DOI: 10.3303/CET25117093
Paper Received: 3 January 2025; Revised: 9 February 2025; Accepted: 3 May 2025
Please cite this article as: Marroni G., Guarguaglini M., Kuipers S., Dentone D., Casson Moreno V., Landucci G., 2025, A Practical Three-
dimensional Tool for Real-time Safety-security Risk Assessment of Process Facilities, Chemical Engineering Transactions, 117, 553-558
DOI:10.3303/CET25117093
CHEMICAL ENGINEERING TRANSACTIONS
VOL. 117, 2025
A publication of
The Italian Association
of Chemical Engineering
Online at www.cetjournal.it
Guest Editors: Fabrizio Bezzo, Flavio Manenti, Gabriele Pannocchia, Almerinda di Benedetto
Copyright © 2025, AIDIC Servizi S.r.l.
ISBN 979-12-81206-17-5; ISSN 2283-9216
A Practical Three-Dimensional Tool for Real-Time Safety-
Security Risk Assessment of Process Facilities
Giulia Marronia, Michela Guarguaglinia, Sanneke Kuipersb, Dino Dentonec, Valeria
Casson Morenoa, Gabriele Landuccia,*
aDepartment of Civil and Industrial Engineering – University of Pisa, Largo Lucio Lazzarino n.2, 56126 Pisa, Italy
bInstitute of Security and Global Affairs, Leiden University, Turfmarkt n.99, 2511 DP Den Haag, the Netherlands
cDataCH Technologies s.r.l., Via Leonardo da Vinci n.5, 57123 Livorno (Italy)
gabriele.landucci@unipi.it
Plants that process and store significant quantities of hazardous substances can become targets of malicious
attacks, potentially leading to major accidents, e.g., fires, explosions, and toxic dispersions, which could also
lead to domino effects toward neighbouring units. Despite the rising interest in the security of process facilities,
current tools offer at most semi-quantitative evaluations based on simplifying assumptions. Moreover, intentional
attacks escalate quickly, so they are not well represented using conventional risk tools. The aim of this work is
to show the progress in the development of a tool for Integrated Safety-Security (ISS) risk assessment and
related domino effects. The graphical interface of the tool is made by the 3D reconstruction of the plant. Real-
time data are then associated with critical assets. The tool evaluates the probabilities and 3D consequences of
accidents given real-time and/or user-input data, e.g. meteorological conditions; moreover, the performance of
safety and security barriers is included in the evaluation. The tool allows for the real-time and 3D calculation of
risk. In the present contribution, we provide an application of the tool to showcase its potentialities. We show
how tracking real-time changes in process parameters is essential to map the risk of the areas surrounding the
plant. Possible weaknesses can therefore be highlighted using this tool, which could guide technical response
measures and investments to reduce the vulnerability of industrial installations.
1. Introduction
As technological systems grow more complex and interconnected, more advanced tools for risk estimation,
communication, and management are required (Jones, 2019). Namely, real-time data acquisition and simulation
align with the current European digitalization trend of automation in the framework of Industry 4.0 (Wahlster,
2012). In this context, process plants storing hazardous materials face unique challenges. Beyond internal
process upsets, these facilities are increasingly exposed to external events, such as intentional attacks, which
introduce complex dynamics that conventional risk analysis tools often fall short in capturing. Additionally, these
events could escalate and propagate among neighbouring units, generating the so-called domino effects.
Consequently, understanding the real-time dynamic evolution of external attacks is essential to protect people,
assets, and the environment.
Several works have dealt with dynamic and real-time analyses of conventional process safety. Among those,
Vairo et al. (2022) developed a predictive decision-making tool based on Deep Neural Networks and
Hierarchical Bayesian Networks to assess indicators of the overall safety level for process plants. Lee et al.
(2019) developed a dynamic risk approach by combining the concepts of Systems Engineering and Digital
Twins. However, there are no works focusing on developing a tool to comprehensively evaluate safety and
security risks. Thus, the LIFE20 ENV/IT/000436 LIFE SECURDOMINO project aims at addressing the
challenges that come with the Integration of Safety and Security (ISS) through the development of a tool for
Three-Dimensional (3D), Real-Time (RT) risk assessment.
This work deals with the developed methodology to design and operate the tool, which is presented in Section
2. The 3D reconstruction of the plant serves as the graphical interface of the tool, which has different features.
553
Firstly, the tool quantitatively evaluates 3D-RT-ISS scenarios and associated risks. Additionally, the tool is
designed to efficiently store process documentation, administration, and logistics in order to ensure a
comprehensive management of an industrial facility. An application of the tool to a case study is presented in
Sections 3 and 4, while Section 5 discusses the results and future perspectives.
