Accountability for cyber-physical risk is not clearly defined
Cyber-physical risk poses a life safety threat. That was the impetus for the Cyber Safety Summit held on June 10th at the National Academy of Sciences in Washington, D.C. But a life-safety issue needs an accountable party, and the summit's sessions made clear that none currently exists. Panels of experts addressed the inevitable question: who is professionally and legally accountable when a connected physical system is compromised and what is the cyber safety standard of care? There is currently no recognized engineer of record for cyber-physical risk, and a growing number of engineers, insurers and policymakers are debating whether the answer is a new discipline: cyber safety engineering.
Cyber Safety Engineering Is Following An Old Pattern
As described in the summit’s strategy framework, engineering standards of care have historically been built only reactively. They have followed a consistent sequence: a hazard is identified, people are harmed, the profession organizes and a standard is codified – often after insurers, regulators and public outcry force the issue following a tragedy. In the mid-1800s, fatal boiler explosions across America occurred almost every four days until a novel insurance product linked to quality inspection was established, eventually leading to the development of the American Society of Mechanical Engineers boiler and pressure vessel code. The Great Chicago Fire killed roughly 300 people and destroyed 17,000 buildings, leading to building fire codes. The collapse of the Quebec Bridge in 1907, which killed 75 ironworkers due to a calculation error and engineering inexperience, helped establish the professional engineer as a guardian of public safety. Wyoming passed the first engineering licensure law in 1907, and other states quickly followed.











