17.2: Safety Critical Items Register (SCIL)#
| SCIL ID | Node | Component Name | Irreversible Hazard Consequence | Software Bypass Vulnerability | Mandatory Hardwired Safety Invariant |
|---|---|---|---|---|---|
| SCIL-01 | N6 | CDU Secondary Isolation Valve | Total coolant flow starvation; accelerator silicon reaches its emergency shutdown trip () | Modbus command injects 0% position while reporting open | Spring-return fail-open actuator; mechanical travel stops locked at 40% open. |
| SCIL-02 | N6 | CDU Circulating Pump Assembly | Rapid fluid stagnation; water hammer rupture on sudden stop | Unauthenticated VFD shutdown drops fluid flow instantaneously | Bi-metallic snap-action thermal cutout switches hardwired to server power supply rails. |
| SCIL-03 | N2 | Block UPS Inverter Bridge | Electrical fire; battery DC bus short circuit; explosive arc flash | Cloud management firmware update corrupts PWM dead-time | Fast-acting semiconductor fuses and hardwired mechanical shunt-trip breakers. |
| SCIL-04 | N1 | Substation Synchrocheck Relay | Substation transformer catastrophic explosion () | IEC 61850 SV voltage spoofing forces out-of-phase breaker closure | Hardwired electromechanical synchrocheck interlock completely isolated from network. |
| SCIL-05 | N10 | Clean Agent Gas Suppression | Premature gas discharge asphyxiates personnel; HVAC shutdown | BACnet write command asserts manual discharge solenoid | Physical double-action mechanical pull stations and pneumatic pressure switches. |
| SCIL-06 | N14 | BESS Battery Management System | Thermal runaway propagation; explosive hydrogen release | Modbus command disables cell over-voltage balancing alerts | Shunt-trip contactor wired directly to analog gas-detection sensors (H2/CO). |
5. Mathematical Formulations Governing Critical Spares#
Classical inventory theory models component failure as a Poisson process. However, targeted cyber-physical attacks introduce correlated common-cause failures, breaking classical spares equations.
5.1 Bimodal Failure Probability Density Function#
In an adversarial operating environment, total component failure probability density is a mixture of stochastic mechanical wear and deterministic cyber exploitation:
Where:
- is the constant mechanical failure rate ().
- is the probability of a targeted cyber campaign against the facility.
- is the Dirac delta function representing simultaneous failure across all identical devices sharing a common firmware vulnerability.
5.2 Actuarial Business Interruption Single Loss Expectancy ()#
When a critical component fails, the Single Loss Expectancy is dominated by the replacement lead time :
For a 100 MW high-density AI facility:
- Unserved compute SLA revenue loss rate: .
- Custom 4.5 MW chiller compressor lead time: .
The physical asset replacement cost () represents only 1.36 percent of the total loss. The remaining 98.64 percent of loss is pure business interruption, demonstrating why managing the RCIL and maintaining on-site strategic spares is the primary actuarial priority.
5.3 Optimal Capital Spares Buffer under Gordon-Loeb Limits#
The optimal capital expenditure dedicated to on-site critical spares inventory is bounded by the Gordon-Loeb theorem:
Where maintaining on-site cold-standby spares reduces restoration lead time from 42 weeks down to 48 hours (), slashing Single Loss Expectancy from to .
5.4 Thermal Catastrophe Velocity Governing Component Trip#
When a CDU pump stops (SCIL-02), the heat transfer rate collapses while high-density accelerator ASICs dissipate intense heat flux:
Where:
- per accelerator package, the configurable maximum NVIDIA publishes for a GB200-class Blackwell GPU.
- Volumetric flow collapses from PG25 coolant to zero.
- Heat flux is across the dual-die package.
- thermal capacitance of the stagnant cold plate assembly, dominated by the coolant retained in the channels once flow stops.
Junction temperature surges at from a nominal . Within , silicon junction temperature reaches the emergency hardware shutdown trip point. Only an analog, hardwired bi-metallic switch operating in can cut electrical power quickly enough to stop the package climbing on toward the organic substrate glass transition region, where irreversible damage begins.
5.5 Return on Security Investment (ROSI) for Strategic Spares#
The financial return on establishing an on-site strategic critical spares depot is quantified as:
For a dedicated spares depot containing two complete CDU pump assemblies and one chiller compressor (), the annual expected loss reduction is taken as $7,200,000 USD, giving a modeled (modeled: the loss reduction and the inventory cost are both working-group estimates, and this paper does not derive the figure from the registers above; treat it as an assumed input to the ratio).