2. Methodology
The methodology for real-time 3D mapping is the result of an interdisciplinary effort bridging expertise in
chemical engineering, computer science, visual design, and the humanities. Originally developed in a previous
work (Marroni et al., 2023), it consists of five steps, which are hereby recalled:
1. Preparatory phase: plant documentation is gathered and analysed to determine critical assets to map in
the tool;
2. Plant inspection: drone photogrammetry is used to survey the plant;
3. Development of the graphical interface of the tool: three-dimensional reconstruction of the plant and
coupling critical assets with information and real-time data;
4. Implementation of real-time evaluation of consequences and risks of an accidental or intentional release.
Each step is discussed in the following sub-sections.
2.1 Preparatory phase (Step 1)
The preparatory phase aims to understand how the facility under analysis works. Hence, data on the facility
should be collected; the collaboration of the tool-development team with the staff of the plant, e.g., process
engineers and plant managers, is essential for optimal execution of this phase. For the sake of clarity, the
documentation to be retrieved has been grouped into three categories: plant technical documentation, plant
security documents, and context analysis. Plant technical documentation includes but is not limited to: Piping
and Instrumentation Diagrams, Process Flow Diagrams, heat and material balance, plant layout, control
systems logic, safety barriers, emergency plans, manning levels, hazardous substances inventory, and safety
datasheets. Then, plant security documents should be available. They include a list of all security measures, a
map of their placement, and information on the response times and location of the emergency team. Additionally,
reports on compliance with security legislation should be supplied if they exist. Lastly, the socio-economic and
political analysis of the context where the plant operates should be conducted. The documentation retrieved
supports the screening of the critical assets to be analysed. In this work, a chart-based screening methodology
is used. More specifically, five levels of criticality, ranging from 0 (lowest) to 5 (highest), can be assigned by
intersecting on a reference chart the type of equipment with the physical state of its inventory. This score
considers both the inherent hazard posed by the asset and its visibility, which reflects how attractive the asset
might be to potential attackers. Full details on the chart are available in (Marroni et al., 2023).
2.2 Plant inspection (Step 2)
After the completion of the preparatory phase, the team inspects the plant by flying a drone. The pilot must
obtain all required permits and licenses, as drone flight is subject to restrictions according to the flight zone. The
tool-development team is then admitted to plant grounds, escorted by plant staff. The drone is flown above the
plant, capturing photos and videos. The images contain information on the latitude, longitude, elevation, and
inclinations, which are used in Step 3 to create the graphical interface of the tool (see Section 2.3). Extra
attention is dedicated to capturing all relevant details on the critical assets identified in the preparatory phase of
the methodology. For indoor areas, such as warehouses, a camera is used instead of the drone. The camera is
also used to shoot in the outdoors to capture distinctive graphical elements, such as patterns and textures.
2.3 Development of the graphical interface of the tool (Step 3)
The graphical interface of the tool is constituted by the 3D reconstruction of the analysed plant. It is obtained by
processing the information from the images obtained in Step 2 of the methodology using Agisoft Metashape.
This tool, developed by Agisoft LLC, uses aerial photogrammetry to create 3D models (Agisoft, 2024). This
technique exploits photographs taken from different angles to extrapolate data and recreate 3D models of
environments; this technique is adopted in many fields by different actors, like tech giant Google (Google, 2019).
Once the reconstruction is complete, post-processing techniques are applied to improve the visual aspects of
the tool’s interface; specific sub-models for equipment are created by the computer science and visual design
experts of the team. An example of the graphical enhancement is shown in Figure 1a: the right side of the picture
shows the photogrammetry model, while the left side shows the manually enhanced model. Once the interface
is complete, data are associated with critical assets and barriers, which are clickable and interactive. Technical
details, sketches, and documentation for assets are stored in dedicated tabs for easy retrieval during third-party
inspections.
554
Figure 1: a) Comparison between the photogrammetry model (right) and manually enhanced model (left); b)
graphical representation of real-time data (filling level) of an atmospheric floating roof tank in 3D interface.
The tool is also equipped to store and process RT data. RT data include meteorological data, which can be
obtained through a weather station; of particular interest for 3D-RT ISS risk assessment are wind speed, wind
direction, relative humidity, and ambient temperature. Moreover, process parameters can also be stored, such
as storage temperature, pressure, and level. The graphical models in the interface of the tool dynamically
represent the variations of these parameters. For instance, as the liquid level changes, the height of the floating
roof inside the tank adjusts accordingly, as illustrated in Figure 2b.
