Compliance Has a Working Range
A plant that is run by a control system can be driven by that control system. Whatever the plant can be commanded to do, it can be commanded to do by whoever holds the commands, however they came to hold them.
Two questions follow, and they get treated as one.
The first is what it takes to keep the commands in the right hands: to manage known vulnerabilities as fixes are published for them, to separate what should not be reachable, to govern who holds credentials, and to be able to recover when something fails. This is what the discipline is organised around. It is structured by compliance frameworks, audited on a cycle, and it does real work.
The second is what the plant can be driven to if the first is not enough. Not how likely a compromise is, but what becomes available when one succeeds, and whether anything stands between that and an outcome the operator cannot accept. That is not a new kind of question, and industries that handle serious hazards have been required to answer it for decades. What is new is asking it about a compromised control system, and there the question does not appear as a standard deliverable in the general lifecycle: not in the design review, the acceptance test, the modification procedure or the audit. Across most operational technology, where the work is done at all it is done electively, by somebody who decided it was worth doing.
The two are not competing claims on the same budget. They work at different scopes. A programme reduces exposure everywhere, by an amount nobody can state, across a population of scenarios nobody could enumerate: somebody reaches an HMI, a historian, an alarm server, an engineering station, and the list does not close. Nothing could study them one at a time and a floor does not have to. A demonstration does the opposite. It takes one named outcome, establishes what one compromised authority can do towards it, and establishes whether anything stands in the way that the same authority cannot also reach. The naming is what makes that possible, because an enumeration with no stated end never closes. One works broadly against what nobody specified. The other only works once something is specified. Neither can be run the other way.
The first question is universal, and its answer raises a floor. That gives the programme a working range: the consequences that are recoverable and acceptable as ordinary loss. The second question exists because that range has an edge.
Three positions are possible. Where everything available to one compromised authority falls inside that range, the programme is the correct instrument and no separate demonstration is owed. Where an unrecoverable or unacceptable consequence is available to that authority, something it cannot defeat has to stand between the two. Where the answer is not known, establishing which condition applies is what is owed first.
What an attestation asks for
Compliance here means one specific transaction. The operator attests that specified measures have been implemented and operate as required, an assessor tests the assertion, and the deliverable is the attestation. It is not a claim about what any particular framework says about itself.
The function is to raise a floor. Somebody sets a level, everybody in scope has to reach it, and the assessor finds where they have not. Across a population that would otherwise sit wherever each operator individually decided, that is a real gain, and it is achieved without anyone having to quantify anything. An instruction to be appropriately secure cannot be administered as an attestation without being translated into determinate evidence requirements. An obligation may be written in outcome terms and still be discharged through a list. What is described here is the deliverable that gets assessed, not the language the obligation was written in.
That is why there is a list, and the list is where the instrument’s limits sit. It supplies a stopping point for each cycle and no defensible stopping point over time. Within a cycle, effort terminates when the list is complete, because the list is the object. Across cycles, nothing establishes that the list was ever the right length, because nothing in the obligation asks what the list was intended to achieve and nothing in the evidence indicates whether it achieved it. A list that is not terminated by an outcome contains no internal reason for the additions to stop, and nothing sizes the return on the next control either, so the decision falls to the list.
This explains behaviour that is usually attributed to indifference or to underfunding. An operator working to an attestation follows good practice as far as the plant allows and stops where operational constraint, available resources and prevailing regulatory pressure place the stop, because nothing else is available to decide it. The obligation does not say when secure is secure enough, and it has never told the operator what that would have to mean.
An attestation records whether the specified obligations were met, and a clean one establishes exactly that. It is a competent instrument for the purpose. What it is not is an instrument for establishing that an unacceptable outcome is constrained. Attested facts may become evidence inside a demonstration; they do not assemble themselves into one. The objection is not that attestations are done badly. It is that a perfect one leaves the second question untouched.
Residual risk is the missing quantity, and not because nobody writes one down. Where a framework requires it a figure is produced, compared against a tolerance the organisation sets for itself, and accepted. The decision is taken and somebody owns it. What it is taken against is a judged likelihood rather than an established bound, so what gets accepted is a rate nobody derived, for an event nobody characterised.
