 |
Customer Success Story Scaling rigorous STPA at least 10× with VisualPro’s integrated AITo explore the viability of STPA on the scale of a national electricity grid, CF Cyber Services needed STPA at a depth that traditional, manual analysis simply can’t reach. With VisualPro’s AI workflow, a single semi-retired expert produced 483 loss scenarios and 122 unsafe control actions, all from a simplified control model — and with no observed hallucinations.  | Chris Few Director, CF Cyber Services Ltd · Developer of ARMMACCS |
|
|
10×+ Analyst productivity increase | 483 Loss scenarios generated | 122 Unsafe control actions (UCAs) | 0 Hallucinations observed |
|
The Challenge Conventional cybersecurity frameworks weren’t rigorous enoughChris Few’s field is the cybersecurity of critical cyber-physical systems — above all, the electricity grids he knows best. In his view, conventional cybersecurity frameworks and standards are “not rigorous enough to justify the ever-increasing levels of trust being placed in them.” They fail to identify every interaction between the cyber and physical layers, and rarely analyse what happens if those interactions are manipulated. STPA (System-Theoretic Process Analysis) is an excellent framework for generating loss scenarios on exactly that basis. Chris combines it with cyber attack-path analysis in his own method, ARMMACCS, to answer a deceptively simple question: how sophisticated does a cyber-attacker need to be to cause physical impact to a cyber-physical system? There was just one problem. Producing the Unsafe Control Actions and the loss scenarios — the analytical heart of STPA — was by far the most time-consuming and difficult part of the STPA work. For a system as complex as a national power grid, doing it by hand at the required depth was barely feasible for one person. |
“Adoption of STPA has been slow partly because it is so onerous to apply. AI does much to reduce that problem.” — Chris Few, CF Cyber Services |
|
Why VisualPro Chosen after trialling every commercial optionChris approached the tooling decision the way he approaches everything else — rigorously. He identified the available STPA products from the MIT Partnership for Systems Approaches to Safety and Security (PSAS) website, then trialled all three commercial offerings side by side. VisualPro was his choice — not least because of how naturally its AI/LLM integration fit into the STPA workflow he needed. He began by building a basic control structure for a fictional electricity grid, deliberately modelled to be representative of many real national grids. |
 Going deeper: the substation HV protection systems. This control structure models the distance, line-differential, over-current and over-voltage protection relays — with the breaker-failure protection relay — acting on the high-voltage equipment. It reaches a level of detail most cybersecurity frameworks never touch, and generated many of the most interesting UCAs and loss scenarios. |
The Solution AI-assisted modelling, with the expert firmly in the loopWith the control structure in place, Chris tasked Claude — working through VisualPro’s integrated LLM workflow — with producing UCAs for a handful of selected control actions. He reviewed the output, gave feedback, and then gradually widened the scope to generate more UCAs and their associated loss scenarios. Domain depth came from a second AI working in concert: he posed a structured series of questions about substation protection mechanisms to Google Gemini, then fed those curated answers to Claude as training material. Refining that material steadily raised the quality of what Claude produced. |
On AI hallucinations: the model that learned to generalise In safety-critical work, hallucinations are a real risk — yet across the entire analysis Chris saw no apparent hallucinations. The one early issue was the opposite of invention: Claude’s first UCAs were unnecessarily specific, narrowing the range of possible loss scenarios. When Chris explained why less detail was better, the model “seemed to genuinely understand the reasoning” and folded it into new UCAs — yielding a much wider range of scenarios. |
|
The Impact At least ten-fold productivity — and a depth one person couldn’t reach aloneChris estimates the AI integration can increase the productivity of STPA analysts “at least ten-fold.” The biggest single saving is in the generation of loss scenarios — which typically outnumber the UCAs several times over, and each of which still requires individual thought. The numbers tell the story. From 5 losses and 3 hazards, the analysis expanded to 122 unsafe control actions, 483 loss scenarios, and 11 prioritised countermeasures — spanning two substations and the full operator hierarchy of a national grid. Much of that output, Chris notes, is already more detailed than he could have produced manually in a very long time. |