2.4 Implementation of three-dimensional real-time consequences and risks (Step 4)
The final step of the methodology is the development of ISS algorithms. The tool operates in two different modes,
a ‘default’ and a ‘custom’ mode. The default mode does not allow the change of significant ISS parameters and
is hence intended for less experienced users. For example, release diameters from American Petroleum
Institute (2008) have been adopted for safety releases and adapted to intentional releases. Conversely, more
experienced users can use the custom mode to change the parameters. If available, the tool processes real-
time weather data; if no RT data are available, then default 2F and 5D conditions are used, in accordance with
conventional safety analyses. The frequency fFO of final outcomes is evaluated using the Event Tree Analysis
(ETA). Namely, the methodology developed by Landucci et al. (2017) was used to integrate the performance of
security barriers with the ETA conventionally used in safety analyses as also exemplified by Casson Moreno et
al. (2022). More specifically, the synergistic performance of safety and security barriers is obtained using specific
decisional gates, tailored to different functions and working principles. More details can be found by the Reader
in previously mentioned references. The modelling of physical effects follows a practicality principle. Namely,
this tool should be able to support emergency operations after a major accident. For this reason, it was
necessary to find an optimal compromise between accuracy and computational time. For example, point and
multi-point sources were used for flame modelling.
Table 1: Compatibility matrix used for risk assessment, adapted from Laurent et al. (2021); LFL = Lower
Flammability Limits, LC50 = Lethal Concentration for 50% of exposed population (30 minutes), IDLH =
Immediately Dangerous to Life or Health
Impact zones →
Pool/jet fire [kW/m2] →
Fireball [kJ/m2] →
Flash-fire →
Overpressure [mbar] →
Toxic dispersion →
Frequency fFO ↓
High lethality
12.5
Fireball radius
LFL
200
LC50
Starting lethality
7
350
½ LFL
140
-
Irreversible injuries
5
200
-
70
IDLH
Reversible injuries
3
125
-
30
-
fFO < 10-6 DEF CDEF BCDEF ABCDEF
10-6 < fFO ≤ 10-4 EF DEF CDEF BCDEF
10-4 < fFO ≤ 10-3 F EF DEF CDEF
fFO > 10-3 F F EF DEF
The tool displays the final results as risk and vulnerability contours, depending on the users’ choice. The Italian
compatibility matrix for land-use planning is used in this work for risk assessment, and it is shown in Table 1. A
territorial category (ranging from A, densely populated to F, industrial grounds) is assigned to each combination
of frequency and impact zone; the Reader is referred to (Laurent et al., 2021) for more details. As this risk
representation is scenario-based, tool users can browse through different scenarios coming from the ETA
a) b)
555
analysis. On the other hand, the overall vulnerability is obtained through the cumulation of all probabilities of
attack success in the ETA, thus allowing users to visualize which areas of the plant are less protected from an
intentional attack. More details on barriers, physical models for consequences, risk, and vulnerability contours
are available in the open repository of the project (Securdomino, 2024).
3. Case study
To demonstrate the tool's functionality, the methodology was applied to a petroleum depot, shown in Figure 2.
The depot has been active for 70 years and is located in a mild socio-economic and political context. The plant
stores petroleum products (gasoline, diesel fuel, jet fuel) in floating and fixed-roof tanks.
Figure 2: Layout of the analysed facility, and intrusion path (dotted line)
Figure 2 also shows an example of an attack path: an attacker passes the entry control gate during the day,
runs to the gasoline tank (capacity: 8000 m³), which is 50% filled, and detonates 10 kg of TATP (Triacetone
triperoxide, an improvised explosive device) inside the catch basin. The gasoline tank is protected by a sprinkler
system. If the attack is successful, a simplified case of a catastrophic release with immediate ignition is
considered, leading to a pool fire.
4. Results
The results of the ETA analysis are shown in Figure 3. The frequency of the attack scenario was assumed to
be once in the lifetime of the facility, i.e., 1.43E-02 1/y.
Figure 3: Results of the ETA analysis implemented in the tool.
PERIMETER
Entry gate
Gasoline tank
Catch basin
and stairs
Intrusion
path
N 30m
3.71E-04 Escalation
FAIL
3.80E-03
FAIL 3.42E-03 Mitigated escalation
5.95E-03
2.16E-03 2.16E-03 No escalation
WORK
6.91E-05 Escalation
FAIL
7.06E-04
6.37E-04 Mitigated escalation
FAIL
1.11E-03 4.02E-04 4.02E-04 No escalation
WORK
1.94E-05 Escalation
FAIL
1.98E-04
FAIL 1.79E-04 Mitigated escalation
7.43E-03
1.47E-03 FAIL
WORK 3.11E-04 1.13E-04 1.13E-04 No escalation
WORK
3.42E-06 Escalation
FAIL
3.49E-05
3.15E-05 Mitigated escalation
attack scenario
1.43E-02 5.48E-05
FAIL 1.99E-05 1.99E-05 No escalation
WORK
WORK
6.86E-03 6.86E-03 No escalation
Entry gate
Employees
Emergency
intervention
Fragility
Sprinkler
System
Sprinkler
System
Sprinkler
System
Sprinkler
System
Fragility
Fragility
Fragility
556
The attacker could be either detected at the entry gate or by employees (dark blue gates in Figure 3). The
fragility of the equipment, i.e., its physical resistance to the attack mode, is represented by the green gate, while
the light blue gate is the sprinkler system. The emergency team is represented by the purple gate: in this case,
the attacker is quicker than the emergency response in performing the attack, hence it cannot be neutralized.
