← Back to project catalogue
GP-CY-1D2074GCybersecurityReady

Cybersecurity Risk-Scoring Blind Spots in Operational Technology

Explore what a cybersecurity decision can miss when exposure, process consequences or maintenance information is unknown.

Cybersecurity Risk-Scoring Blind Spots in Operational Technology project visual
GP-CY-1D2074G · Cybersecurity
  • Python 3.12
  • Matplotlib
  • Docker

Software compatibility

Python 3.12 or later

The core analysis uses only Python standard-library modules. Docker is optional. No industrial device, cloud service or API key is needed.

Project definition

Problem statement

A vulnerability record may leave important deployment information unresolved. Filling the gaps with reassuring defaults can hide the range of possible conclusions.

Urgency and preparation are different questions: a project can require urgent review while patch testing or a maintenance window remains unresolved.

Project objectives

  • Explain the different purposes of CVSS, EPSS and stakeholder-specific vulnerability decisions.
  • Track every decision compatible with missing observations under a declared custom policy.
  • Separate review priority from preparation for an authorized equipment change.
  • Measure dependence on an illustrative control-credit assumption.
  • Find the smallest observed-field sets that determine each fictional case outcome.

Project structure

Project components

01

Literature review

Connects OT engineering guidance, vulnerability severity, exploitation evidence and contextual decision methods.

02

Review policy

Uses seven finite input fields, ordinal priority floors and separate preparation routes.

03

Missing evidence

Enumerates exact possible-decision sets instead of imputing favorable observations.

04

Information sufficiency

Checks all 128 observed-field subsets for each of twelve fictional cases.

05

Source consistency

Preserves a versioned SSVC table/definition discrepancy without silently repairing it or importing it into the custom policy.

Methodology

Project workflow

  1. 01
    Read the assumptions

    Understand the fictional cases, finite domains and meaning of review versus authorization.

  2. 02
    Trace the sources

    Use the annotated references and access notes to distinguish guidance from published experiments and local assumptions.

  3. 03
    Reproduce the results

    Verify the supplied calculations offline, with or without Docker.

  4. 04
    Hide an input

    Use the case inspector to examine how missing information changes possible conclusions.

  5. 05
    Present an extension

    Explain a justified model change, its calculations and its remaining limitations using the editable slides.

Demonstration scenario

Hide patch status and the maintenance window in fictional case OT04. Urgent review remains stable, but four preparation routes remain possible. Explain why a stable priority does not authorize a change.

Engineering

Tools and method

Analysis
Standard-library Python calculates exact finite sets, policy contrasts and information bounds.
Verification
98 checks cover independent counting, invalid inputs, set containment, minimality, source provenance and delivered artifacts.
Documentation
Includes introduction, literature review, theory, methodology, results, discussion, conclusions, future work and labelled figures and tables.

Testing

Evaluation

Evaluation measures

  • Stable and ambiguous priorities after input removal
  • Preparation-route ambiguity separately from urgency
  • Control-credit policy sensitivity across the design grid
  • Minimum sufficient observations and guaranteed information gain
  • Independent arithmetic, source consistency and byte-exact reproduction

Project boundaries

  • This is a theoretical study, not a scanner, plant risk assessment or CVSS/SSVC implementation.
  • All twelve cases are fictional. Design-grid counts are not estimates of real facility prevalence.
  • The control credit is a contestable policy assumption, not measured protection effectiveness.
  • Possible-decision sets are logical alternatives, not probabilities or confidence intervals.
  • No equipment changes, real-world predictive claims or industrial safety certification are included.
  • No information is collected.

Included

  1. 0175-page project documentation in PDF and editable Word formats
  2. 02Eight-page usage guide in PDF and editable Word formats
  3. 0320-slide editable presentation with source notes and native charts
  4. 0416 annotated references, source matrix and one attributed literature image
  5. 05Six labelled analytical figures and eleven retained CSV/JSON outputs
  6. 06Twelve fictional cases and a 2592-state exhaustive design
  7. 07Complete Python source code, 98 automated tests and offline reproduction

Project record

No information is collected on this page.

Permanent project ID
GP-CY-1D2074G
Catalogued
21 Aug 2026
Completed
06 Sept 2026
Verified
06 Sept 2026
Demonstration
Included in repository

Handover

After purchase

  1. 01
    Payment is confirmed

    The project is marked unavailable and cannot be purchased again.

  2. 02
    Repository access is granted

    The buyer's submitted GitHub account receives access to the private repository.

  3. 03
    The purchase record is delivered

    The certification sheet is prepared from the reviewed buyer details and sent privately by email.