What a demonstration asks for
A demonstration inverts the deliverable. The operator states the outcome that must not occur, produces an argument that it is bounded, and the assessor tests the argument rather than the inventory. The safety case is the established form of this in major-hazard industry, and the term is used here for the deliverable rather than for any one jurisdiction’s version of it.
Measures appear in a demonstration. They appear as evidence in support of a claim, not as the claim itself, and what can be entered as evidence is constrained by what can be characterised: a physical limit, a separation the compromised authority cannot alter, a device that fails in a known direction, or test and analysis showing that one of those holds. The difference from an attestation is not rigour and it is not cost. It is where the work stops and what stopping means. Under an attestation the work stops when the list is finished. Under a demonstration it stops when the argument holds, and if the argument does not hold, no quantity of additional control attestations closes it. A measure closes it only when it establishes the missing constraint and can be credited in the argument on that basis.
This also determines what a change means. Under an attestation a plant modification raises the question of whether the control set still applies. Under a demonstration it raises the question of whether the argument still holds. The first is answered by inspection. The second occasionally requires the operator to conclude that it does not.
Why one cannot do the other’s work
A control is an item on a list: a framework requires it to be present or performed, and an assessor confirms that the requirement is met. A safeguard is something credited in a protection argument, either by carrying a figure into a calculation or by establishing a limit on what the plant can be driven to. The same equipment often answers to both descriptions. What is being claimed about it differs.
Where a safeguard is credited with probabilistic risk reduction, the credit rests on a model of how often it will be unavailable when demanded. That reasoning works where the future resembles the past and failures arrive at random: the safeguard degrades at some rate, the demand arrives independently of that degradation, and the two occasionally coincide. The methods used to credit a protective measure rest on that model, whether the inputs are measured, conventional or inherited. A credited failure probability rests on a stated test interval, failure data for the components, an architecture, and independence from the cause against which the measure is credited. Each is an assumption or property somebody can examine, and the credit is only as sound as the weakest of them.
That model holds for random failure. It does not select its moment or its failure mode after examining the safeguard. An adversary can. Threat intelligence and observed technique are records of what has already been done, describing a population that changes in response to what defenders do. Extrapolating from them assumes a stability that the subject does not have. Under an adversary the failure and the demand are the same event, selected together by something that examined the safeguard first. The attacker chooses the moment and chooses which failure mode to use. There is no interval over which the failure is distributed, because the failure is not distributed. No quantity of operating history produces a rate for an event that is chosen rather than sampled, and no conservative constant substitutes for a rate that does not exist as a kind. Numbers of this kind can be produced and are, by judgement or by modelling. What cannot be produced is one derived from the failure model that licenses the credit, or validated against observation of the thing it describes.
None of that makes a control programme ineffective. Removing a known vulnerability removes it. Segmentation can remove or constrain reachability. Access governance removes unnecessary standing credentials and constrains those that remain. Each of those reduces what an attacker encounters, and the reduction is real. What cannot be done is size it. A programme of this kind can be relied upon and it cannot be credited, and those are different claims about different things.
The two mechanisms
A bound is a limit on what the plant can be driven to. It may be physical, where the plant cannot deliver the outcome whatever it is told to do, or it may stand in the way, where something stops the sequence that the compromised authority does not reach. Either way it is a property of the plant and not of any document, and whether one exists is a different question from whether anyone has established that it does. Establishing that one holds is consequence work of a different kind from anything the programme does. A control programme acts on the event: it works to prevent it and, where it does not, to limit the loss and return the operation to a viable state. A bound acts on the plant before any event, by establishing that the state it can be driven to is one the operator can accept. Restoration requires the harm to be reversible. A bound does not, which is why a bound reaches past the boundary and restoration stops at it.
A bound holds whatever anyone commands through the pathway against which it was established. It does not depend on whether that authority was exercised by operator error, by an insider at a keyboard or by an external actor. A bound established against control-system authority does not answer for somebody with a wrench, and is not offered as one. The consequence side is established by ordinary process engineering. The reach of compromised authority is not. The work is scarce because the two have to be established together, not because either question is individually new.
The programme’s own split has instruments on each side, and the second is not preventive at all. It reduces the opportunity for a compromise to succeed, through patching, segmentation and access governance. It also reduces what a compromise costs once it has succeeded, through backup and restore, incident response, continuity planning and rehearsed recovery, all of which need a viable position still to exist. That second half is already inside the programme, and a substantial part of why the programme works where it works.
