Service

Risk, (process) safety & info/cyber security

For critical infrastructure — we protect CIIP and CIP assets and optimize the balance between industrial process safety and multidimensional cybersecurity, including AI/ML.

Download brochure (PDF)

Managing process safety, cybersecurity and AI risks

In a comprehensive manner — we apply and integrate key risk-management frameworks to build resilient process safety & security architectures.

  • ISO 31000 / 31010
  • ISO/IEC 27005
  • ISA/IEC 62443
  • IEC 61511 / 61508
  • ISO 14971
  • ISO 10418
  • Norsok Z-013
  • NIST SP 800-30/37/39
  • NIST CSF 2.0
  • CCPS-CPQRA
  • NIST AI RMF

Risk & control architecture

We design risk management systems and control architectures through their life cycle, with risk criteria, appetite and tolerance.

Asset & asset-health management

Discovery, classification and prioritization across the life cycle, including dependencies and Process Safety Information (PSI).

Control & barrier management

Static & dynamic control, barrier and safeguard management, inherently safer processes and secure operating procedures.

Performance & maturity

Process-safety performance indicators (API RP 754, CCPS), InfoSec measurement (ISO/IEC 27004) and maturity (ISO/IEC 21827).

Risk engineering methods

Foundational methods

PHA, Functional Safety (SIL & SIS), HAZOP, FMEA/FMECA, FTA, ETA, LOPA, Bow-Tie, RCA, MCDA, ALARP/SFAIRP, F-N curves, HAZID and SoM.

Cybersecurity methods

Info-sec & IT cybersecurity (ISO/IEC 27005, NIST CSF 2), OT (IEC 62443), IoT/IIoT (ISO/IEC 27400), AI safety (ISO 23894, NIST AI RMF), VAM, TARA, FAIR, STRIDE, PASTA.

Specific methods

Criticality, reliability (RBD, HRA), availability, maintainability, dependability, obsolescence, fitness-for-service, Markov analysis, HACCP, HARA and human factors engineering.

Probability & impact modeling

Probabilistic, frequentist, possibilistic, deterministic and Bayesian models; BIA, PML, cross-impact, scenario analysis, stress testing and AI-assisted risk modeling.

Continuous control — before, during & after

Before

QA/QC, pre-startup review, Management of Change (MoC), transient operating modes, job safety analysis, GMP/GSP/GLP and risk-based inspection (RBI).

During

Loss control & adjustment, abnormal events / emergencies & crisis preparedness and response, plus exercises and testing.

After

Event/incident investigation (ISO/IEC 27041/3; CCPS) and control-effectiveness assessment.

Ready to improve, be better?

Talk to our experts