Engineer in an industrial control room
|

Designing Safe AND Secure Cyber-Physical Systems

A modern car, factory line or medical device is no longer just a physical system — it is a computer wrapped in metal, connected to a network. That connection is a feature and a threat: every link is a way in. Designing safe and secure cyber-physical systems means engineering safety and security together from the start, because in a connected system a security breach can become a safety failure.

Safety engineers have decades of method; security is now equally essential and increasingly governed by standards. Here is how the two come together.

Key Frameworks and Concepts

Framework / conceptWhat it covers
IEC 62443Security for industrial automation and control systems
ISO/SAE 21434Cybersecurity engineering for road-vehicle electronics
TARAThreat Analysis and Risk Assessment in the concept phase
Secure by designBuilding threat modelling and security in from the start
Attack & fault treesModelling how breaches and failures propagate — together
The standards and methods behind safe, secure cyber-physical systems.

Why Safety AND Security, Together

In a safety-critical connected system, the two are inseparable. An attacker who disables a brake controller has caused a safety failure by a security route. Engineering them in separate silos leaves exactly the gap attackers use, which is why modern practice unifies the safety and security lifecycles.

The Standards

Two stand out. IEC 62443 governs security for industrial automation and control systems — the world of plants and critical infrastructure. ISO/SAE 21434 sets cybersecurity engineering requirements across the lifecycle of road-vehicle electronics. Both push the same idea: manage cybersecurity risk as a disciplined engineering activity, not a bolt-on.

TARA: Threat Analysis and Risk Assessment

Just as FMECA systematically surfaces how a system can fail, TARA systematically surfaces how it can be attacked — identifying assets, threats, attack paths and the security requirements needed to counter them, starting in the concept phase. It is the security mirror of safety analysis.

Attack Trees Meet Fault Trees

The most powerful model-based approaches unify the two: an attack tree (how an adversary reaches a goal) and a fault tree (how a failure propagates) modelled together, with shared countermeasures. A model-based approach links physical behaviour, data flows and attack paths into one design you can analyse.

Build It Into the Requirements

The cheapest place to address security is the same as for safety: the requirements. Secure-by-design means deriving security requirements from threat analysis early and tracing them through the design, exactly as you would safety requirements — not patching them in after a pen test.

A Concrete Scenario: The Connected Car

Make it real. A modern car’s infotainment unit is connected to the internet and, through the internal network, can reach the braking controller. An attacker who compromises the infotainment unit and pivots across that network has not just stolen data — they can interfere with braking. The safety hazard (loss of braking) and the security threat (network intrusion) are the same incident seen from two angles. Analyse them separately and you miss the path between them; analyse them together and you design the network segmentation that closes it.

Integrating the Safety and Security Lifecycles

This is why modern practice runs the two lifecycles in lock-step. A fault analysis asks how the system fails; a threat analysis (TARA) asks how it is attacked; and the strongest model-based methods link the resulting attack trees and fault trees so a single design carries countermeasures for both. Standards like ISO/SAE 21434 bake this in by requiring cybersecurity work across the same lifecycle phases that functional safety already covers.

Where to Start

Begin in the concept phase, not after a penetration test. Run a TARA alongside your hazard analysis, derive security requirements from the threats just as you derive safety requirements from hazards, and trace both through design and verification. Security that is engineered in from the first requirement is a fraction of the cost of security bolted on after release.

Frequently Asked Questions

What is a cyber-physical system?

A cyber-physical system combines physical processes with computation and networking – cars, industrial control systems, medical devices, robots. The tight coupling of physical and digital is what makes both safety and security essential and interdependent.

Why must safety and security be designed together?

Because in a connected system a security breach can cause a safety failure – an attacker disabling a safety function is a safety incident by a security route. Engineering them separately leaves gaps; unifying the safety and security lifecycles closes them.

What is TARA in cybersecurity?

TARA (Threat Analysis and Risk Assessment) is a systematic, concept-phase method to identify assets, threats, attack paths and the security requirements needed to counter them – the security counterpart to safety analyses like FMECA, and central to ISO/SAE 21434.

Related guides

Share this article

Similar Posts

Leave a Reply