Segmentation sits across the two halves. It is bought and justified as a likelihood measure, and it can also constrain what a compromise can reach, which is consequence work. Whether it does the second depends on where the boundaries were drawn and what authority crosses them. Boundaries drawn for operational convenience constrain reach incidentally rather than by design, and nothing in the programme establishes which kind a given site has. Where a boundary is deliberately drawn against the named outcome and cannot be altered through the authority assumed compromised, it may form part of the bound.
Recovery breaks the pattern, because it produces evidence of its own function. A restore is attempted and it either completes or it does not, where a measure that works by preventing or detecting reports nothing when it misses. That evidence is bounded in the same direction as everything else: a restore test establishes that the restore works against the failure the tester chose, not that it works after an adversary who reached the backup chain first. Recovery is strongest where the causes are random.
Which mode governs a given exposure depends on whether the consequence is recoverable and whether it is acceptable as ordinary loss. Where both hold, unquantified reduction is sound: being wrong about its size costs money and time, and the position is recovered. Where the consequence cannot be recovered in a time the operation can carry, unquantified reduction leaves nothing to fall back on when it proves insufficient. Where it can be recovered but is not acceptable as ordinary loss, the position can be restored and the requirement is still not met: surviving the event was never the argument for permitting it.
That places the ordinary capabilities where they belong. Where contained ransomware, a lost historian or several days of degraded operation amount only to recoverable and acceptable loss, patching, segmentation, monitoring, access governance and tested backup are the appropriate instruments.
The programme is legitimate and it is capped. What it governs it governs, and it may not be credited as the reason an unacceptable outcome will not occur, because the limit is in the failure model rather than in the execution.
The two are not independent of each other in practice. The programme reduces the opportunity to acquire any authority and maintains the separations between them. The demonstration does not credit that reduction. It credits only an established property: that an authority capable of initiating the outcome cannot also reach or defeat what bounds it. A separation shown on a drawing is not such a property merely because segmentation, credential governance and defect management surround it. Those measures maintain conditions. The demonstration establishes which of them the bound depends on, and therefore what the programme has to maintain.
Two bounds may both hold and not be equally durable. A physical limit does not depend on preventing the acquisition of any authority. One that stands in the way does: it holds while the separation holds, and the separation is maintained by the programme. Both establish that one authority is not enough, and only one of them stays true without anybody’s continued attention.
The two questions also recur differently. The first keeps asking whether the programme is running and the floor is still there. It runs continuously and is reviewed on a calendar, because threats change and controls degrade. A demonstration is reopened when the plant, the authority structure or an assumption supporting the bound changes. The change may leave the argument intact, but that has to be established rather than presumed. Nothing requires the two questions to be put to the same review.
Why the range has an edge
Compliance operates as an audit loop. Obligations are set, an operator attests, an assessor tests, findings are raised, and the formal cycle repeats on a period measured in years.
The loop does not act on the threat as such. It acts on the distance between the list and the estate, finding where the two have drifted apart and causing them to be brought back together. Whatever protection the listed items supply, they supply it whether or not anybody is auditing.
Three gaps are open at any moment. The target gap was fixed when somebody selected a framework, a scope and a level. The delivery gap remains because work against that target is never quite finished: findings stay open, remediation runs late and exceptions are carried. The drift gap opens as the estate moves away from what was implemented against it.
Only the delivery and drift gaps are the audit’s business. The target gap is its premise. An operator can close every finding, carry no exceptions and have no drift on the day of the audit, and the target gap remains untouched, because nothing in the cycle was pointed at whether the target was the right one for this plant.
So compliance is not a promise that no gap exists. The target residual is present immediately after a clean audit, and it cannot be sized for the same reason the reduction cannot be sized. Delivery and drift may be corrected through the programme; the target gap can pass through every cycle untouched.
That is where the range acquires its edge. Can the operator carry being wrong, by an unknown margin, for as long as being wrong lasts?
The question has a physical form that requires none of this vocabulary. Ask what restoring the system returns you to. Inside the range, time to return to operation bounds the loss: the plant comes back, the position is recovered, and the recovery time objective is the operative number. Outside it, the system still comes back and the position does not. A site that has had a release may hold a complete and tested backup set and no route back to operation, because what was lost was not the configuration. It was the plant, or the people, or the permission to run. The recovery time objective remains defined and it now measures the return of the one thing that was never in question.
