| Asset ID | Common potential points of failure and known vulnerabilities | Threat Type | Threat sources | Consequence | Current Risk Likelihood | Risk Rating | Treatment Option & reference |
| People | Personnel with low technical skills | Availability | T1,T2 | Moderate | Almost certain | High | Reduce A3 |
| | Careless about their personal informations such as user ids, password etc. People write it on stick notes paste on their desks | | T1,T2 |
| | short term contract employees | | T1,T2 |
| | People who resigned from the company can reveal the confidential information | Confidentiality | T1,T2 | Moderate | Likely | High | Reduce A1 |
| | Employees getting help from people outside organization to get their job done can lead to risk of revealing confidential information | | T1,T2 |
| | Unaware of consequences if something goes wrong while handling critical things | | T1,T2 |
| | All the employee activities such as system access, contacts etc should be monitored constantly | Integrity | T1,T2 | Moderate | Likely | High | Reduce A2 |
| | Unethical way of using organizations software or try to break it using virus or malicious code | | T1,T2 |
| Management | Various policies related to security issues have to be taken into consideration | Integrity | T1, T2, T3, T4, T5 | Catastrophic | Likely | Extreme | Reduce B2 |
| | No efficiency in work done by the employees | | T1, T2, T3, T4, T5 |
| | No proper agreements at various levels such as service level agreements | | T1, T2, T3, T4, T5 |
| | Poor allocation security roles and responsibilities, No proper authorization based on designation | Confidentiality | T1, T2, T3, T4, T5 | Catastrophic | Likely | Extreme | Reduce B1 |
| | Lack of appropiate response to the security issues | | T1, T2, T3, T4, T5 |
| | On frequent basis proper reviwening all operation procedures, implementations and planning | Availability | T1, T2, T3, T4, T5 | Catastrophic | Likely | Extreme | Reduce B3 |
| | weak and lame personnel in security committee | | T1, T2, T3, T4, T5 |
| Building/Site management | Lack of proper maintainence handeling | Integrity | T1, T2 | Minor | Possible | Medium | Reduce C2 |
| | Natural disasters | | T1, T2 |
| | losses and harm caused to personnel and service due to Environmental hazards | Availability | T1, T2 | Moderate | Unlikely | Medium | Reduce C3 |
| | No proper planning and designing | | T1, T2 |
| | No proper security for property and infrastructure | | T1, T2 |
| | Environment in office not secured or less secured | Confidentiality | T1, T2 | Minor | Possible | Medium | Reduce C1 |
| Information Management | Constantly monitoring and auditning the softwares | Integrity | T1, T2 | Moderate | Almost Certain | High | Reduce D2 |
| | Strong Password policy should be entact and enforced | | T1, T2 |
| | Ex-employees access id and password sould be regularly monitered to avoid un-authorized and illegally actvities | | T1, T2 |
| | Access control should be limted to concerned people to protect un authorized access | | T1, T2 |
| | Any software update should be done from licensed copies only | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce D3 |
| | Installing inappropriate hardware/software or without proper knowledge | | T1, T2 |
| | Recovery plan or devices should be continously monitered | | T1, T2 |
| | unorganized and inadequacy in data management may leads to data breach | Confidentiality | T1, T2 | Moderate | Almost Certain | High | Reduce D1 |
| | Policies and procedures should be up to data and document | | T1, T2 |
| | | | T1, T2 |
| Communication and Network | Mis interpretation of information may results in breach of the data | Confidentiality | T1, T2 | Minor | Likely | Medium | Reduce E1 |
| | loop holes in policies, rules of network equipment. | | T1, T2 |
| | weak segment network leads to network valunerability | | T1, T2 |
| | Unprotected wireless channels grant unapproved access, network breach. | | T1, T2 |
| | Unethical hacking, cyber attacks, interruptions in data transmissions | Integrity | T1, T2 | Moderate | Almost Certain | High | Reduce E2 |
| | No proper time to time network activity analysis | | T1, T2 |
| | Eradicating irrelevant information | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce E3 |
| | Obstruction from different devices | | T1, T2 |
| SCADA Application Software | Lack of new technology | Integrity | T1, T2 | Major | Likely | High | Reduce F2 |
| | Use of licensed software | | T1, T2 |
| | Challenges in maintaining the modern software | | T1, T2 |
| | Network crash | Availability | T1, T2 | Major | Likely | High | Reduce F3 |
| | User fails to cope up with the required often changes | | T1, T2 |
| | Lack of knowledge of the new introduced software | | T1, T2 |
| | Difficulty in software maintenance | | T1, T2 |
| | Problem faced through stern security | Confidentiality | T1, T2 | Moderate | Likely | High | Reduce F1 |
| SCADA Hardware including operating System | Application Inconsistency | Integrity | T1, T2 | Moderate | Likely | High | Reduce G2 |
| | Management failure | Confidentiality | T1, T2, T3, T4 | Moderate | Almost Certain | High | Reduce G1 |
| | possibility of system accessible by many | | T1, T2 |
| | Improper access codes | | T1, T2 |
| | Failure of equipment | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce G3 |
| | Lack of extra quipment | | T1, T2 |
| | Power failures | | T1, T2 |
| | No proper monitoring and planning | | T1, T2 |
| SCADA Field Devices | Failure in security hardening | Confidentiality | T1, T2 | Moderate | Likely | High | Reduce H1 |
| | Having same default security configuration for every system | | T1, T2 |
| | Using older username and password | | T1, T2 |
| | physicial damage | Availability | T1, T2 | Moderate | Almost Certain | High | Reduce H3 |
| | access to the service | | T1, T2 |
| | Hardware and Software application | Integrity | T1, T2 | Minor | Likely | Medium | Reduce H2 |
| | use of other devices for operating | | T1, T2 |
| Supporting Utilities | power deficiency | Integrity | T1, T2 | Moderate | Likely | High | Reduce I2 |
| | backup power defieciency | Availability | T1, T2 | Major | Likely | High | Reduce I3 |
| | Capacity planning | | T1, T2 |
| | Damage to utilities which are used in support | | T1, T2 |
| | Breach of confidentiality | Confidentiality | T1, T2 | Minor | Possible | Medium | Reduce I1 |