PDF · opens in a new tab
// white paper
The Four Hats of Cyber-Risk Exposure
Where cybersecurity liability originates for connected-product manufacturers that also service and operate their assets.
Hillstrong Group Security ·
A company that builds connected hardware, services it under contract, and runs it inside critical infrastructure wears four hats at once. Each hat carries its own threat actors, regulators, and failure modes, and all four sit on the same systems. One firmware vulnerability can land as a product-liability event, a contractual breach, and a grid-safety incident in the same week.
Most programs scope the enterprise IT surface. The model puts all four exposure sources on the same program.
01. The enterprise (the public business)
Origin. Reputation, investor and market expectations, board-level cyber governance, and the corporate IT and intellectual-property attack surface.
Trigger. Material breach, theft of trade-secret technology, ransomware against operations, or a regulator’s enforcement action.
Clocks. SEC Form 8-K Item 1.05 (US): disclose a material cybersecurity incident within 4 business days of the materiality determination. Reg S-K Item 106: annual risk-management and governance disclosure. Adopted 26 Jul 2023. EU NIS2 (Dir 2022/2555): the management body approves and oversees cyber risk measures, with director training (Art. 20); senior individuals carry personal liability and, for essential entities, face temporary management bans (Art. 32); fines reach €10M or 2% of group worldwide turnover for essential entities, €7M or 1.4% for important (Art. 34). Australia SOCI Act 2018: the governing body approves the annual Critical Infrastructure Risk Management Program report; directors carry duty-of-care exposure under the Corporations Act.
Failure mode. Disclosure failure, securities liability, turnover-scale fines, personal liability and management bans.
This is the hat CISOs already report. It is not the only hat.
02. The product (the connected device)
Origin. Market expectation of an intrinsically secure product, and product-liability law for a cyber-physical device whose failure carries physical consequences.
Trigger. A vulnerability in shipped firmware or software, exploited across the deployed fleet through the update channel.
Clocks. EU Cyber Resilience Act, Reg (EU) 2024/2847, Art. 14: for an actively exploited vulnerability or severe incident, early warning within 24h, notification within 72h, final report within 14 days of a fix, via the ENISA Single Reporting Platform. SBOM in technical documentation; security-update support generally 5 years. Reporting obligations apply 11 Sep 2026; full obligations 11 Dec 2027.
Failure mode. Fleet-wide liability, loss of EU market access, CRA penalties.
03. The operator (service provider under customer contract)
Origin. Preventive and break/fix maintenance, plus MSSP-style continuous monitoring and response, delivered through standing privileged remote access into customer environments.
Trigger. Compromise of the service platform or the remote-access channel propagates across every customer tenant. SLA and audit clauses turn a customer’s incident into the provider’s breach.
Clocks. Contractual, not statutory: service-level penalties, customer audit rights, indemnification, and flow-down of the customer’s own duties. EU NIS2 Art. 21 supply-chain security pushes obligations onto suppliers and service providers.
Failure mode. Penalty exposure, multi-customer breach, termination, litigation.
Third-party vendor risk for OT is how this hat shows up in a customer program. If you are the vendor, it is your hat.
04. Critical infrastructure (the asset on the grid)
Origin. The operational asset’s role in grid stability draws sector regulators and nation-state threat actors, independent of corporate status.
Trigger. Disruption or manipulation of the control system that affects supply.
Clocks. NERC CIP-008-6 (US bulk electric system): report a Reportable Cyber Security Incident, and attempts, to E-ISAC and CISA within 1 hour. EU NIS2, Dir (EU) 2022/2555 Art. 23: 24h / 72h / 1-month for essential entities. Australia SOCI Act 2018: 12h (significant) or 72h (relevant) to the ACSC.
Failure mode. Regulatory enforcement, license risk, grid-safety and societal impact.
The convergence point
The product sold is the asset serviced is the node on the grid. One defect can trigger all four hats together. Scope the program to the convergence, not to a single hat.
Supply chain sits across all four. The company inherits upstream component vulnerabilities and is itself a supply-chain link for its customers. Risk flows both directions.
Threat actors differ. Financial and IP-driven actors target the enterprise and the product. Nation-state and hacktivist actors target the grid. Defense priorities differ by hat.
How to use it
Map each engagement’s obligations and findings to a hat, then confirm no hat is unscoped. That is the whole method.
If the annual 10-K still describes plant risk in IT language, read The OT Disclosure Gap. Citations in the PDF were verified June 2026. Reporting clocks change. Confirm against primary sources before client use.
Download the one-pager for the table of clocks. The HTML on this page is the citable version.