Risk
AuraScore 83/100

Operational Technology Cyber-Physical Exposure Matrix

Correlate SCADA, PLC, and industrial network vulnerabilities with physical line stoppages and downtime financial impact.

Use this template when assessing operational technology (OT) vulnerabilities, shop-floor network segmentation, and legacy PLC assets. It builds an OT risk matrix mapping cyber threats directly to physical production shutdown costs and containment controls.

Template

Role: Principal Industrial Cybersecurity Architect & OT Resilience Director.

Context

  • Industrial site network scope: {{manufacturing_network_scope}}
  • Control systems & field devices: {{scada_plc_architecture}}
  • End-of-life and unpatched assets: {{legacy_equipment_inventory}}
  • Vendor & operator access vectors: {{remote_access_protocols}}
  • Network zoning & Purdue model status: {{air_gap_segmentation_status}}
  • Hourly operational downtime impact: {{production_downtime_cost}}

Task

Develop an Operational Technology Cyber-Physical Exposure Matrix that correlates network vulnerabilities, legacy hardware blind spots, and remote access pathways with physical plant shutdown risks and safety-critical overrides.

Method

  1. Audit the physical-to-digital boundaries within {{manufacturing_network_scope}} using the Purdue Enterprise Reference Architecture.
  2. Map unpatched and end-of-life devices in {{legacy_equipment_inventory}} against known programmable logic controller (PLC) exploit vectors.
  3. Evaluate inbound connections and third-party vendor conduits within {{remote_access_protocols}}.
  4. Measure the effectiveness of current industrial firewalls and network segmentation in {{air_gap_segmentation_status}}.
  5. Quantify financial and physical risks using {{production_downtime_cost}} for complete line stoppage scenarios.
  6. Determine physical consequence severity including equipment destruction, safety system bypass, or production contamination.
  7. Formulate hardening countermeasures combining network isolation, micro-segmentation, and firmware monitoring.

Constraints

  • MUST clearly separate pure enterprise IT risks from OT cyber-physical impacts affecting shop-floor operations.
  • MUST calculate downtime cost exposure per line using {{production_downtime_cost}}.
  • MUST NOT recommend software patching where vendor-approved firmware validation is impossible without downtime.
  • Remediation recommendations must include fallback physical kill-switch or manual override protocols.

Output format

  • Section 1: Cyber-Physical Threat Landscape (max 150 words).
  • Section 2: OT Risk Exposure Matrix (Markdown table with columns: Plant Cell / Zone, Asset Class, Vulnerability / Attack Vector, Cyber-Physical Impact, Downtime Risk [$ / hr], Purdue Level [0-3], Hardening Safeguard).
  • Section 3: Rapid Containment & Fail-Safe Action Items (3-4 prioritized controls).

Self-review

  1. Did I distinguish between IT enterprise vulnerabilities and direct OT line-stoppage impacts?
  2. Are downtime figures directly derived from {{production_downtime_cost}}?
  3. Do all suggested remediations respect legacy firmware constraints?
AuraScore breakdown
83/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering12/12 · Strong

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency5/10 · Thin

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness5/5 · Strong

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

business-strategy
business-risk
manufacturing-industrial
ot-security
scada
manufacturing