Key information
Next application deadline: TBC
Next course starts: TBC
Format: Fully online, asynchronous and synchronous
Course duration: 12 weeks
Language: English
EQF Level: 7
Delivered by: POLIMI, CEFRIEL
Awarding Institution: German University of Digital Science
Certification: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
Fees: €350
Microcredential Information
The module emphasizes the integration of legal frameworks, best practices, and case studies to develop resilient, safe, and secure cyber-physical systems, especially in critical infrastructure. Participants will learn to perform continuous risk assessments, manage organizational and human factors, and implement strategies for business continuity and interdependent system resilience.
The Risk Management of Cyber-Physical Systems module aims to equip students with the skills to analyse, assess, and manage risks associated with socio-cyber-physical systems. It provides a comprehensive understanding of complexities and practices in technology risk governance (in the different stages of the system life cycle), and in operational resilience, through practical applications of industry-recognized methods, tools and processes. Students will analyse case studies and engage with a serious game to gain practical insights into the interplay between cybersecurity and business continuity. The module includes three core instructors and features guest lectures from industry professionals, offering valuable practitioner perspectives.
Key Details
Time commitment
- (Estimated) Total workload: 125
- Contact hours: 50
- Private study, including examination preparation, specified in hours: 75
Assessment
- A group written assignment: prepare either an essay on the state of art review of a relevant topic/challenge in the industrial cybersecurity risk management domain, or a Technology Risk Assessment report on an advanced digital technology. (40%)
- Final proctored written test, comprising exercises and theoretical questions (60%)
Subjects covered
Week 1
- Course introduction.
- Risk management concept and process.
- Risk-based technology selection and adoption.
Week 2
- System safety engineering of cyber-physical systems.
- Risk engineering methods:
- Failure Mode Effects and Criticality Analysis (FMECA)
- Fault Tree Analysis (FTA)
- Event Tree Analysis (ETA)
- Probabilistic Risk Analysis (PRA)
Week 3
- Risk analysis of socio-technical systems:
- Human and organisational risk factors
- Risk management of organisational accidents
- High Reliability Organization theory
- Critical incident analysis
Week 4
- Cyber risk modelling:
- Types of risks (humans, IT, OT)
- Cyber risk models and principles
- Cascading effects
- Correlation among risks
- Risks of intangible assets
Week 5
- Challenges and advances in industrial cyber risk assessment:
- Information security today
- Challenges in modern security governance
- Continuous risk assessment
- Principles of social engineering
Week 6
- Cyber risk maturity models and management:
- CMMs
- DevSecOps drill down (SCA, SBOM, best practices)
- EU legislation framework
- US legislation framework and comparison
Week 7
- Case study by practitioners: Cybersecurity Threats, Strategy and Management at Intesa SanPaolo
Week 8
- Case study by practitioners: Cyber and Physical Risk Management at SNAM spa
Week 9
- Business Continuity Management:
- BCM fundamentals and business cases
- Business Impact Analysis
- Recovery strategies
- Collaborative BCM and supply chain resilience
Week 10
- Business Continuity Management – Serious Game (Session 1)
Week 11
- Business Continuity Management – Serious Game (Session 2)
Week 12
-
- Cybersecurity for Critical Infrastructure:
- Importance of CIP-R
- Critical infrastructure resilience
- Interdependencies and cascading events
- Modelling and analysis of interdependent systems
- Cyber threats to CI
- Best practices and frameworks for CIP-R
Learning objectives
After successful completion of this course, students will be able to:
- Identify and categorise technology risks of operating and digital technologies
- Describe and prioritise risk and resilience features of socio-cyber-physical systems exposed to a variety of threats
- Distinguish and compare approaches to and methods for technology risk governance at different system life cycle stages (from deign, to project management, to operations)
- Select and apply the most appropriate risk assessment approach and methods given the features of the socio-cyber-physical system under analysis
- Examine and evaluate the suitability of an organisation’s technology risk governance model
- Prepare a strategic report on technology risk assessment
- Describe the concepts and principles related to the Business Continuity Management (BCM), conduct Business Impact Analysis (BIA), identify and evaluate recovery strategies, develop Business Continuity Plans
Module leaders
Prof. Paolo Trucco
Paolo Trucco is Full Professor of Industrial Risk Management at Politecnico di Milano (Italy), Deapartment of Management, Economics and Industrial Engineering. He is Director of the Centre for Risk and Resilience Management of Complex Systems and Scientific Director of the Observatory on Space Economy.
His research and professional activities range from Supply Chain Risk Management and Resilience, Capital Project Risks in the context of Climate Change and Energy Transition, to Resilience Engineering of interdependent Critical Infrastructure Systems.
He is advisor of DG Home Affairs (EC) on Critical Infrastructure and Key Resource Supply Chain Resilience, and advisor of the Lombardy Region Government for the Critical Infrastructure Resilience Programme.
He is member of ANRA and FERMA (Federation of European Risk Management Associations) and ESRA (the European Safety and Reliability Association).
He is author of more than 290 scientific publications, and frequently hosted as commentator on TV and newspapers on industrial strategy and management topics.
Register your interestMaking Europe cyber-aware
Our digital world is under constant attack. Master the advanced skills to defend critical data and infrastructure. Become a sought-after expert in one of today’s most vital and in-demand career fields.
Download prospectusFAQs
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.