Industrial Cybersecurity & OT Risk worked example

Vendor Remote Session Risk with vendor session impact score of 4 score: a worked example

This worked example runs the vendor remote session risk numbers for a tougher week than the baseline: vendor session impact score of 4 score instead of the typical 8 score. Rank vendor remote session risk using operational impact, session exposure, and control weakness.

The inputs for this scenario

  • Vendor session impact score: 4 score (the input this scenario stresses; the baseline uses 8)
  • Vendor session exposure score: 7 score (held at the documented default)
  • Vendor access control weakness score: 4 score (held at the documented default)

Working through the calculation

  • The calculation starts from the formula this tool documents: Vendor remote session risk score = vendor session impact score × vendor session exposure score × vendor access control weakness score.
  • Vendor remote session risk score works out to 5.05 score at these inputs, and this is the headline figure for the scenario.
  • Vendor session impact score works out to 4 score at these inputs.
  • Vendor session exposure score works out to 7 score at these inputs.
  • Vendor access control weakness score works out to 4 score at these inputs.

How this compares with the baseline

  • Against the tool's baseline example, where vendor session impact score sits at 8 score and the headline result is 6.65 score, this scenario comes in 24.06% below the baseline at 5.05 score.
  • Use it to rank standing OEM, integrator, and support connections so you harden the most dangerous sessions first. A result at this level usually justifies acting on the stressed input before touching anything else, because every other figure in the table is downstream of it.

Results at a glance

  • Vendor remote session risk score: 5.05 score (headline result)
  • Vendor session impact score: 4 score
  • Vendor session exposure score: 7 score
  • Vendor access control weakness score: 4 score

Run it with your numbers

  • To rerun this with your own numbers, open the live Vendor Remote Session Risk calculator, set vendor session impact score to your actual value, and adjust the remaining inputs to match your operation.

Last reviewed 2026-05-12.