Recoverable here means the operation can be returned to a position it can continue from, in a time it can carry, rather than that nothing was damaged. Where the consequence is recoverable and acceptable, the answer is yes and the arrangement is sound in aggregate. Incidents occur inside open windows, they cost money and time, the position is recovered, and delivery or drift gaps can be corrected through the programme. Speed is not the issue: ransomware executes in minutes and the mode still holds, because what follows can be unwound.
Where the consequence cannot be undone, there is no aggregate for the loop to be right about on average. One occurrence in one open window ends the sequence, and the gap the audit eventually finds is one that has already been paid for.
There is a route out of that which does not work. An operator can state a risk, decide it is acceptable, record the decision and carry it. That decision requires a frequency for the named outcome, to compare against what the operation is prepared or entitled to tolerate. Inside the range the uncertainty can be carried, the decision is made on whatever evidence exists, and being wrong about the size of the reduction costs money and time. Outside it, the relevant frequency is the one that cannot be established in the form that would license acceptance, so there is no figure to accept against. What is left is to find out whether a bound already holds, and if none does, to make one hold: by removing what lets a compromise reach the outcome, by placing an independent limit in the path, or by changing the process so the outcome is not available. Declining to look is not one of them. It is a decision to carry an exposure nobody has sized.
Survival is one limb and acceptability is the other, and the second does not turn on size. An outcome is unacceptable where the operator is not entitled to govern it as an ordinary recoverable loss, whether because of safety, environmental, legal or public obligations, or because the operation has itself placed it outside what may be traded. A fatality may be survivable for a large company in every sense a balance sheet recognises, and that does not make it an ordinary payable loss against which an uncharacterised reduction in cyber likelihood can be optimised. The same holds for a major release, and for harm that lands outside the fence on people who were party to none of it. An essential service is the same case without a hazard in it. An essential-service operator may survive two weeks without supply in winter in every sense its accounts recognise, while the people who cannot heat their homes are not party to that arrangement. The operation may continue after any of them. That is not the recovery the second question is concerned with. Carrying the loss was never the available protection argument.
The criterion is not a regulatory threshold, and it is not seriousness either. Hazard-regulation thresholds are commonly set by substance and inventory quantity, to allocate regulatory attention across a population of sites. They do not determine whether a consequence can be undone. A site outside major-hazard regulation may still hold a fired boiler, a refrigeration plant charged with ammonia or a stored quantity of toxic gas, and the outcome available at that site is not made recoverable by the fact that no directive names it. Major accident hazard is where the criterion is most obvious, not what the criterion is.
Screening
Applying the criterion requires knowing what the exposure permits, which is what the determination establishes. That is less circular than it appears. Most of the range resolves without one, and where it does not is a describable place.
A determination establishes whether a bound exists, what it depends on, and whether it still holds in the plant as it runs rather than as it was drawn. It is finished when the answer and its basis are recorded, and it is owed where the consequence is real and unexamined. That is a large population and it is not the one regulatory attention is aimed at. It includes the below-threshold site whose ammonia charge has never been treated as a major hazard because no directive applicable to the site names it. It includes plant where mechanical protection was credited decades ago and has never been assessed against a pathway that did not exist when it was installed. It includes any site where the honest answer to what the control system can drive the process into is that nobody has looked.
Existing continuity work assists the first screen. Setting a recovery time objective requires knowing what an outage costs, which is a consequence determination that no framework treats as controversial. A number derived from what the operation can absorb, rather than from what the systems can restore, will sometimes show that the consequence is not recoverable at all.
The condition in which nobody has looked is the common one, and it is a fact about the lifecycle rather than about operators. Hazard studies examine control failure as a cause of deviation, case by case, and they are required at design and at modification. What they do not ordinarily assemble is the full range of states the control system can command, taken together and treated as a property of the system rather than as an input to one scenario. The question has no owner, so it has no answer, and its absence is invisible because nothing reports on it.
