Real attacks cross systems. A phishing event compromises an office identity, that identity opens a remote-access path, and the remote path reaches operational control. A single bowtie can become unreadable if it tries to contain the entire chain.
Chained bowties keep each supporting asset understandable while connecting the scenarios that propagate between them.
Consequence becomes threat
A chain link says that a consequence in one bowtie acts as a threat event in another.
For example:
Office identity compromised
→ unauthorized remote access
→ operational workstation compromised
→ manipulated control commands
Each bowtie retains its own top event, barriers, consequences and owner. The chain records the dependency between them.
Propagating frequency
When numerical propagation is enabled, the downstream threat frequency comes from the mitigated frequency of the upstream consequence. The manually entered downstream estimate remains available but does not drive the path while the chain is active.
This creates a powerful what-if view. Improve phishing-resistant authentication in the upstream bowtie and the calculated exposure of downstream operational bowties can fall as well.
Propagation should remain inspectable. Reviewers need to see:
- which upstream path supplies the frequency;
- whether the link is numerical or navigational only;
- which assessment version produced the input; and
- whether the scopes and time bases are compatible.
Why cycles are blocked
A numerical cycle would make frequency feed itself: bowtie A influences B, B influences C, and C influences A. The simple path model cannot resolve that loop without a different analytical technique.
Cyberkit therefore marks or blocks cyclic propagation. A relationship can remain as a link only for navigation while its frequency is estimated separately.
This is not merely a software restriction. The warning shows that the causal model needs clarification or a more advanced method.
The portfolio view
The portfolio represents each top event as a node and each chain as a connection. It supports questions that an individual diagram cannot answer:
- Which supporting assets create downstream exposure?
- Where does one barrier protect several business outcomes?
- Which architecture assets still lack assessment?
- Which high-risk paths share the same weak measure?
- Where would one improvement reduce risk across several bowties?
Unassessed architecture assets can appear as ghost or dashed nodes. They are not zero-risk assets; they are visible gaps in assessment coverage.
Avoid building a decorative map
Only create a chain when the downstream causal relationship is meaningful. Similar timing, shared business ownership or visual proximity are not enough.
For each link, be able to state:
If this upstream consequence occurs, it changes the frequency or context of this downstream threat because…
If the explanation is weak, use a portfolio grouping or reference instead of numerical propagation.
Improvement at portfolio scale
Shared measures and chained paths make prioritization more realistic. A maturity improvement in a widely reused access-control capability may reduce several upstream and downstream scenarios. The roadmap can compare that portfolio effect with a local barrier addition.
The result is not a prediction of an attacker’s exact route. It is a transparent model of dependencies that helps owners see where local control decisions create wider resilience.
Go to the source
Sources and further reading
Apply the method
Want to discuss this in your own risk model?
Keep the details high-level. We can start with scope, terminology and evaluation approach.