POV Whitepaper Series • August 2026

Rethinking OT Cyber Risk Beyond CVSS

The Operational Context Gap — the distance between what cybersecurity tools can describe and what operations needs to know before that data becomes a decision.

Executive summary

Industrial organisations can now see more of their operational technology than at any point in the last two decades — yet CISOs and plant leaders still cannot say, with confidence, which cyber conditions actually threaten their operation right now. This is not a visibility failure. CISA has published over 12,000 known OT/ICS vulnerabilities since 2010, and severity keeps climbing. The problem is that severity is not consequence.

A critical finding on an isolated, redundant display and an identical finding on a single-point-of-failure safety controller are not the same risk. Closing the gap means building the context that has lived only in experienced engineers’ heads: what an asset does, what depends on it, and what would genuinely happen if it failed.

“Visibility tells an organisation what exists. Context tells it what matters. Intelligence tells it what to do about it.”

This paper examines why CVSS, alert volume and generic criticality break down inside OT — a conclusion CISA itself reached in June 2026 when it formally retired mandated CVSS-based prioritisation — walks through five documented incidents, and introduces the Operational Context Stack.

01 — Visibility paradox

Seeing more hasn’t meant knowing what matters

Passive, protocol-aware monitoring now identifies most devices automatically, and CISA’s advisory pipeline scaled to over 500 ICS advisories in a single year for the first time. Average CVSS severity has risen steadily since 2010.

Yet ~45% of independent OT assessments still uncover fundamental visibility gaps. Information has grown faster than any organisation’s capacity to interpret it — more sensors and advisories have not produced a proportional increase in knowing what actually matters.

02 — Five capabilities

Seeing an asset is not understanding an asset

Five capabilities are routinely treated as one: Discovery (something is there), Identification (it has a name), Classification (it has a type), Contextualisation (it has a place), and Operational Understanding (it has a meaning).

Modern tooling is strong at the first three. A sensor can identify a controller’s exact model and firmware — but cannot tell you, unaided, that this specific controller governs an emergency shutdown sequence with no manual backup, while an identical unit two buildings away controls parking-lot lighting.

03 — The gap

The Operational Context Gap

The gap is the distance between what cybersecurity data can technically describe and what operations, engineering and executive functions need to know before that description becomes a decision. The resolving information — process role, failure mode, redundancy — has always lived in engineering drawings and operator memory, not in any system security tooling can query.

Each stakeholder feels it differently: CISOs cannot translate a vulnerability count into a board-level business case; SOC analysts face alert fatigue with no reliable way to separate routine anomalies from real threats; plant managers see patch requests disconnected from operational reality.

04 — Why models break

Why traditional risk models break down in OT

CVSS: describes theoretical severity, independent of environment. In June 2026, CISA’s Binding Operational Directive 26-04 retired mandated CVSS-based prioritisation, replacing it with exposure, exploitation and mission-impact questions.

Counts, criticality, threat intel: raw counts measure exposure trends but not what to do today — only ~3% of one year’s ICS vulnerabilities required truly immediate action once context was applied. Static criticality misses that importance shifts with production schedule and redundancy. Sector intel says who is out there, not whether they can reach a specific asset.

05 — Cyber vs operational risk

Same CVE, very different operational risk

A CVSS 9.8 on an isolated HMI duplicated by physical gauge panels is a low-priority finding. The identical 9.8 on an HMI with vendor remote access, on a flat network shared with IT, and no manual override for a pressure-relief valve, is an emergency.

Two assets can carry identical technical findings and warrant entirely different responses — invisible to any tool that stops at the technical layer.

06 — The stack

The Operational Context Stack

Six layers, ordered from easiest to automate to most cross-functional: Asset → Relationship → Process → Criticality → Threat → Consequence.

Most organisations can answer through Relationship (topology, reachability). Very few can answer Consequence in board-ready terms without days of manual work per asset. That distance between layer two and layer six is the gap in structural form.

07 — Fusion

From technical signals to operational intelligence

Most organisations already own the raw material — OT telemetry, asset inventory, engineering docs, threat intel, business criticality — sitting in different systems owned by different teams. Collecting more data widens the gap; each new feed adds another dashboard to manually reconcile.

Data fusion, not collection, is the unlock: a persistent layer that joins telemetry to the process it belongs to, so a new finding inherits its operational meaning the moment it appears.

08 — Human problem

Five functions, five vocabularies

SOC, cybersecurity, engineering, operations and executive leadership look at the same environment and see materially different things. OT incident response plans are often absent, engineers rarely trained in cyber response, and assumed IT/OT segmentation frequently fails pen testing.

IT and OT teams don’t primarily need more shared data; they need shared insight built around what an asset does operationally. Security tooling must feed structured operational context as native output, not leave teams reconciling spreadsheets after the fact.

09 — New model

Operational Materiality

Rather than a false-precision score: a qualitative, banded model — Low / Elevated / Material / Severe — based on the combination of reachability, process role, failure consequence, plausible adversary, and timing. CVSS and threat intel stay as supporting evidence, never as the full judgment.

10–12 — Destination

Cyber-Aware Operations & roadmap

“Cyber-Aware Operations is not a bigger SOC. It is an operation that understands its own cyber risk the way it already understands its own safety risk.”

Five architectural principles: context as a persistent layer; fusion over collection; bidirectional flow between engineering and security; role-specific views from one shared foundation; design for degradation (recognise compensating controls).

Roadmap: Assess maturity per Stack layer (months 1–2) → Contextualise the smallest asset set carrying the largest risk (2–6) → Prioritise with Materiality bands, even manually (4–8) → Operationalise into an auto-updating context layer (8–16) → Continuously learn from every incident.

Case studies

Five documented incidents through the context lens

Colonial Pipeline (2021): an IT-only ransomware event shut 45% of the US East Coast fuel supply — driven not by what attackers reached, but by what the organisation could not prove they hadn’t. A Relationship-layer (segmentation confidence) failure.

Triton/Trisis (2017): safety-controller malware undetected for two months because the first SIS anomaly was investigated as mechanical fault, not a cyber event. Engineering and security had no channel connecting safety process to adversary behaviour.

Ukraine grid (2015–2016): BlackEnergy3 reconnaissance dwelled for months before breakers were opened; a year later Industroyer manipulated grid protocols directly. Process/consequence knowledge of topology and manual restoration blunted impact.

Norsk Hydro (2019): LockerGoga never touched controls directly, yet cost ~$71M H1 by forcing 160 plants to manual operation. Resilience — trained manual procedures, strong backups — was the Consequence-layer mitigation.

Oldsmar water (2021): an operator watching a moving mouse cursor caught a lye-dosing change automation missed. Decades-old process-safety layering (redundant pH alarms, 24–36h physical delay) worked as designed — context that predates cybersecurity tooling.

Conclusion

A meaning problem, not a data problem

“The industry does not have a data problem anymore. It has a meaning problem. And meaning cannot be scanned for — it has to be built.”

Organisations that internalise this distinction now will be the ones able to say, with confidence, what a given vulnerability actually means to their operation.

Let’s talk

How you think about OT security — we’d like to hear it. Reach out at contact@velosshield.com.

About Velos Shield — OT monitoring designed around trustworthy evidence, operational context and persistent memory.