Operational Technology Cyber-Physical Exposure Matrix
Correlate SCADA, PLC, and industrial network vulnerabilities with physical line stoppages and downtime financial impact.
Use this template when assessing operational technology (OT) vulnerabilities, shop-floor network segmentation, and legacy PLC assets. It builds an OT risk matrix mapping cyber threats directly to physical production shutdown costs and containment controls.
Role: Principal Industrial Cybersecurity Architect & OT Resilience Director.
Context
- Industrial site network scope: {{manufacturing_network_scope}}
- Control systems & field devices: {{scada_plc_architecture}}
- End-of-life and unpatched assets: {{legacy_equipment_inventory}}
- Vendor & operator access vectors: {{remote_access_protocols}}
- Network zoning & Purdue model status: {{air_gap_segmentation_status}}
- Hourly operational downtime impact: {{production_downtime_cost}}
Task
Develop an Operational Technology Cyber-Physical Exposure Matrix that correlates network vulnerabilities, legacy hardware blind spots, and remote access pathways with physical plant shutdown risks and safety-critical overrides.
Method
- Audit the physical-to-digital boundaries within {{manufacturing_network_scope}} using the Purdue Enterprise Reference Architecture.
- Map unpatched and end-of-life devices in {{legacy_equipment_inventory}} against known programmable logic controller (PLC) exploit vectors.
- Evaluate inbound connections and third-party vendor conduits within {{remote_access_protocols}}.
- Measure the effectiveness of current industrial firewalls and network segmentation in {{air_gap_segmentation_status}}.
- Quantify financial and physical risks using {{production_downtime_cost}} for complete line stoppage scenarios.
- Determine physical consequence severity including equipment destruction, safety system bypass, or production contamination.
- Formulate hardening countermeasures combining network isolation, micro-segmentation, and firmware monitoring.
Constraints
- MUST clearly separate pure enterprise IT risks from OT cyber-physical impacts affecting shop-floor operations.
- MUST calculate downtime cost exposure per line using {{production_downtime_cost}}.
- MUST NOT recommend software patching where vendor-approved firmware validation is impossible without downtime.
- Remediation recommendations must include fallback physical kill-switch or manual override protocols.
Output format
- Section 1: Cyber-Physical Threat Landscape (max 150 words).
- Section 2: OT Risk Exposure Matrix (Markdown table with columns: Plant Cell / Zone, Asset Class, Vulnerability / Attack Vector, Cyber-Physical Impact, Downtime Risk [$ / hr], Purdue Level [0-3], Hardening Safeguard).
- Section 3: Rapid Containment & Fail-Safe Action Items (3-4 prioritized controls).
Self-review
- Did I distinguish between IT enterprise vulnerabilities and direct OT line-stoppage impacts?
- Are downtime figures directly derived from {{production_downtime_cost}}?
- Do all suggested remediations respect legacy firmware constraints?
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.