At the obvious ends of the question, screening is free and resolves in a sentence. A chlorine store or a fired heater screens immediately into the population that has to be examined, and the operator holding one already knows it, usually from a hazard study written for entirely different reasons. Whether a bound holds there is the open question; whether the question is worth asking is not. A conveyor line, packaging hall or distribution warehouse in which the worst control-system outcome is stopped production and an expensive week screens as fast in the other direction: nothing is unrecoverable or unacceptable, and compliance is the correct and complete instrument for the cyber consequences available there. No demonstration is owed there and none should be sold.
Neither end is decided by how dangerous the site is. A single-train plant whose only compressor can be damaged beyond repair through its control authority, and which carries an eighteen-month replacement lead time, resolves outside the range with no hazard involved at all. Nothing about that outcome is dangerous and nothing about it is permanent. The operation does not survive eighteen months of not running, and a compliance programme cannot establish that the loss will not occur, because what is needed is a limit on what a compromise can do to that machine.
The pathway is chosen for convenience
Consequence depends on how far one compromised authority reaches, and that distance is set by architecture rather than by control coverage.
There is no rule requiring a metrics collector to reach every system on a site with the authority to change it. That deployment is chosen because it is faster to build, simpler to maintain and quicker to hand over. The same logic produces flat administrative domains and remote access arrangements scoped to whatever was convenient at the time. None of these decisions is careless. Each is the efficient answer to the question that was actually asked.
This is how a capability appropriate inside the working range reaches beyond it. Monitoring and backup are the right instruments for a recoverable consequence. Monitoring and backup delivered as site-wide infrastructure with authority to change what they reach are also a pathway, and nothing about the range they were bought for constrains where they reach.
Convenience selects the architecture, and the architecture determines how far one authority reaches. As production and information systems couple more tightly without a corresponding limit on what travels with them, that distance grows, and nothing in an attestation asks what any of these components can reach.
What is offered instead
The standard explanation for stopping at the compliance minimum is that the money is not there. Sometimes it is, and where the binding constraint is engineering hours rather than budget, that is a real constraint and a different one. But two kinds of deferral are being confused, and only one of them is about cost at all.
Informed deferral is a stated risk, an assessed consequence, and a documented decision to accept it for now, revisited on a cycle. Major-hazard operators do this routinely, with capital backlogs whose work and cost can be sized but cannot all be funded at once. That is risk management working under constraint.
Default deferral has no assessment, therefore no stated risk, therefore nothing to decide against, therefore nothing happens. No decision was taken, because there was never a decision in front of anyone. The two look identical in the installed plant. The certification artefact allows the confusion to persist: it records a decision about conformity, but its date, signature and reference to an obligation give it the appearance of a decision about risk, without requiring anyone to state a consequence or accept one.
The obvious response is that the discipline should stop treating this as compliance and start treating it as a business risk, actively managed, owned and reviewed. Moving it onto a register does not close the gap. The entry closes nothing unless it states the consequence, identifies how a compromised authority can reach it, and records the established bound or the absence of one. A register can hold the result of a determination. It cannot substitute for one.
Attention is not the missing ingredient. The missing ingredient is a deliverable that can fail. An attestation can be incomplete. A rating can be disputed. Only a demonstration can be shown wrong.
This correction has been made before
An adjacent discipline has already run this experiment and published the result.
Offshore oil and gas in the United Kingdom was governed before 1988 by a prescriptive regulatory regime, mandatory, inspected and enforced, administered by the same department responsible for offshore energy development. The public inquiry into the Piper Alpha disaster, led by Lord Cullen, reported in November 1990. What followed changed the required deliverable: from conformity with prescription, to an argument by the dutyholder demonstrating control of the hazard. Compliance with a list of requirements had not been equivalent to control of what the list was written for.
The correction was structural. Safety regulation transferred to the Health and Safety Executive, separating it from that department, and the Offshore Installations (Safety Case) Regulations 1992 replaced prescription with a goal-setting obligation. Each dutyholder had to submit a safety case for acceptance, identifying the major accident hazards and demonstrating that the risks arising from them were as low as reasonably practicable. From 30 November 1995, existing installations within the regulations’ scope could not lawfully continue operating without an accepted safety case.
