Risk & Vulnerabilities
Cyber risk register, threat catalogue, vulnerability management with SLA timers, mitigation plans, supply-chain and personnel risk (Module 8.5–8.6).
22 of 22
| ID | Asset / System | Threat | Inherent | Residual | Due | Status |
|---|---|---|---|---|---|---|
| RSK-001 | Site Monitoring Workstation | Denial of service against SCADA gateway | Medium | High | 23 Sept 2026 | Mitigation In Progress |
| RSK-002 | Turbine Governor SCADA | Denial of service against SCADA gateway | High | Low | 06 Oct 2026 | Closed |
| RSK-003 | Corporate ERP | Malicious firmware update via compromised vendor channel | Medium | High | 01 Sept 2026 | Mitigation In Progress |
| RSK-004 | Site Office IT | Man-in-the-middle on unencrypted communication path | Medium | High | 16 Sept 2026 | Accepted |
| RSK-005 | Hydro Governor Control System | Supply-chain compromise of third-party component | Medium | High | 08 Sept 2026 | Accepted |
| RSK-006 | Security Operations Center Platform | Man-in-the-middle on unencrypted communication path | Low | Medium | 10 Dec 2026 | Accepted |
| RSK-007 | Site Network Gateway | Loss of monitoring visibility due to sensor outage | Critical | Critical | 08 Sept 2026 | Open |
| RSK-008 | Turbine Governor SCADA | Unauthorized remote access to control network | Medium | High | 16 Sept 2026 | Accepted |
| RSK-009 | Site Business Systems | Man-in-the-middle on unencrypted communication path | Medium | Low | 10 Dec 2026 | Closed |
| RSK-010 | Security Operations Center Platform | Supply-chain compromise of third-party component | Medium | High | 01 Sept 2026 | Open |
| RSK-011 | Site Business Systems | Denial of service against SCADA gateway | High | Low | 26 Oct 2026 | Closed |
| RSK-012 | Site Network Gateway | Unauthorized remote access to control network | Low | Low | 06 Oct 2026 | Closed |
| RSK-013 | Inverter Control Network | Legacy protocol exploitation (no authentication) | Medium | High | 23 Sept 2026 | Mitigation In Progress |
| RSK-014 | Security Operations Center Platform | Supply-chain compromise of third-party component | Medium | High | 10 Dec 2026 | Mitigation In Progress |
| RSK-015 | Captive DCS | Ransomware propagation from IT to OT | Medium | High | 23 Sept 2026 | Mitigation In Progress |
| RSK-016 | Site ERP Gateway | Loss of monitoring visibility due to sensor outage | High | Critical | 01 Sept 2026 | Mitigation In Progress |
| RSK-017 | DCS — Unit 1-5 Control | Legacy protocol exploitation (no authentication) | High | Critical | 08 Sept 2026 | Open |
| RSK-018 | Site LAN & File Server | Physical tampering with field device | High | Critical | 16 Sept 2026 | Open |
| RSK-019 | Coal Handling PLC Network | Ransomware propagation from IT to OT | Medium | High | 26 Oct 2026 | Mitigation In Progress |
| RSK-020 | Site LAN & File Server | Loss of monitoring visibility due to sensor outage | High | Low | 08 Sept 2026 | Closed |
| RSK-021 | Substation RTU Network | Man-in-the-middle on unencrypted communication path | Medium | High | 26 Oct 2026 | Open |
| RSK-022 | Identity & Access Management | Denial of service against SCADA gateway | High | Critical | 06 Oct 2026 | Mitigation In Progress |