Industrial Cybersecurity & OT Risk worked example

Security Control Gap with required ot security controls of 60 controls: a worked example

This worked example runs the security control gap numbers for a tougher week than the baseline: required ot security controls of 60 controls instead of the typical 120 controls. Estimate the percentage gap between required OT security controls and implemented controls.

The inputs for this scenario

  • Required OT security controls: 60 controls (the input this scenario stresses; the baseline uses 120)
  • Implemented OT security controls: 84 controls (held at the documented default)
  • Accepted compensating controls or exceptions: 8 controls (held at the documented default)

Working through the calculation

  • The calculation starts from the formula this tool documents: Security control gap = required OT security controls - implemented OT security controls - accepted compensating controls or exceptions.
  • Security control gap rate works out to -300 % at these inputs, and this is the headline figure for the scenario.
  • Absolute margin works out to -24 value at these inputs.
  • Available amount works out to 60 value at these inputs.
  • Required amount works out to 84 value at these inputs.

How this compares with the baseline

  • Against the tool's baseline example, where required ot security controls sits at 120 controls and the headline result is 450 %, this scenario comes in 167% below the baseline at -300 %.
  • Use it after a controls assessment to size remediation scope, or quarterly to trend coverage against your security baseline. A result at this level usually justifies acting on the stressed input before touching anything else, because every other figure in the table is downstream of it.

Results at a glance

  • Security control gap rate: -300 % (headline result)
  • Absolute margin: -24 value
  • Available amount: 60 value
  • Required amount: 84 value

Run it with your numbers

  • To rerun this with your own numbers, open the live Security Control Gap calculator, set required ot security controls to your actual value, and adjust the remaining inputs to match your operation.

Last reviewed 2026-05-12.