Conformance with the pre-1988 regime tested whether the list had been followed, not whether the hazard was controlled, and nothing about following the list without incident had shown that the two were the same question. The relevant point is not Piper Alpha. It is that a sector established that its governance mode was outside its working range, identified the mismatch precisely, and changed the mode. More than thirty-five years after Cullen reported, operational technology security still relies on the same kind of instrument in cases presenting the relevant problem: conformity with specified measures does not establish that an unacceptable outcome is bounded. The recurrent response is to ask whether the list should be longer or its enforcement firmer.
The mode has since transferred to security. The Office for Nuclear Regulation moved nuclear security regulation to an outcome-focused basis in 2017, covering cyber security alongside physical and personnel security and deliberately aligning it with the non-prescriptive safety regime beside it. The regime contains principles, expected outcomes and indicative arrangements, but the arrangements are not the deliverable: a dutyholder may depart from them if it can demonstrate that its own arrangement achieves the required outcome. What the regulator receives is a security plan setting out claims, arguments and evidence, and what it tests is whether the required outcome has been demonstrated. It is not a safety case for cyber security and should not be described as one. Establishing and maintaining that mode has required continuing work by regulator and dutyholders alike.
What the deliverable would be
State the outcome that must not occur. Identify the pathways by which one compromised authority can reach it. Establish that those pathways are limited by something that authority cannot also defeat. Test the bound, record the result, and repeat when the plant or an assumption supporting the result changes.
That is four sentences and it is the whole deliverable. It is answerable at any scale. A large operator answers it at greater effort than a small one, which is an argument for requiring it there rather than for substituting a control programme in its place. Scale changes the difficulty of the answer. It does not dissolve the question.
A limit can be physical: a vessel rated above anything the process can generate, an orifice bored to pass less than the outcome requires. Nothing needs to intervene, because the outcome is not among the things the plant can do. That holds only where the property doing the limiting is fixed by manufacture or installation rather than set in configuration. A valve travel limit held in a positioner and an inventory held down by a control loop are not physical limits in this sense, whatever they look like on a drawing. They hold while their configuration holds, and the question is whether the authority assumed compromised can change it. Where the limit instead stands in the way, it has to be beyond the reach of that authority. Being a different product, a different network or a different supplier does not put it there.
What the bound has to hold against is one authority, not the absence of consequence. One authority means everything a compromise of it reaches, however many hosts, credentials or actions that takes: once acquired, it does not have to be acquired again for each command issued through it. Further compromise inside the same authority adds nothing, because the actor already holds what it reaches. Two authorities are distinct where moving from one to the other requires defeating something neither of them administers. What stands between one authority and the outcome must therefore be either a physical limit no command can alter, or a second authority the first does not supply. The same actor may still acquire that second authority on its own. Preventing that is work for the programme. What the demonstration establishes is narrower: acquiring one authority is not enough. One is not an arbitrary number. Engineered protection already reasons about independence from a single initiating failure; the question here is whether the same logic survives when the initiating cause is compromise of an authority.
It is not a risk assessment and it is not a remediation programme. Bounding a consequence produces an envelope, not a position: it establishes what the plant can be driven to, not how likely anything is. Exposure and likelihood remain worth assessing inside that envelope, using the methods and evidence already established for the plant’s ordinary causes, and neither requires an adversarial frequency to be invented. Consequence is sequenced first because it is the axis on which information exists, and because it determines which consequences are available to one authority at all. What follows from an adverse result is the operator’s decision, taken with the same people who decide every other capital question at the site.
The assessment terminates. What it uncovers may not. Declining to look does not remove the exposure. It leaves the operator unable to say whether a capital decision already exists, and leaves the timing of that decision to the event.
The demonstration is not a permanent second programme running alongside the first. It answers a question once, and again when the plant or an assumption supporting the answer changes. What it does in between is resize the band that the control programme is responsible for.
A bound does not make a compromise consequence-free. It limits what the compromised authority can reach, so that what remains is recoverable and acceptable.
Where the required bounds hold, everything still available to one compromised authority falls inside the range the operation can recover from and may govern as ordinary loss, and the compliance programme is then operating in the mode the case requires. Not tolerated. Correct. What remains open is narrower and does not reopen the mode question: whether the programme’s own delivery introduces reach that the bounds did not assume.