6. Procurement Assurance and Life-Cycle Quality Gates#
To ensure that components placed on the RCIL and SCIL do not introduce persistent vulnerabilities into the operational plant, procurement teams must enforce four mandatory quality gates:
Four-Stage Procurement Systems Assurance Gates#
| Gate | Requirement | Mandatory evidence |
|---|---|---|
| Gate 1 | CycloneDX 1.6+ multi-BOM delivery (HBOM / SBOM / CBOM) | Machine-readable software and silicon bill of materials |
| Gate 2 | Hardware root of trust and attested provenance | Caliptra 2.0 silicon RoT, DICE keys, OpenSIL verified boot chain |
| Gate 3 | Independent SIL-3 hardwired analog safety validation | Third-party laboratory verification of non-networked physical cutouts |
| Gate 4 | Contractual supply chain vulnerability SLA | Vendor committed 72-hour patch SLA backed by EU CRA Article 13/14 fines |
6.1 Gate 1: Mandatory CycloneDX Multi-BOM Ingestion#
Vendors delivering equipment on the RCIL or SCIL must provide certified CycloneDX 1.6+ manifests. The delivery must include an HBOM specifying every microchip, an SBOM listing all firmware libraries, and a CBOM identifying cryptographic certificate algorithms. Equipment delivered without machine-readable BOMs is rejected at the loading dock.
6.2 Gate 2: Silicon Root of Trust Verification#
All programmable controllers and network interface cards must incorporate an immutable hardware root of trust conforming to the OCP S.A.F.E. specification. The controller must execute authenticated firmware verification via Caliptra 2.0 or DICE protocols before initializing network interfaces.
6.3 Gate 3: Physical Safety Function Attestation#
For SCIL assets, the manufacturer must demonstrate physical, non-software fail-safe functionality. Safety interlocks must be verified by an accredited testing laboratory (TUV, UL) under IEC 61508 to achieve Safety Integrity Level 3 (SIL-3) with a Probability of Failure on Demand:
7. Actuarial and Reinsurance Treaty Structuring#
Registers that a syndicate can audit, line by line and against the physical plant, alter the underwriting terms of property catastrophe and business interruption reinsurance treaties. The register is the auditable object; the terms in the table below are a proposed structure for negotiation, and the percentages in the right-hand column are the working group's estimates rather than filed rates:
| Treaty Underwriting Dimension | Facility Without Formal Critical Items Lists | Facility with Audited RCIL / SCIL Assurance | Actuarial & Reinsurance Impact |
|---|---|---|---|
| Business Interruption Period | Calculated against unhedged 42-week OEM lead times; massive rate loadings. | Calculated against 48-hour on-site strategic spares replacement window. | Premium reduction of 34%; business interruption reserves released. |
| Systemic Accumulation Surcharge | Common-cause cyber exploit assumed to take down all sister facilities. | CycloneDX diversity audit evidences decoupled firmware; conduit isolation is a separate finding and needs a physical network survey. | 0% portfolio accumulation loading; risk treated as uncorrelated. |
| Lloyd's Y5381 Compliance | Disputed claims during nation-state campaigns; litigated war exclusions. | SIL-3 analog safety interlocks certified by an accredited laboratory bound physical rupture regardless of who issues the command. | The state-backed cyber-attack exclusion still applies regardless of hardening; SIL-3 attestation narrows the physical-causation dispute a claim will need, not the coverage determination. |
| Retention Deductibles & Sub-Limits | Punitive $25,000,000 deductible with strict waiting periods and narrow sub-limits. | Dynamic $2,500,000 retention indexed to spares depot audits carried out by the carrier's own surveyor; full replacement cost. | Working capital unlocked; affirmative consequential loss coverage preserved. |
| Probable Maximum Loss (PML) | Unhedged PML exceeds $150,000,000 due to unmitigated multi-month lead times. | Hardwired SIL-3 limits bound single-event PML below $15,000,000. | Treaty capacity unlocked; primary layer attachment rates drop 22%. |
8. Summary of Engineering Principles#
Reliability and Safety Critical Items management establishes five immutable engineering principles:
- Separate Reliability from Safety: RCIL protects uptime; SCIL protects physical existence. Never treat safety-critical hazards with mere software reliability controls.
- Software Must Never Hold Exclusive Safety Authority: Table B assets demand analog, hardwired physical invariants that mechanically enforce safety when software is compromised.
- Business Interruption Dwarfs Physical Asset Value: Lead time is the primary driver of loss. An inexpensive pump with a 30-week lead time is a multi-million-dollar financial liability.
- Common-Cause Defeats Classical Spares Models: Redundant units that share network firmware are not independent. Spares inventory models must account for simultaneous adversarial interdiction.
- Contractual Rigor Drives Balance-Sheet Resilience: Enforcing CycloneDX bills of materials and on-site spares buffers transforms uninsurable cyber-physical tail-risk into an affirmative, underwritten asset class.
9. References#
The method applies IEC 62443-3-2 security level targets, the CycloneDX bill-of-materials specification, the Gordon-Loeb model, and Lloyd's Market Bulletin Y5381. The per-accelerator power figure in section 5 is NVIDIA Corporation's own published figure, given in its Datasheet for NVIDIA Blackwell Architecture, product datasheet.