VWAY

Newsroom
Company News


Products & ServicesCustomer Success Story: Scaling rigorous STPA at least 10× with VisualPro’s integrated AI

VisualPro logo

Customer Success Story

Scaling rigorous STPA at least 10× with VisualPro’s integrated AI

To explore the viability of STPA on the scale of a national electricity grid, CF Cyber Services needed STPA at a depth that traditional, manual analysis simply can’t reach. With VisualPro’s AI workflow, a single semi-retired expert produced 483 loss scenarios and 122 unsafe control actions, all from a simplified control model — and with no observed hallucinations.

Portrait of Chris Few, Director of CF Cyber Services
Chris Few
Director, CF Cyber Services Ltd · Developer of ARMMACCS
10×+
Analyst productivity increase
483
Loss scenarios generated
122
Unsafe control actions (UCAs)
0
Hallucinations observed

The Challenge

Conventional cybersecurity frameworks weren’t rigorous enough

Chris Few’s field is the cybersecurity of critical cyber-physical systems — above all, the electricity grids he knows best. In his view, conventional cybersecurity frameworks and standards are “not rigorous enough to justify the ever-increasing levels of trust being placed in them.” They fail to identify every interaction between the cyber and physical layers, and rarely analyse what happens if those interactions are manipulated.

STPA (System-Theoretic Process Analysis) is an excellent framework for generating loss scenarios on exactly that basis. Chris combines it with cyber attack-path analysis in his own method, ARMMACCS, to answer a deceptively simple question: how sophisticated does a cyber-attacker need to be to cause physical impact to a cyber-physical system?

There was just one problem. Producing the Unsafe Control Actions and the loss scenarios — the analytical heart of STPA — was by far the most time-consuming and difficult part of the STPA work. For a system as complex as a national power grid, doing it by hand at the required depth was barely feasible for one person.

“Adoption of STPA has been slow partly because it is so onerous to apply. AI does much to reduce that problem.”

— Chris Few, CF Cyber Services

Why VisualPro

Chosen after trialling every commercial option

Chris approached the tooling decision the way he approaches everything else — rigorously. He identified the available STPA products from the MIT Partnership for Systems Approaches to Safety and Security (PSAS) website, then trialled all three commercial offerings side by side.

VisualPro was his choice — not least because of how naturally its AI/LLM integration fit into the STPA workflow he needed. He began by building a basic control structure for a fictional electricity grid, deliberately modelled to be representative of many real national grids.

STPA control structure of a power-grid substation HV protection system drawn in VisualPro's modelling screen — control actions and feedback between controllers, protection relays and circuit breakers

Going deeper: the substation HV protection systems. This control structure models the distance, line-differential, over-current and over-voltage protection relays — with the breaker-failure protection relay — acting on the high-voltage equipment. It reaches a level of detail most cybersecurity frameworks never touch, and generated many of the most interesting UCAs and loss scenarios.

The Solution

AI-assisted modelling, with the expert firmly in the loop

With the control structure in place, Chris tasked Claude — working through VisualPro’s integrated LLM workflow — with producing UCAs for a handful of selected control actions. He reviewed the output, gave feedback, and then gradually widened the scope to generate more UCAs and their associated loss scenarios.

Domain depth came from a second AI working in concert: he posed a structured series of questions about substation protection mechanisms to Google Gemini, then fed those curated answers to Claude as training material. Refining that material steadily raised the quality of what Claude produced.

On AI hallucinations: the model that learned to generalise

In safety-critical work, hallucinations are a real risk — yet across the entire analysis Chris saw no apparent hallucinations. The one early issue was the opposite of invention: Claude’s first UCAs were unnecessarily specific, narrowing the range of possible loss scenarios. When Chris explained why less detail was better, the model “seemed to genuinely understand the reasoning” and folded it into new UCAs — yielding a much wider range of scenarios.

The Impact

At least ten-fold productivity — and a depth one person couldn’t reach alone

Chris estimates the AI integration can increase the productivity of STPA analysts “at least ten-fold.” The biggest single saving is in the generation of loss scenarios — which typically outnumber the UCAs several times over, and each of which still requires individual thought.

The numbers tell the story. From 5 losses and 3 hazards, the analysis expanded to 122 unsafe control actions, 483 loss scenarios, and 11 prioritised countermeasures — spanning two substations and the full operator hierarchy of a national grid. Much of that output, Chris notes, is already more detailed than he could have produced manually in a very long time.

VisualPro STPA dashboard — totals of 5 losses, 3 hazards, 3 system-level constraints, 122 UCAs, 483 loss scenarios and 11 countermeasures with donut and bar charts

The analysis at a glance. VisualPro’s dashboard tracks the full STPA artifact set — 122 UCAs, 483 loss scenarios and 11 countermeasures — alongside UCA-flag ratios, relation coverage and unlinked-item checks.

The analysis, by the numbers

One semi-retired expert. One fictional national electricity grid. A volume and depth of analysis that redefines what a single analyst can produce.

483
Loss scenarios
122
Unsafe control actions
11
Prioritised countermeasures
3→1
Tools trialled, one chosen
0
Hallucinations observed
10×+
Estimated productivity gain

The Future

From power grids to nuclear

Chris plans to publish ARMMACCS shortly and to offer his services helping organisations implement it — using VisualPro to demonstrate its value through worked examples. Next on his roadmap: applying STPA to a fictional nuclear power station, a sector in which he has no prior experience, trusting AI to surface enough credible information to support the analysis.

His message to other safety and security engineers weighing AI-driven STPA is unambiguous: human expertise is still essential to provide and refine the training material — but the volume of analysis achievable from a given amount of human knowledge and effort is now vastly greater.

“From what I can see, AI has the potential to be a game-changer — the volume of analysis that can be produced for a given amount of human knowledge and effort will be much greater.”
Portrait of Chris Few, Director of CF Cyber ServicesChris Few
Director, CF Cyber Services Ltd

About the customer

CF Cyber Services logo — a shield with circuit traces and a lightning bolt

Led by Chris Few, CF Cyber Services specialises in the cybersecurity of critical cyber-physical systems, with deep experience in electricity grids. Chris is the developer of ARMMACCS, a rigorous model-based method that combines STPA with cyber attack-path analysis.

Method developed by ChrisARMMACCS methodology logo
Connect with Chris Few on LinkedIn →

About VisualPro

VisualPro logo

VisualPro is VWAY’s model-based safety and security analysis platform with integrated AI, purpose-built for STPA. It helps engineering teams build control structures, generate and refine UCAs and loss scenarios, maintain full traceability, and manage countermeasures — turning one of the most onerous analyses in safety engineering into a fast, auditable workflow.

Follow VWAY on LinkedIn →
Read the full story →
Start a free trial

This success story is based on a customer interview and an STPA analysis performed on a fictional electricity grid model created for demonstration purposes. Figures reflect the customer’s own analysis and estimates. © VWAY. VisualPro is a trademark of VWAY.