Cybersecurity Risk Assessment

Machinery cybersecurity risk assessment is part of machinery safety risk assessment when corruption can create a hazardous situation or weaken a protective measure. The analysis should start from the machine, its intended use, reasonably foreseeable misuse, hazards, and safety-related control functions.

Safety risk assessment controls the structure

determine the limits of the machinery or related product, which include the intended use and any reasonably foreseeable misuse thereof

Regulation (EU) 2023/1230, Annex III Part B

Annex III Part B requires the manufacturer to determine applicable essential health and safety requirements and design the machinery or related product to eliminate hazards or minimise relevant risks. ISO 12100 gives the same safety sequence: determine limits, identify hazards and hazardous situations, estimate risk, evaluate risk, and reduce risk.

Cybersecurity work should enter that sequence at the point at which a corruptible connection, software item, data item, configuration, or control path can affect the hazard or the protective measure.

Corruption paths belong to hazards

A useful machinery cybersecurity assessment does not start with a long list of generic threats. It starts with the safety function or protective measure, then asks how corruption could compromise it.

Safety function first

Name the safety function, safe state, limit, interlock, stop behaviour, mode, or protective measure that prevents harm.

Interface second

Identify the interface or path that can change software, data, configuration, commands, or process information used by that safety function.

Corruption effect third

Explain how accidental or intentional corruption could create a new hazard, increase risk, or defeat the intended risk reduction.

Protection last

Select protective measures that reduce the safety risk without weakening the functional safety of the machinery.

Threat assessment is safety-limited

prEN 50742 treats threat assessment as an addition to the machinery risk assessment, not a replacement for it. Its draft structure says vulnerabilities can compromise protective measures and that the risk can be assessed only through the impact on functional safety.

That distinction is useful even while prEN 50742 remains a draft. A network scan result, missing password policy, or exposed service is not enough by itself. The machinery file needs the path from that weakness to a hazardous situation or a safety-related control effect.

Records show the safety reasoning

ISO 12100 expects risk-assessment documentation to show the machinery assessed, assumptions, hazards and hazardous situations, information used, risk-reduction objectives, protective measures, residual risks, and the result of the assessment. For cybersecurity, those records should also make the corruption path visible.

  • the product, configuration, software version, and intended use assessed;
  • the safety function or protective measure affected by corruption;
  • the interface, access path, update path, or data path that can cause the corruption;
  • the safety effect if the corruption occurs;
  • the protective measure, countermeasure, or information for use relied on;
  • the residual risk and any limits of the selected protection.

Technical documentation carries the result

Article 10 requires manufacturers to draw up the technical documentation before placing machinery or a related product on the market or putting it into service. Annex IV requires documentation on the risk assessment, including applicable essential health and safety requirements and the protective measures used to meet them.

Source code and programming logic

Article 10 also allows competent national authorities to request source code or programming logic when it is necessary to check compliance with Annex III.

Sources