A panel at S4x26 explored whether a rapid 0–10 impact score could bring clarity to industrial cybersecurity events, helping distinguish minor disruptions from truly consequential attacks.

Impact score insights
- The OT cybersecurity community plays a significant role in shaping public perception of incidents and must take responsibility for reducing unnecessary hype.
- A simple, rapidly generated impact score could help distinguish minor disruptions from truly consequential industrial cyber events.
- Any effective scoring system must balance speed, credibility and clarity while acknowledging the uncertainty that surrounds early incident reporting.
When headlines scream about cyberattacks on water systems or pipelines, how does the general public know whether the incident was catastrophic or relatively minor? That question framed an interesting panel discussion at the S4x26 industrial cybersecurity conference, where industry leaders proposed a new way to measure and communicate the real-world impact of OT cyber incidents.
“A question,” moderator and S4 founder Dale Peterson began. “How does your mom or your congressperson know the impact of an OT cyber incident? Whether it’s trivial, minor or huge?”
Peterson argued that the cybersecurity community itself bears responsibility for amplifying fear, uncertainty and doubt, or FUD, as the cyber community calls it.
“These stories just don’t pop out of nowhere,” he said. “A lot of times … maybe even some of you in this room contact the press and say, ‘This is a huge incident.’ So since we are largely responsible for the FUD, I think it’s incumbent upon us to also find a way to reduce it.”
Richter scale for OT
The proposed solution is an OT incident impact score, a simple 0–10 rating designed not for cybersecurity experts, but for the general public.
“It has to be easy to understand,” Peterson said. “What’s easier than a zero to 10 score?”
Unlike existing post-incident analyses that can take weeks or months, the goal is speed. “This has to come out within 12 hours,” he said, suggesting a crowdsourced model where vetted OT professionals quickly score incidents based on severity, reach and duration.

The formula is straightforward: Rate each category from zero to 10, multiply the three numbers together, divide by 100 and produce a single score. Peterson displayed early examples that he had scored. Colonial Pipeline, he said, would score a 3.9. The Clorox cyber incident, which disrupted operations but had limited broader reach, a 2.6. A widely reported Texas water tank overflow in Muleshoe would be a 0.0.
“That’s one person’s view of the score,” Peterson acknowledged. “But now I hope you’re ready to score some incidents.”
A cybersecurity tool for the media
Kelly Jackson Higgins, a veteran cybersecurity journalist and editor-in-cheif at Dark Reading, said such a score could help reporters decide how aggressively to pursue a story.
“Having a score helps us decide what type of reporting resources we want to put toward it,” she said. “Is this a big story? Is this something we should hold on to and see how it evolves?”
She emphasized that industry media differ from general outlets chasing clicks. “From my perspective at Dark Reading, I’d be like, ‘Wait. What really happened here? Is this a big story?’”
Still, she raised questions about credibility, suggesting that endorsements from standards bodies or government agencies could help strengthen adoption.
Emergency management perspective on the impact score
Robert Hanson, associate program leader for national security infrastructure at Lawrence Livermore, drew on his experience preparing for national-level incidents. He said an objective score could help cut through noise and give people a clearer picture of what’s actually going on.
“There’s a lot of noise in the space right now,” he said. “[Emergency managers] are not cyber experts, so they can’t wade into a Dark Reading article … and say, ‘OK, this one matters. This one doesn’t.’”
But he cautioned that accuracy and timeliness are critical, as early reports don’t often have the complete picture when it comes to cybersecurity incidents.
“Does the score change once the facts change?” he asked. “Accurate information is going to be important.”
Peterson acknowledged the limitations. “This is not going to be perfect,” he said. “If you want to do it quickly … it’s not going to have the rigor of [a physical measurement].”
The score, he reiterated, is not intended to guide tactical response decisions. “It was geared at my mom,” he said. “’Oh Mom, don’t worry. It’s a 0.0.’”
Learning from disaster science
Munish Walther-Puri, head of critical digital infrastructure for the TPO Group, inspired the concept in an S4 talk from a previous year. He framed the effort as part of a broader attempt to “bring disaster science to cybersecurity.” Looking to models like the Richter scale, he noted that today’s standardized measurements emerged only after years of trial and error.

“The most important thing is that it went through iterations,” he said. “My goal was to try and microwave that. How do we get to something more rigorous, more reliable?”
He also stressed that measurement forces clarity. “How do we get better at measuring it, not should we measure it?”
Should an impact score be independent?
Panelists debated whether government agencies should own such a metric, but Hanson suggested independence might be an advantage. A group without federal limitations can make a judgment, he said, without navigating classified information or internal equities.
Peterson closed with a call to action, asking the assembled group to use the new site when the next cyber incident occurs but acknowledging that the framework will evolve. The scoring platform is now live at impact.icssecurityadvisory.com, where vetted OT professionals can log in and begin rating incidents based on severity, reach, and duration.
“I’m sure what it is now will not be what it’ll be in six months,” he said. “But this is how we learn. This is how we make progress.”
The discussion underscored a growing recognition that industrial cybersecurity needs not just better defenses, but better ways to communicate consequences. If adopted, the impact score could mark an early step toward bringing greater clarity and less noise to how OT cyber incidents are understood beyond the industry.
OT IMPACT SCORE WEBSITE
impact.icssecurityadvisory.com
LEARNING OBJECTIVES
- Understand the rationale behind creating a simple, rapid “impact score” to communicate the real-world consequences of OT cyber incidents to the public.
- Recognize the challenges of balancing speed, accuracy and credibility when measuring and reporting industrial cybersecurity events.
- Evaluate how clearer impact metrics could influence media coverage, public perception and emergency response decision-making.
CONSIDER THIS
How can we communicate the true operational impact of cyber incidents in a way that reduces hype while still driving appropriate action?