← All guides

Architecture and scale · Guide 08

Chained bowties and the portfolio

Connect consequences to downstream threats so improvements in one system reveal their effect across the wider attack path.

Begin reading

Real attacks cross systems. A phishing event compromises an office identity, that identity opens a remote-access path, and the remote path reaches operational control. A single bowtie can become unreadable if it tries to contain the entire chain.

Chained bowties keep each supporting asset understandable while connecting the scenarios that propagate between them.

Consequence becomes threat

A chain link says that a consequence in one bowtie acts as a threat event in another.

For example:

Office identity compromised
  → unauthorized remote access
    → operational workstation compromised
      → manipulated control commands

Each bowtie retains its own top event, barriers, consequences and owner. The chain records the dependency between them.

Propagating frequency

When numerical propagation is enabled, the downstream threat frequency comes from the mitigated frequency of the upstream consequence. The manually entered downstream estimate remains available but does not drive the path while the chain is active.

This creates a powerful what-if view. Improve phishing-resistant authentication in the upstream bowtie and the calculated exposure of downstream operational bowties can fall as well.

Propagation should remain inspectable. Reviewers need to see:

  • which upstream path supplies the frequency;
  • whether the link is numerical or navigational only;
  • which assessment version produced the input; and
  • whether the scopes and time bases are compatible.

Why cycles are blocked

A numerical cycle would make frequency feed itself: bowtie A influences B, B influences C, and C influences A. The simple path model cannot resolve that loop without a different analytical technique.

Cyberkit therefore marks or blocks cyclic propagation. A relationship can remain as a link only for navigation while its frequency is estimated separately.

This is not merely a software restriction. The warning shows that the causal model needs clarification or a more advanced method.

The portfolio view

The portfolio represents each top event as a node and each chain as a connection. It supports questions that an individual diagram cannot answer:

Unassessed architecture assets can appear as ghost or dashed nodes. They are not zero-risk assets; they are visible gaps in assessment coverage.

Avoid building a decorative map

Only create a chain when the downstream causal relationship is meaningful. Similar timing, shared business ownership or visual proximity are not enough.

For each link, be able to state:

If this upstream consequence occurs, it changes the frequency or context of this downstream threat because…

If the explanation is weak, use a portfolio grouping or reference instead of numerical propagation.

Improvement at portfolio scale

Shared measures and chained paths make prioritization more realistic. A maturity improvement in a widely reused access-control capability may reduce several upstream and downstream scenarios. The roadmap can compare that portfolio effect with a local barrier addition.

The result is not a prediction of an attacker’s exact route. It is a transparent model of dependencies that helps owners see where local control decisions create wider resilience.

Go to the source

Sources and further reading

Apply the method

Want to discuss this in your own risk model?

Keep the details high-level. We can start with scope, terminology and evaluation approach.

Ask about your use case