Cyber and physical security are increasingly interdependent as physical operations, facilities, and security systems rely on connected technologies for monitoring, access, control, automation, and decision-making. A compromise originating in the cyber domain can create physical or operational consequences, while physical vulnerabilities can expose or enable access to cyber systems.
Attack Scenario: An attacker exploits a vulnerability in a critical operational technology (OT) system and gains access. The network is compromised, causing operator loss, view, and control. Further, the attacker directly manipulates operational performance of high-risk systems causing dire consequences including physical damage resulting in a cyber-physical attack.
Understanding these dependencies is central to cyber-physical security. OPACC evaluates how systems, assets, vulnerabilities, and potential attack pathways interact across domains to identify risks that may not be apparent when cyber and physical security are assessed independently.