Replacing Likelihood With Credibility In The Risk Equation @S4Events
Replacing Likelihood With Credibility In The Risk Equation  @S4Events
Uploaded June 2025 | Updated September 2026, 2 weeks ago
Andrew makes the case "credibility" should replace "likelihood" in the risk equation, especially for low frequency, high impact events.

NIST 800-30, IEC 62443-3-2 and many others model risk as "consequence x likelihood". A better word is "credibility." Using "credibility" instead of "likelihood" makes it clear we are exercising judgement, rather than trying to estimate an objective probability.

Further, when we discount attack scenarios because of lack of credibility, we should document that assessment and decision for the court cases that will inevitably arise if we are mistaken and suffer a high-impact event. IEC 62443-3-2 is being updated as we speak, and this is an opportunity to update the wording to better reflect the realities of assessing and managing OT cyber risks.

Subscribe to Dale’s ICS Security: Friday News & Notes email here:
friday.dale-peterson.com/signup
Check out S4x26. Feb 23 - 26 in Miami South Beach:
s4xevents.com
Replacing Likelihood With Credibility In The Risk EquationMeasuring And Reducing Maintenance DebtOT SecOps Or BustS4 Legend Interview: Mark WeatherfordOT Security Market By The Numbers #shortsHoneypots For Threat IntelligenceCyber Av3ngers #shortsThe Origin Of Now, Next, Never #shorts3 Step Success Story In SemiconductorsAlternate Factors For MFA Deep In The Manufacturing EnvironmentFrenos Session In The S4x26 POC PavilionGaming With Metrics To Achieve An OT Security Program
S4 Events |

Replacing Likelihood With Credibility In The Risk Equation

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER