Skip to main content

Damage Scenario

According to ISO/SAE 21434, a damage scenario describes the adverse consequences that occur when a security property of an asset is violated — for example the manipulation of the braking function after the integrity of an ECU’s software has been compromised. Damage scenarios answer the question “what would be bad?” and thus form one half of the risk assessment; the other half is provided by the feasibility of the associated attacks.

Rating via Four Impact Categories

Each damage scenario is rated in four categories: safety (harm to persons), financial (financial damage), operational (impairment of vehicle functions) and privacy (violation of privacy), S/F/O/P for short. For each category, the standard provides a four-step scale from negligible to severe. This rating yields the impact level of the scenario. The rating is done from the perspective of the affected road users; the safety category builds the bridge to the severity rating of the HARA from ISO 26262.

The Role in the TARA

In the Threat Analysis and Risk Assessment (TARA), damage scenarios are attached to the assets of the item: an asset is worth protecting precisely when the violation of one of its security properties — confidentiality, integrity or availability — leads to a relevant damage. Threat scenarios then describe how this violation can come about. The risk level of a risk results from the combination of impact level and attack feasibility level via the risk matrix. Finally, cybersecurity goals address the damage scenarios whose risk is to be reduced.

Damage Scenarios in Practice

The same damage scenarios appear in many places in real analyses: a scenario such as “vehicle can be immobilised remotely” is reached by several threat scenarios via different attack paths. If its rating changes, all dependent risk decisions must be updated. For consistent, audit-ready analyses according to ISO/SAE 21434, it therefore pays off to maintain damage scenarios as independent, reusable elements instead of one line of text per spreadsheet row — our article on the TARA provides an introduction.

Related terms

Frequently asked questions

How is a damage scenario rated?
In four impact categories: safety (harm to persons), financial (financial damage), operational (impairment of vehicle functions) and privacy (violation of privacy), S/F/O/P for short. Each category is rated on a four-step scale from negligible to severe; this yields the impact level of the scenario.
What is the difference between a damage scenario and a threat scenario?
The damage scenario describes the consequence: what happens at vehicle or stakeholder level when a security property is violated. The threat scenario describes the way there: which compromise of which asset leads to this consequence. One damage scenario can be reached by several threat scenarios.
From whose perspective is the damage rated?
From the perspective of the affected road users, i.e. drivers, passengers and other traffic participants — not primarily from the manufacturer’s perspective. The safety category deliberately builds the bridge to the severity rating of the HARA from ISO 26262.
Reviewed by Jens Bühl, Product Owner on August 21, 2026