UtilitySTAT™ – Essentials
Self-Guided with the UtilitySTAT Tool
Utility personnel complete the assessment directly within UtilitySTAT.
Measure What You Know
Traditional risk assessment methods frequently ask, “How likely is this threat to occur?”
But how accurately can anyone know that?
The Department of Homeland Security Lexicon states that determining likelihood for malevolent threats is generally not possible. There is simply not enough data in the dataset to establish probability.
Attempting to predict adversarial threat pairings is a failed method for security improvement.
Measure the probability of success of a threat against a known security architecture.

Categories are
not measurements.

Measure the probability of success of a threat against a known security architecture.
Because when it comes to categories, how much better is “High” than “Medium”? Which mitigation caused the improvement? How much resilience was gained?
Ask:
How much better is “High” than “Medium”?
Which mitigation caused the improvement?
How much resilience was actually gained?
| UtilitySTAT ASCE 78-24 |
AWWA J100-21 |
EPA VSAT |
|
|---|---|---|---|
| Adversary-Agnostic Security Assessment | Core methodology | Speculative Probabilty/Likelihood Scenarios | Speculative Threat Likelihood Categories |
| Degree of Difficulty to Compromise | Quantitatively & Qualitatively Evaluated | Not a core measurement | Not a core measurement |
| Cumulative Defensive Difficulty | Measured across layers | No equivalent metric | No equivalent metric |
| Measures Improvement as Threat Advances Toward Asset | Yes | No cumulative measurement | No cumulative measurement |
| Identifies Weak or Non-Contributing Security Layers | Directly exposed by CDS analysis | Indirect through vulnerability analysis | Indirect through vulnerability analysis |
| Requires Malevolent Threat Probability to Measure Security | Does not rely on Probability Estimations | Attempts to Measure Likelihood Without Sufficient Data | User Default/User-Adjusted Ranges |
| Countermeasure-Specific Difficulty Values | Mathematically and Objective Scored | Vulnerability based on Estimated Likelihood | Vulnerability based on Estimated Likelihood |
| Ordered Defense Layers | Core methodology | Not a core requirement | Not a core requirement |
| Physical-Security Countermeasure Design Guidance | Primary Purpose for Risk Mitigation | Only within low measurements of estimated likelihood | Only within low measurements of estimated likelihood |
| Security Architecture / Retrofit Application | Explicitly addressed | Only within low measurements of estimated likelihood | Only within low measurements of estimated likelihood |
| Physical Security Measurement Basis | Measurement of Difficulty based on Known Countermeasures | Traditional based on Threat Likelihood Estimated Values | Traditional based on Threat Likelihood Estimated Values |
The EPA states that the Safe Drinking Water Act (SDWA) §1433 identifies what the Risk & Resilience Assessment (RRA) must address but does not require a particular assessment methodology. EPA recommends a variety of methodologies including the ASCE 78-24 rooted in Cumulative Defense Strategy, to which UtilitySTAT is aligned.
UtilitySTAT™
Utility personnel complete the assessment directly within UtilitySTAT.
Your team owns the assessment with expert assistance where needed.
Qualified consultants use UtilitySTAT to conduct, document, and deliver assessments for their clients.
Your
Assessment
Should Be Too
Update the known inputs and see how the security posture changes.
Improve your security posture from an AWIA compliance product every five years into a security-management platform with real time value.