See how cyber risk travels.Decide where to stop it.

Cyberkit Bowtie guides you through the established bowtie methodology—from understanding how threats, barriers and consequences connect to acting on the improvements that matter most. Learn through the website, then use the tooling to apply the method to your own risk stories.

The Cyberkit Bowtie application showing a connected-service model with two threats, preventive barriers, an integrity-compromised event, recovery barriers and two consequences.
Cyberkit Bowtie connects threats, barriers, a loss-of-control event and consequences in one working view.

Trace causesConnect credible threats to the event.

Test barriersShow strength, condition and evidence.

See consequencesMake operational impact concrete.

Risk analysisAssess likelihood and impact before and after action.

Compare actionsFocus effort where it changes risk.

Why bowtie helps

Cyber risk crosses technology, people and process. A bowtie gives engineers, operators, risk owners and managers one scenario to challenge together: how control can be lost, what prevents it, what limits the consequences and where an intervention changes the path.

A bowtie makes the entire risk path visible at once—and makes weak assumptions difficult to hide.

The established bowtie method

Follow risk from cause to consequence

Build one risk story in six moves—from the moment control is lost outward to threats, barriers, consequences and action. The left side asks which preventive barriers can stop that loss; the right asks which recovery barriers can keep it from becoming harm.

Walk through the six steps below to understand the methodology in practice.

  1. 01Anchor
  2. 02Expose
  3. 03Prevent
  4. 04Recover
  5. 05Assess
  6. 06Act

Which improvement should move forward?

Turn the assessment into action

Compare improvements by risk reduction and reach, then take the strongest next step. The model keeps each action connected to the path—and the assumptions—it is meant to change.

Water-treatment Cyberkit Bowtie model and assessmentA simplified application canvas models an operational-technology risk in water treatment. An unauthorized PLC change or stolen vendor credentials can lead to loss of chemical-dosing control. Preventive barriers protect the path, while recovery barriers limit unsafe water release or an extended supply interruption. A five-by-five risk matrix compares the current high risk with the expected medium risk after an independent dosing trip is added.HAZARDSafe water treatmentLOSS OF CONTROLDosing controllostTHREATUnauthorized PLC changeTHREATStolen vendor credentialsPREVENTIVE BARRIERLogic-change approvalPREVENTIVE BARRIERControlled remote accessRECOVERY BARRIERQuality alarm & responseRECOVERY BARRIERManual dosing fallbackCONSEQUENCEUnsafe water releasedCONSEQUENCEExtended supply outageRisk comparison5 × 5 MATRIXLIKELIHOOD →IMPACTPROPOSED IMPROVEMENTAdd independent dosing tripCURRENT RISKHIGHEXPECTED RISKMEDIUMIMPROVE
One water-treatment risk, two views: build the path from OT threats to water consequences, then assess risk and compare a concrete improvement.

Put the method to work

The tool follows the reasoning—not the other way around.

Start with a bounded system, build only credible paths, expose the assumptions and compare improvements. The software keeps that thread connected.

  1. 01 · Scope

    Map the system

    Identify supporting assets, interfaces, zones and the assessment boundary.

  2. 02 · Model

    Build the paths

    Describe threats, top events, consequences and independent barriers.

  3. 03 · Analyze

    Test the layers

    Assess frequency, impact, inherent strength, maturity and residual risk.

  4. 04 · Improve

    Prioritize action

    Compare changes by expected risk reduction and reach, then use the evidence behind those estimates to guide attention and budget.

Have a use case you want to explore?

Ask about the method or evaluation approach. Keep operational details high-level and non-sensitive.

Discuss your use case

Choose your next step

Learn one path. Then build one.

Begin with the eight-minute guide, or use public and synthetic information to explore the live beta.