 The analysis at a glance. VisualPro’s dashboard tracks the full STPA artifact set — 122 UCAs, 483 loss scenarios and 11 countermeasures — alongside UCA-flag ratios, relation coverage and unlinked-item checks. |
The analysis, by the numbersOne semi-retired expert. One fictional national electricity grid. A volume and depth of analysis that redefines what a single analyst can produce. 483 Loss scenarios | 122 Unsafe control actions | 11 Prioritised countermeasures | 3→1 Tools trialled, one chosen | 0 Hallucinations observed | 10×+ Estimated productivity gain |
|
|
The Future From power grids to nuclearChris plans to publish ARMMACCS shortly and to offer his services helping organisations implement it — using VisualPro to demonstrate its value through worked examples. Next on his roadmap: applying STPA to a fictional nuclear power station, a sector in which he has no prior experience, trusting AI to surface enough credible information to support the analysis. His message to other safety and security engineers weighing AI-driven STPA is unambiguous: human expertise is still essential to provide and refine the training material — but the volume of analysis achievable from a given amount of human knowledge and effort is now vastly greater. |
“From what I can see, AI has the potential to be a game-changer — the volume of analysis that can be produced for a given amount of human knowledge and effort will be much greater.”  | Chris Few Director, CF Cyber Services Ltd |
|
|
About the customer 
Led by Chris Few, CF Cyber Services specialises in the cybersecurity of critical cyber-physical systems, with deep experience in electricity grids. Chris is the developer of ARMMACCS, a rigorous model-based method that combines STPA with cyber attack-path analysis. | Method developed by Chris |  | Connect with Chris Few on LinkedIn → |
|
About VisualPro 
VisualPro is VWAY’s model-based safety and security analysis platform with integrated AI, purpose-built for STPA. It helps engineering teams build control structures, generate and refine UCAs and loss scenarios, maintain full traceability, and manage countermeasures — turning one of the most onerous analyses in safety engineering into a fast, auditable workflow. Follow VWAY on LinkedIn → |
|
|
This success story is based on a customer interview and an STPA analysis performed on a fictional electricity grid model created for demonstration purposes. Figures reflect the customer’s own analysis and estimates. © VWAY. VisualPro is a trademark of VWAY. |
Customer Success Story
Scaling rigorous STPA at least 10× with VisualPro’s integrated AI
To explore the viability of STPA on the scale of a national electricity grid, CF Cyber Services needed STPA at a depth that traditional, manual analysis simply can’t reach. With VisualPro’s AI workflow, a single semi-retired expert produced 483 loss scenarios and 122 unsafe control actions, all from a simplified control model — and with no observed hallucinations.
The Challenge
Conventional cybersecurity frameworks weren’t rigorous enough
Chris Few’s field is the cybersecurity of critical cyber-physical systems — above all, the electricity grids he knows best. In his view, conventional cybersecurity frameworks and standards are “not rigorous enough to justify the ever-increasing levels of trust being placed in them.” They fail to identify every interaction between the cyber and physical layers, and rarely analyse what happens if those interactions are manipulated.
STPA (System-Theoretic Process Analysis) is an excellent framework for generating loss scenarios on exactly that basis. Chris combines it with cyber attack-path analysis in his own method, ARMMACCS, to answer a deceptively simple question: how sophisticated does a cyber-attacker need to be to cause physical impact to a cyber-physical system?
There was just one problem. Producing the Unsafe Control Actions and the loss scenarios — the analytical heart of STPA — was by far the most time-consuming and difficult part of the STPA work. For a system as complex as a national power grid, doing it by hand at the required depth was barely feasible for one person.
— Chris Few, CF Cyber Services
Why VisualPro
Chosen after trialling every commercial option
Chris approached the tooling decision the way he approaches everything else — rigorously. He identified the available STPA products from the MIT Partnership for Systems Approaches to Safety and Security (PSAS) website, then trialled all three commercial offerings side by side.
