Skip to main content

Risk Management of Cyber-Physical Systems

Risk Management of Cyber-Physical Systems

Key information

Next application deadline: TBC
Next course starts: TBC
Format: Fully online, asynchronous and synchronous
Course duration: 12 weeks
Language: English
EQF Level: 7
Delivered by: POLIMI, CEFRIEL
Awarding Institution: German University of Digital Science

Certification: 5 ECTS (~125 hours of study workload, including course activities and self-directed learning)
Fees: €350

Microcredential Information

The module emphasizes the integration of legal frameworks, best practices, and case studies to develop resilient, safe, and secure cyber-physical systems, especially in critical infrastructure. Participants will learn to perform continuous risk assessments, manage organizational and human factors, and implement strategies for business continuity and interdependent system resilience.

The Risk Management of Cyber-Physical Systems module aims to equip students with the skills to analyse, assess, and manage risks associated with socio-cyber-physical systems. It provides a comprehensive understanding of complexities and practices in technology risk governance (in the different stages of the system life cycle), and in operational resilience, through practical applications of industry-recognized methods, tools and processes. Students will analyse case studies and engage with a serious game to gain practical insights into the interplay between cybersecurity and business continuity. The module includes three core instructors and features guest lectures from industry professionals, offering valuable practitioner perspectives.

Key Details

Time commitment

  • (Estimated) Total workload: 125
  • Contact hours: 50
  • Private study, including examination preparation, specified in hours: 75

Assessment

  • A group written assignment: prepare either an essay on the state of art review of a relevant topic/challenge in the industrial cybersecurity risk management domain, or a Technology Risk Assessment report on an advanced digital technology. (40%)
  • Final proctored written test, comprising exercises and theoretical questions (60%)
Register your interest

Subjects covered

Week 1

  • Course introduction.
  • Risk management concept and process.
  • Risk-based technology selection and adoption.

Week 2

  • System safety engineering of cyber-physical systems.
  • Risk engineering methods:
  • Failure Mode Effects and Criticality Analysis (FMECA)
  • Fault Tree Analysis (FTA)
  • Event Tree Analysis (ETA)
  • Probabilistic Risk Analysis (PRA)

Week 3

  • Risk analysis of socio-technical systems:
  • Human and organisational risk factors
  • Risk management of organisational accidents
  • High Reliability Organization theory
  • Critical incident analysis

Week 4

  • Cyber risk modelling:
  • Types of risks (humans, IT, OT)
  • Cyber risk models and principles
  • Cascading effects
  • Correlation among risks
  • Risks of intangible assets

Week 5

  • Challenges and advances in industrial cyber risk assessment:
  • Information security today
  • Challenges in modern security governance
  • Continuous risk assessment
  • Principles of social engineering

Week 6

  • Cyber risk maturity models and management:
  • CMMs
  • DevSecOps drill down (SCA, SBOM, best practices)
  • EU legislation framework
  • US legislation framework and comparison

Week 7

  • Case study by practitioners: Cybersecurity Threats, Strategy and Management at Intesa SanPaolo

Week 8

  • Case study by practitioners: Cyber and Physical Risk Management at SNAM spa

Week 9

  • Business Continuity Management:
  • BCM fundamentals and business cases
  • Business Impact Analysis
  • Recovery strategies
  • Collaborative BCM and supply chain resilience

Week 10

  • Business Continuity Management – Serious Game (Session 1)

Week 11

  • Business Continuity Management – Serious Game (Session 2)

Week 12

    • Cybersecurity for Critical Infrastructure:
    • Importance of CIP-R
    • Critical infrastructure resilience
    • Interdependencies and cascading events
    • Modelling and analysis of interdependent systems
  • Cyber threats to CI
  • Best practices and frameworks for CIP-R
Register your interest

Learning objectives

After successful completion of this course, students will be able to:

  • Identify and categorise technology risks of operating and digital technologies
  • Describe and prioritise risk and resilience features of socio-cyber-physical systems exposed to a variety of threats
  • Distinguish and compare approaches to and methods for technology risk governance at different system life cycle stages (from deign, to project management, to operations)
  • Select and apply the most appropriate risk assessment approach and methods given the features of the socio-cyber-physical system under analysis
  • Examine and evaluate the suitability of an organisation’s technology risk governance model
  • Prepare a strategic report on technology risk assessment
  • Describe the concepts and principles related to the Business Continuity Management (BCM), conduct Business Impact Analysis (BIA), identify and evaluate recovery strategies, develop Business Continuity Plans
Register your interest

Module leaders

Prof. Paolo Trucco

Paolo Trucco is Full Professor of Industrial Risk Management at Politecnico di Milano (Italy), Deapartment of Management, Economics and Industrial Engineering. He is Director of the Centre for Risk and Resilience Management of Complex Systems and Scientific Director of the Observatory on Space Economy.

His research and professional activities range from Supply Chain Risk Management and Resilience, Capital Project Risks in the context of Climate Change and Energy Transition, to Resilience Engineering of interdependent Critical Infrastructure Systems.

He is advisor of DG Home Affairs (EC) on Critical Infrastructure and Key Resource Supply Chain Resilience, and advisor of the Lombardy Region Government for the Critical Infrastructure Resilience Programme.

He is member of ANRA and FERMA (Federation of European Risk Management Associations) and ESRA (the European Safety and Reliability Association).

He is author of more than 290 scientific publications, and frequently hosted as commentator on TV and newspapers on industrial strategy and management topics.

Register your interest

Making Europe cyber-aware

Our digital world is under constant attack. Master the advanced skills to defend critical data and infrastructure. Become a sought-after expert in one of today’s most vital and in-demand career fields.

Download prospectus

FAQs

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

newsletterStay ahead in cybersecurity

Subscribe to our newsletter for exclusive insights and breakthroughs from Digital4Security directly to your inbox

Applications open
Hybrid Master's
Application deadline:
Friday, 11th September 2026, 22:00 CET
Course starts:
Monday, 28th September 2026
Course duration:
2 years | Hybrid (online + in-person intensives)
Course delivery:
Hybrid program
Certification:
ARACIS (Romania)-accredited masters's degree (120 ECTS)
Language:
English
Apply now
Applications closed
Microcredentials
Application deadline:
Friday, 25th September, 12:00 CEST
Course starts:
From October 2026 (application opens Monday, 27th July)
Course duration:
6-12 weeks depending on chosen course
Course delivery:
Online
Certification:
Official recognition of your completed learning outcomes and awarded ECTS
Language:
English
Register your Interest
Apply now Toggle