Assessing Cyber Risks in Hydropower Systems Through HAZOP and Bow-Tie Analysis
Kwabena Opoku Frempong-Kore, Rishikesh Sahay, Md Rasel Al Mamun, Bell Eapen

TL;DR
This paper compares HAZOP and BowTie risk assessment methods for cyber threats in hydropower systems, highlighting their complementary strengths and vulnerabilities under cyber-attack scenarios.
Contribution
It introduces a practical two-stage approach to adapt traditional safety methods for cybersecurity assessment in hydropower control systems.
Findings
Cyber extensions reveal coordinated attack scenarios that traditional methods miss.
Barriers sharing network infrastructure can be compromised, challenging defense-in-depth.
Both methods together provide comprehensive cyber risk coverage.
Abstract
With the widespread use of software systems in critical infrastructures such as hydropower plants has brought many advantages, yet it has exposed these systems to cyber threats. Cyber risk assessment & mitigation is important to identify cyber threats and protect these systems from unwanted incidents. This paper evaluates and compares the two risk assessment methodologies namely Hazard and Operability Study (HAZOP) and BowTie analysis for identifying cyber induced threats in hydropower systems. We selected these two methodologies because they offer a complementary perspective for cyber-safety risk assessment. Each method is first applied in traditional form to identify hazards, barriers, and threat scenarios arising from accidental causes, then extended to examine how findings change under cyber-induced causation. The traditional HAZOP identifies 18 deviations across five control…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
