Proceedings of the
European Safety and Reliability Conference (ESREL2026)
14 – 19 June 2026, Braga, Portugal

Towards Harmonizing Models and Metrics in Physical Security and Cybersecurity Risk Assessment: An Approach for Cross-Domain Risk Alignment

Dustin Witte

Institute for Security Systems, University of Wuppertal, Germany.

witte@uni-wuppertal.de

Thomas Termin

Institute for Security Systems, University of Wuppertal, Germany.

thomas.termin@witte-automotive.de

Daniel Lichte

Institute for the Protection of Terrestrial Infrastructures, German Aerospace Center (DLR), Germany.

daniel.lichte@dlr.de

Kai-Dietrich Wolf

Institute for Security Systems, University of Wuppertal, Germany.

wolf@iss.uni-wuppertal.de

ABSTRACT

Systematic risk assessment is an essential tool to design appropriate protection for critical systems against malicious attacks, both physical and cyber. Although the assessment of physical security and cybersecurity risk both rely on attacker-centered models for analyzing threats and vulnerabilities, the methodologies and standards of these two fields have evolved largely in isolation from each other. This separation complicates the determination of comparable risk levels, which is however becoming increasingly important as systems become more interconnected. Aiming for a unified perspective on security risk, this paper takes up representative standards and methods - namely MITRE ATT&CK and CVSS in cybersecurity, and ASD and EASI in physical security - highlighting structural analogies and domain-specific divergences in vulnerability analysis. Particular focus is given to the consideration of uncertainties arising from adversarial behavior, scenario assumptions and model limitations. Based on the identified analogies, we show how vulnerability could be consistently represented across both domains, and propose a unified model regarding three aspects of physical security and cybersecurity: intrusion paths, protection functions and assessment metrics. We apply our proposal to an illustrative example and discuss its potential to support coherent cross-domain risk assessment for balanced decisions on physical security and cybersecurity measures in a security-critical environment.

Keywords: Physical Security, Cybersecurity, Vulnerability Assessment, Security Convergence, Decision Support.



Download PDF