Rethinking OT Risk: Operational Resilience Threat Modeling cover
Download the PDF

PDF · opens in a new tab

// white paper

Rethinking OT Risk: Operational Resilience Threat Modeling

Challenging the Current OT External Risk Analysis Model

Roger Hill ·

Most manufacturing ransomware never touches a PLC. It encrypts ERP, MES, Active Directory, or a supplier’s order system. The line stops because the business process that feeds it stopped. Purdue, IEC 62443, and NIST CSF still treat the ICS surface as the problem. They do not score that cascade.

OT-ORTM (OT Operational Resilience Threat Modeling) is the method for that job. RISE is the score that ranks which dependencies get fallbacks first.

What the current model misses

ICS-centric history (Stuxnet, Triton, Industroyer) trained the industry to hunt for logic changes on PLCs, HMIs, and DCS. Ransomware operators go where the plant cannot run without: order entry, raw-material procurement, production scheduling, payroll clocks, vendor payments.

Purdue (ISA-95) isolates Levels 0-3 from 4-5. That is still useful segmentation. It does not tell you what happens when Level 4 dies and Level 2 is fine. IEC 62443 and NIST CSF 2.0 give you zoning, SLs, and Govern. They do not quantify IT-originated production loss.

Four phases

1. Identify IT-OT business-process dependencies. Inventory the enterprise systems production cannot run without. ERP for procurement. MES for scheduling. Workforce systems for clocks. Finance for vendor payments. Classify by how fast the line stops if that system is gone.

2. Map attack paths through those dependencies. Phishing into ERP admins. A supplier’s IT. Cloud MES. Lateral movement that takes Active Directory. The 2022 Toyota supplier case is the pattern: ERP at a parts vendor, 14 plants down, no ICS compromise.

3. Score with RISE. Risk exposure (R) 30%. Impact on production (I) 30%. Speed of recovery (S) 20%. Effort to mitigate (E) 20%.

RISE score = (R × 0.3) + (I × 0.3) + (S × 0.2) + (E × 0.2)

The paper applies that to JBS Foods 2021 and lands 8.3 / 10 (high risk). Use the number to rank work, not to decorate a slide.

4. Test resilience against the high scores. Offline or degraded ERP/MES. Manual line operation if IT is gone. Vendor contingencies when a supplier’s IT dies. Then exercise those paths.

Cases the model is built on

Bassett Furniture, MKS Instruments, JBS Foods, Toyota, Dole. Same shape: IT or supplier IT fails, OT output stops, ICS stays up. Colonial Pipeline is the cousin in energy: IT hit, OT shutdown by decision, not by PLC payload.

If you need the assessment that walks a site through this, use the OT ransomware readiness assessment. Manufacturing is the industry landing. RiskSpan covers the IT/OT boundary the cascade crosses.

The PDF has the decision trees, worked RISE tables, and the 62443/CSF map. This page is the citable argument.

// white paper FAQ

Questions this paper answers

What is OT-ORTM?
OT Operational Resilience Threat Modeling. It is Hillstrong's method for quantifying how an IT ransomware event cascades into manufacturing downtime when no PLC is ever touched. Four phases: identify IT-OT business-process dependencies, map attack paths through those dependencies, score them with RISE, then test resilience strategies against the highest scores.
Why does IT ransomware stop a plant if ICS is untouched?
Production depends on ERP, MES, vendor payments, and scheduling. Encrypt those and the line idles even when Level 0-2 stays clean. Toyota's 2022 supplier ERP hit stopped 14 plants with no ICS compromise. Purdue segmentation does not model that cascade.
What is RISE scoring in OT-ORTM?
A 1-10 score of ransomware resilience on a dependency. Risk exposure 30 percent, impact on production 30 percent, speed of recovery 20 percent, effort to mitigate 20 percent. The paper works a JBS Foods 2021 example to 8.3 out of 10, high risk. Use it to rank which IT systems get offline fallbacks first.
How does OT-ORTM sit next to IEC 62443 and NIST CSF?
Those frameworks still matter for ICS protection, zoning, and the Govern function. They do not score business-process failure from an IT hit. OT-ORTM fills that gap and maps its phases onto 62443 and CSF so the work lands in the program you already run.

Turn the research into a running program

Book a 30-minute demo. We will show how Resilion turns your existing assessments into a program you can run and prove.