The RISE Model: Prioritizing OT Vulnerabilities Where It Matters Most
Hillstrong Group Security ·

Author: Roger Hill
Focus Limited Resources Where They’ll Deliver Maximum Impact
If every vulnerability were equal, our jobs would be a lot simpler. We could line them up, knock them down, and call it a day. However, the reality inside OT environments tells a different story. One where not all vulnerabilities are worth the same effort—and not all fixes yield the same return.
When you’re operating in a world where patching isn’t always feasible, and resources are stretched thin, prioritization isn’t just a helpful tactic—it becomes the foundation for effective risk management. That’s why we built the RISE model. It’s not a theory or a vendor framework. It’s born out of years of watching teams chase the wrong vulnerabilities while real risks quietly simmered just out of view.
RISE stands for Risk, Impact, Scoring Improvement, and Effort. It’s a pragmatic lens designed to help OT cybersecurity leaders answer a deceptively complex question: Where should we act first?
The Problem with Traditional Prioritization
Too often, external forces dictate prioritization in OT environments—scanners flagging CVSS 9s and 10s, compliance audits calling for remediations, or dashboards that paint risk in shades of red. These inputs are useful, but they’re incomplete. They fail to capture the nuance of physical systems, safety-critical dependencies, and the operational pain associated with even minor changes.
We’ve already covered how raw CVSS scores can be misleading. But beyond scoring, the entire structure of traditional prioritization assumes the cost of action is low, and the benefit is high. That’s rarely the case in OT.
You need a model that respects the tradeoffs. That’s what RISE is built to do.
Breaking Down the RISE Components
1. Risk Given the asset’s exposure and function, this is the potential for exploitation. It includes things like:
- Is the vulnerability reachable from an unmanaged or remote system?
- Is the device involved in production or safety-critical processes?
- Could this be a pivot point to higher-value targets?
Risk isn’t a score pulled from a database. It’s context-specific. OT must account for both cyber pathways and physical process exposure.
2. Impact What’s at stake if this vulnerability is exploited? Not just technically, but operationally:
- Could it halt a production line?
- Would it violate a safety constraint or environmental regulation?
- Does it tie back to compliance reporting or customer deliverables?
You’re not just protecting assets—you’re protecting outcomes. Impact elevates that reality.
3. Scoring Improvement This is the most overlooked factor in OT vulnerability conversations. It’s about the delta. How much risk do we eliminate if we remediate or mitigate this issue?
Sometimes, fixing a vulnerability cuts off a major attack path. Other times, the fix offers only marginal improvement because other exposures still exist. We must stop spending 80% of our effort for 5% of the risk reduction.
4. Effort The cost of mitigation isn’t just technical—it’s political, operational, and economic.
- Does the fix require downtime?
- Will it impact validated systems or require requalification?
- Is there a playbook, or is this a one-off engineering lift?
In OT, effort is a gating factor. Even a high-risk issue might need to be deferred if the mitigation introduces unacceptable disruption. And that’s not weakness—that’s leadership.
Applying RISE in the Field
Let’s say you have five vulnerabilities across different devices:
- A Level 1 drive with a denial-of-service CVE
- A remote access service on an engineering laptop
- A firmware issue on a PLC used in packaging
- An out-of-date OS on a historian
- An unpatched browser vulnerability on a QA station
Traditionally, the ones with the highest CVSS scores would rise to the top. But through the RISE lens, your ranking might look very different.
The engineering laptop may have lower CVSS but presents a high risk, high impact, and moderate scoring improvement—with low effort to isolate or remediate. That becomes your top priority.
The historian OS might have a high score but sit behind a series of segmentation boundaries with no real exposure and patching it might require 12 hours of requalification. That drops.
It’s not about ignoring severity—it’s about putting it in context.
Building a RISE Dashboard
Applying the RISE model doesn’t require buying new tools or launching a major project. It requires alignment between teams. OT security must coordinate with engineering, operations, and safety to understand real-world variables.
Start small. Build a spreadsheet. Score your top 10 open vulnerabilities using RISE on a 1–5 scale for each category. You’ll immediately see where intuition and dashboards diverge—and that’s where your leadership comes in.
Over time, you can operationalize RISE into your governance framework. Assign ownership, create workflows for exceptions, and build reporting that tells the story of decisions—not just alerts.
The Leadership Imperative
Boards don’t want noise—they want decisions. They want to know that the OT cybersecurity team spends its time and budget on what matters most. RISE gives you a language to explain that.
When a regulator asks why a critical vulnerability hasn’t been patched, RISE allows you to respond confidently: “Yes, it’s high severity. But based on our RISE model, it represents low real-world risk, minimal scoring improvement, and high operational cost. We’ve applied compensating controls and are focusing our efforts on higher-leverage issues.”
That’s not deflection. That’s risk management.
A Model Grounded in Reality
The RISE model isn’t about chasing perfection—it’s about optimizing decisions. It helps you focus on how intervention changes outcomes. That’s the kind of leadership OT environments need right now.
You can’t fix everything. You’re not supposed to. But with RISE, you can fix the right things.
Next week, we’ll build on this by introducing the QUICK framework—a method to classify asset criticality across Quality, Uptime, Information Integrity, Compliance, and Key Deliverables. Prioritization only works if you truly understand what’s at stake.
Thanks for reading! For more OT cyber blogs and eBook releases and to stay up-to-date, please follow us on LinkedIn!