Risk
AuraScore 77/100

Industrial Automation Cyber Exposure Assessment Brief

Assess shop-floor operational technology vulnerabilities and financial downtime risks during plant automation upgrades.

Apply this template when legacy production machinery connects to modern networked systems. It pinpoints lateral attack vectors and outlines prioritized containment controls.

Template

Role: Senior Operational Technology (OT) Security Strategist and Industrial Systems Resilience Advisor.

Context

  • Manufacturing facility classification: {{manufacturing_plant_type}}
  • Deployed supervisory & control layer: {{scada_ot_systems}}
  • Legacy controller & equipment baseline: {{legacy_machinery_status}}
  • Current network isolation posture: {{network_segmentation_level}}
  • Line stoppage burn rate: {{average_hourly_downtime_cost}}
  • Compliance & cybersecurity standard: {{regulatory_compliance_mandate}}

Task

Draft a high-impact risk brief evaluating cyber-physical and network vulnerabilities across {{scada_ot_systems}} and {{legacy_machinery_status}}, delivering an operational protection strategy that prevents line downtime.

Method

  1. Evaluate the threat vector between enterprise IT networks and {{scada_ot_systems}} based on {{network_segmentation_level}}.
  2. Identify protocol and patch deficiencies inherent in {{legacy_machinery_status}}.
  3. Calculate production outage exposure per 8-hour, 24-hour, and 72-hour incidents using {{average_hourly_downtime_cost}}.
  4. Map technical exposure gaps against mandatory audit clauses in {{regulatory_compliance_mandate}}.
  5. Categorize risks into immediate cyber-physical safety hazards, data exfiltration, and unscheduled line stoppages.
  6. Formulate practical defense-in-depth countermeasures tailored for continuous {{manufacturing_plant_type}} operations.
  7. Detail an incident isolation protocol to protect physical tooling while minimizing full-plant trip events.

Constraints

  • MUST correlate technical cyber exposures directly to production financial loss using {{average_hourly_downtime_cost}}.
  • MUST NOT propose IT-centric solutions that require uncoordinated plant shutdowns or disrupt PLC cycles.
  • Limit recommendations to pragmatic, zero-trust industrial network architectures.
  • Use standard industrial terminology (Purdue model, IEC 62443, PLC, SCADA).

Output format

  • Section 1: OT Threat Surface Overview (100-150 words)
  • Section 2: Financial & Operational Downtime Exposure Table (Incident Duration | Estimated Cost | Probability | Impacted Line)
  • Section 3: Prioritized Countermeasures (Top 4 ranked engineering controls with implementation difficulty)
  • Section 4: Compliance Gap Summary against {{regulatory_compliance_mandate}} (3 bullet points)

Self-review

  • Ensure technical controls protect {{legacy_machinery_status}} without breaking real-time latency requirements.
  • Verify all cost projections correctly multiply {{average_hourly_downtime_cost}} across scenarios.
  • Confirm clear alignment with the designated {{regulatory_compliance_mandate}}.
AuraScore breakdown
77/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering8/12 · Adequate

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency5/10 · Thin

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness3/5 · Adequate

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

business-strategy
business-risk
manufacturing-industrial
ot security
industrial automation
scada risk