A plant with mechanically constrained final elements, equipment rated above what the process can deliver, or protection the control system does not reach may already be bounded, by engineering carried out long before anyone considered a cyber pathway. The engineering does the work regardless of why it was done. What the operator lacks in that case is not protection. It is the statement, and everything that follows from having one: the ability to credit it, to test it against the next modification, and to say what the security programme is and is not responsible for.
The three results a determination can return are not symmetrical in cost. An established bound costs an assessment and buys a defensible position. An absent one requires change and may require capital. One that cannot be determined either way leaves the operator facing a decision about whether to spend more on determining it. No operator can know which of the three they face without asking.
Who receives it
A demonstration requires an assessor competent to evaluate it. That is the binding constraint, and nothing here resolves it.
A goal-setting regime works where the body receiving the argument can test it, and collapses back into attestation wherever it cannot. That body does not have to be a regulator. A site that runs a process hazard study already has a function that receives an argument about consequence and has standing to reject it, and any operator large enough to sanction capital has somewhere that decides whether an engineering claim holds. What none of them currently does is receive this argument, because nobody asks them to.
The regulatory case shows the same failure at scale. The obligation under NIS2 is stated in goal-setting terms, requiring measures appropriate and proportionate to the risk. What reaches the operator can be a control list all the same, produced by national transposition, by assessors who need something determinate to test against, and by a market that sells against enumerable requirements. Determinacy is demanded from below and granted from above, because the alternative is a regime nobody can administer.
The nuclear case shows what refusing that demand costs. It required a regulator to build and maintain the competence to receive an argument rather than an inventory, and the burden was not only on the assessor: that transition took years and drew heavily on the regulated population.
Competence of this kind is built by doing. The population able to evaluate a demonstration is made out of the people who have produced and reviewed them, which means the constraint resolves on the operator side before it resolves at regulatory scale. It begins where the consequence is already recognised, the hazard is already documented, and an assessment function already receives an argument about it. That is a small population, and it is the one that would have to move first.
That population is further along than the rest. Where a site relies on instrumented protection, the functional safety standards already require work in this territory: the independence assumed in the risk assessment must be justified, cyber security risk to the safety instrumented system must be assessed, and the lifecycle is subject to competent assessment. A receiving body therefore already exists, in the assessment that examines whether the lifecycle was executed rather than whether an inventory is complete. So the question is not unaddressed there. Its components are present, and they stop short of requiring the assembled claim: that the independence on which the credit depends survives everything reachable through the authority assumed compromised. That is a different failure from the one everywhere else, and it is the more tractable of the two.
There is a precedent for building the rest. Functional safety assessment was established by the standards as a defined lifecycle activity with an explicit competence requirement. Certification schemes and a professional market developed around it afterwards, and the form of the assessment matured through use, because a requirement existed and somebody had to be able to receive it. The requirement came first there. Here it has not.
What is missing
Methods are not the missing part. Consequence-first work exists in operational technology. Consequence-driven Cyber-informed Engineering, developed at Idaho National Laboratory, begins from the outcomes an operator cannot tolerate and works back to what would have to be engineered out. Cyber process hazard analysis adapts the deviation structure of a process hazard study to admit compromise as an initiating cause, and as a means of defeating the safeguards credited against the resulting consequence.
Both begin from the right place. Consequence-driven Cyber-informed Engineering can end at the same place, the pathway actually engineered out, though nothing requires it to and nothing tests or records the result when it does. Cyber process hazard analysis cannot: its deliverable is a credit against an existing safeguard, the same quantity that cannot be soundly derived for an event chosen rather than sampled. Nothing requires either method in the first place. Across operational technology no general obligation requires a consequence demonstration, no settled function receives one, and no common lifecycle rule invalidates the result when the plant changes. An operator may never have heard of any of these methods without breaching anything.
The mode of governance they would serve is not experimental. It is taught, it is mandatory in industries that decided some decades ago that lists were not sufficient for cases of this kind, and one of them has already extended it to cyber. In operational technology the nearest obligations stop short of the question, and the assessments that receive them are not looking for the answer. The instrument exists. The obligation does not reach it.
One arrangement in which a bound is credited and not established, and what the calculation requires of anyone who wishes to retain it, is worked through in Independence Cannot Be Discounted. Why an individual control cannot be sized on the likelihood axis, and what one costs to apply rather than to buy, is treated in The Control Nobody Argues About.