Smart Manufacturing Operational Technology Threat Brief
Assess industrial IoT and SCADA network exposure to quantify operational disruption and cyber-physical failure risks.
Use this template when connecting factory floor assets to enterprise networks or evaluating operational technology (OT) vulnerabilities that could cause physical downtime or safety hazards.
Role: Lead Cyber-Physical Systems and Operational Technology (OT) Risk Architect.
Context
- Connected Plant Scope: {{ot_network_scope}}
- Legacy Hardware Footprint: {{legacy_controller_types}}
- Segmentation Architecture: {{air_gap_status}}
- Ingress Channels: {{remote_access_protocols}}
- Production Exposure Value: {{daily_production_value}}
- Triage Speed Expectation: {{incident_response_sla}}
Task
Generate a cyber-physical operational risk brief identifying lateral attack vectors across factory automation systems, quantifying financial exposure, and establishing OT containment priorities.
Method
- Map the boundary between enterprise IT and plant OT across {{ot_network_scope}}.
- Identify exploitable protocol and firmware vulnerabilities inherent in {{legacy_controller_types}}.
- Evaluate the structural integrity and bypass risks associated with {{air_gap_status}}.
- Assess third-party vendor and remote maintenance exposure introduced via {{remote_access_protocols}}.
- Model ransomware and sabotage scenarios that physically halt production, calculating losses via {{daily_production_value}}.
- Benchmark current plant disconnect and manual override procedures against {{incident_response_sla}}.
- Determine compensating controls for legacy controllers that cannot support direct endpoint agents.
- Formulate prioritized mitigation directives separating immediate network segmentation from long-term hardware upgrades.
Constraints
- MUST distinguish between IT data loss and OT physical safety/production stoppage impacts.
- MUST explicitly reference exposure calculations using {{daily_production_value}}.
- MUST NOT recommend standard enterprise IT security agents that disrupt real-time PLC operations.
- All recommendations MUST align with industrial cybersecurity standards (e.g., IEC 62443).
Output format
- Executive Threat Architecture (120-150 words framing cyber-physical plant posture)
- Attack Surface Breakdown (Table: Zone | Asset/Protocol | Threat Vector | Stoppage Risk)
- Financial & Physical Impact Scenarios (2 distinct attack scenarios with downtime cost estimates)
- Compensating Control Directives (Tiered actions: Immediate 48-Hour Hardening, 30-Day Controls)
Self-review
- Verified that all proposed controls protect real-time controller reliability for {{legacy_controller_types}}.
- Checked that downtime calculations accurately reflect {{daily_production_value}}.
- Confirmed incident triage steps meet or exceed {{incident_response_sla}}.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.