Probability Trees

A visual diagram that lays out possible events as branches, with each outcome shown on its own limb and labeled with its likelihood. These probabilities can be combined with impacts along each path to estimate the overall effect if risks occur on the project.

Key Points

  • Shows events and their alternative outcomes as branching paths.
  • Each branch is annotated with the probability of that outcome.
  • Enables calculation of expected impact (e.g., EMV) by multiplying probabilities and impacts along paths and summing results.
  • Useful for sequential or conditional risks and for comparing alternative decisions.

Example

A project faces a supplier delay risk (30% chance) that would cost $50,000. If the delay occurs, there is a 40% chance of additional rework costing $20,000. A probability tree shows: branch 1 (no delay, 70%, $0), branch 2a (delay only, 30% x 60% = 18%, $50,000), branch 2b (delay + rework, 30% x 40% = 12%, $70,000). Expected impact = (0.18 x 50,000) + (0.12 x 70,000) = $9,000 + $8,400 = $17,400.

PMP Example Question

Which risk analysis tool maps possible outcomes as branches, assigns a probability to each branch, and allows you to compute the overall expected impact?

  1. Probability trees
  2. Risk register
  3. Monte Carlo simulation
  4. RACI matrix

Correct Answer: A — Probability trees

Explanation: Probability trees depict outcomes as branches with probabilities, enabling calculation of expected impact across paths. The risk register documents risks; Monte Carlo simulates distributions; a RACI matrix defines roles.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course