VisualPro was his choice — not least because of how naturally its AI/LLM integration fit into the STPA workflow he needed. He began by building a basic control structure for a fictional electricity grid, deliberately modelled to be representative of many real national grids.
Going deeper: the substation HV protection systems. This control structure models the distance, line-differential, over-current and over-voltage protection relays — with the breaker-failure protection relay — acting on the high-voltage equipment. It reaches a level of detail most cybersecurity frameworks never touch, and generated many of the most interesting UCAs and loss scenarios.
The Solution
AI-assisted modelling, with the expert firmly in the loop
With the control structure in place, Chris tasked Claude — working through VisualPro’s integrated LLM workflow — with producing UCAs for a handful of selected control actions. He reviewed the output, gave feedback, and then gradually widened the scope to generate more UCAs and their associated loss scenarios.
Domain depth came from a second AI working in concert: he posed a structured series of questions about substation protection mechanisms to Google Gemini, then fed those curated answers to Claude as training material. Refining that material steadily raised the quality of what Claude produced.
On AI hallucinations: the model that learned to generalise
In safety-critical work, hallucinations are a real risk — yet across the entire analysis Chris saw no apparent hallucinations. The one early issue was the opposite of invention: Claude’s first UCAs were unnecessarily specific, narrowing the range of possible loss scenarios. When Chris explained why less detail was better, the model “seemed to genuinely understand the reasoning” and folded it into new UCAs — yielding a much wider range of scenarios.
The Impact
At least ten-fold productivity — and a depth one person couldn’t reach alone
Chris estimates the AI integration can increase the productivity of STPA analysts “at least ten-fold.” The biggest single saving is in the generation of loss scenarios — which typically outnumber the UCAs several times over, and each of which still requires individual thought.
The numbers tell the story. From 5 losses and 3 hazards, the analysis expanded to 122 unsafe control actions, 483 loss scenarios, and 11 prioritised countermeasures — spanning two substations and the full operator hierarchy of a national grid. Much of that output, Chris notes, is already more detailed than he could have produced manually in a very long time.
The analysis at a glance. VisualPro’s dashboard tracks the full STPA artifact set — 122 UCAs, 483 loss scenarios and 11 countermeasures — alongside UCA-flag ratios, relation coverage and unlinked-item checks.
The analysis, by the numbers
One semi-retired expert. One fictional national electricity grid. A volume and depth of analysis that redefines what a single analyst can produce.
The Future
From power grids to nuclear
Chris plans to publish ARMMACCS shortly and to offer his services helping organisations implement it — using VisualPro to demonstrate its value through worked examples. Next on his roadmap: applying STPA to a fictional nuclear power station, a sector in which he has no prior experience, trusting AI to surface enough credible information to support the analysis.
His message to other safety and security engineers weighing AI-driven STPA is unambiguous: human expertise is still essential to provide and refine the training material — but the volume of analysis achievable from a given amount of human knowledge and effort is now vastly greater.
Director, CF Cyber Services Ltd
About the customer
Led by Chris Few, CF Cyber Services specialises in the cybersecurity of critical cyber-physical systems, with deep experience in electricity grids. Chris is the developer of ARMMACCS, a rigorous model-based method that combines STPA with cyber attack-path analysis.
About VisualPro
VisualPro is VWAY’s model-based safety and security analysis platform with integrated AI, purpose-built for STPA. It helps engineering teams build control structures, generate and refine UCAs and loss scenarios, maintain full traceability, and manage countermeasures — turning one of the most onerous analyses in safety engineering into a fast, auditable workflow.
Follow VWAY on LinkedIn →This success story is based on a customer interview and an STPA analysis performed on a fictional electricity grid model created for demonstration purposes. Figures reflect the customer’s own analysis and estimates. © VWAY. VisualPro is a trademark of VWAY.