Cybersecurity Risk-Scoring Blind Spots in Operational Technology
Explore what a cybersecurity decision can miss when exposure, process consequences or maintenance information is unknown.

Software compatibility
The core analysis uses only Python standard-library modules. Docker is optional. No industrial device, cloud service or API key is needed.
Project definition
Problem statement
A vulnerability record may leave important deployment information unresolved. Filling the gaps with reassuring defaults can hide the range of possible conclusions.
Urgency and preparation are different questions: a project can require urgent review while patch testing or a maintenance window remains unresolved.
Project objectives
- Explain the different purposes of CVSS, EPSS and stakeholder-specific vulnerability decisions.
- Track every decision compatible with missing observations under a declared custom policy.
- Separate review priority from preparation for an authorized equipment change.
- Measure dependence on an illustrative control-credit assumption.
- Find the smallest observed-field sets that determine each fictional case outcome.
Project structure
Project components
Literature review
Connects OT engineering guidance, vulnerability severity, exploitation evidence and contextual decision methods.
Review policy
Uses seven finite input fields, ordinal priority floors and separate preparation routes.
Missing evidence
Enumerates exact possible-decision sets instead of imputing favorable observations.
Information sufficiency
Checks all 128 observed-field subsets for each of twelve fictional cases.
Source consistency
Preserves a versioned SSVC table/definition discrepancy without silently repairing it or importing it into the custom policy.
Methodology
Project workflow
- 01Read the assumptions
Understand the fictional cases, finite domains and meaning of review versus authorization.
- 02Trace the sources
Use the annotated references and access notes to distinguish guidance from published experiments and local assumptions.
- 03Reproduce the results
Verify the supplied calculations offline, with or without Docker.
- 04Hide an input
Use the case inspector to examine how missing information changes possible conclusions.
- 05Present an extension
Explain a justified model change, its calculations and its remaining limitations using the editable slides.
Demonstration scenario
Hide patch status and the maintenance window in fictional case OT04. Urgent review remains stable, but four preparation routes remain possible. Explain why a stable priority does not authorize a change.
Engineering
Tools and method
- Analysis
- Standard-library Python calculates exact finite sets, policy contrasts and information bounds.
- Verification
- 98 checks cover independent counting, invalid inputs, set containment, minimality, source provenance and delivered artifacts.
- Documentation
- Includes introduction, literature review, theory, methodology, results, discussion, conclusions, future work and labelled figures and tables.
Testing
Evaluation
Evaluation measures
- Stable and ambiguous priorities after input removal
- Preparation-route ambiguity separately from urgency
- Control-credit policy sensitivity across the design grid
- Minimum sufficient observations and guaranteed information gain
- Independent arithmetic, source consistency and byte-exact reproduction
Project boundaries
- This is a theoretical study, not a scanner, plant risk assessment or CVSS/SSVC implementation.
- All twelve cases are fictional. Design-grid counts are not estimates of real facility prevalence.
- The control credit is a contestable policy assumption, not measured protection effectiveness.
- Possible-decision sets are logical alternatives, not probabilities or confidence intervals.
- No equipment changes, real-world predictive claims or industrial safety certification are included.
- No information is collected.
Included
- 0175-page project documentation in PDF and editable Word formats
- 02Eight-page usage guide in PDF and editable Word formats
- 0320-slide editable presentation with source notes and native charts
- 0416 annotated references, source matrix and one attributed literature image
- 05Six labelled analytical figures and eleven retained CSV/JSON outputs
- 06Twelve fictional cases and a 2592-state exhaustive design
- 07Complete Python source code, 98 automated tests and offline reproduction
Project record
No information is collected on this page.
- Permanent project ID
- GP-CY-1D2074G
- Catalogued
- 21 Aug 2026
- Completed
- 06 Sept 2026
- Verified
- 06 Sept 2026
- Demonstration
- Included in repository
Handover
After purchase
- 01Payment is confirmed
The project is marked unavailable and cannot be purchased again.
- 02Repository access is granted
The buyer's submitted GitHub account receives access to the private repository.
- 03The purchase record is delivered
The certification sheet is prepared from the reviewed buyer details and sent privately by email.