The full probabilistic model is detailed in (Casson Moreno et al., 2022), to which the Reader is referred to for
more details. The final scenarios can be divided into three types: Escalation takes place if the equipment is
damaged and safety barriers fail, represented by red branches in Figure 3; a mitigated escalation takes place if
equipment fails but the safety barriers are effective (yellow branches in Figure 3); finally, no escalation takes
place if either the attacker is detected or the equipment resists the overpressure generated by the explosive
(green branches in Figure 3).
In the following, we will focus on the escalation scenario: the cumulated frequency of the pool fire from the
escalation is fFO = 4.63E-04 1/y, which is obtained by summing all the red branches in Figure 3. The pool fire
model detailed in (Securdomino, 2024) is then used to assess the physical effects. Gasoline has been simulated
as n-hexane, and the presence of the catch basin was considered by modelling a confined pool in case the
liquid reaches the catch basin walls. Two different meteorological conditions in the time-span January-
November 2024 are investigated: i) case A using the average wind speed and most frequent (0.72 m/s @ 10 m
coming from east), and ii) case B with the maximum wind speed and its associated direction (2.90 m/s @ 10 m
coming from west). Figure 4 shows the obtained risk contours.
Figure 4: Risk contours in different meteorological conditions in: a) average and b) maximum wind conditions;
for territorial categories, see (Laurent et al., 2021)
For both cases, the territorial compatibility is respected. Namely, the plant is located in an industrial landscape
and risk contours slightly impact the road only in case of higher wind speed (Figure 4b). This is also due to the
fact that the real-time amount of substance in the tank is considered, which is lower than the full capacity (50%).
However, the potential targets impinged in the pool fire change. If only the average wind speed and direction
are considered, no other tank is involved in the fire (Figure 4a); instead, the neighbouring tank is impacted in
the case of maximum wind speed and associated direction (Figure 4b).
5. Discussion and future perspectives
The results in Section 4 showed how 3D-RT data influences plant risks. Even for a simple scenario, such as a
pool fire, the risk contours change to a noticeable degree. Wind speed and direction play a critical role, as they
determine how the flame tilts and which targets are affected. For instance, targets at certain heights may either
be impinged or not, depending on the wind conditions. Additionally, wind direction dictates where the flame is
tilted, impacting the specific areas at risk. While these physical effects are well understood, conventional risk
analyses often overlook them by using only two representative wind speeds (2 m/s and 5 m/s) and assuming
equal probabilities for all wind directions. This can lead to overestimating or underestimating risks for certain
targets. Incorporating 3D-RT data provides a clearer view of risk distribution. This enhanced risk representation
has multiple practical applications. It can assist in daily plant operations by increasing staff awareness of
localized risks. It also has value for employee training, offering a straightforward tool to visualize plant
documentation and better understand ISS scenarios. Furthermore, the tool’s computational efficiency allows
first responders to quickly simulate specific scenarios in emergency situations using the “custom” mode
described in Section 2.4. Despite these advantages, some improvements are still required. Firstly, the influence
of other RT-3D parameters should be investigated, such as the equipment’s physical conditions, including level,
a) 0.72 m/s from E b) 2.90 m/s from W
N 30m N 30m
F
EF
DEF
CDEF
557
temperature, or pressure. Then, other risk metrics should be implemented. This is necessary because domino
effect chains, while already implemented in the tool, are not efficiently represented using a compatibility matrix.
On the other hand, the Local Specific Individual Risk (LSIR) would allow a combined view of all intentional and
accidental scenarios, as well as their domino effects. Finally, a comprehensive investigation of the influence of
3D-RT-ISS parameters on the LSIR should be carried out, in order to identify the parameters most influential on
the risks of the plant. This could support plant managers in better identifying technical response measures, thus
reducing the overall vulnerability of the plant.
6. Conclusions
External attacks represent a new challenge for process plants treating hazardous substances. Among those,
intentional attacks are especially critical: their dynamic nature makes the use of conventional risk tools difficult
and inaccurate. Moreover, integrating intentional attack scenarios with conventional process upset is necessary
for efficiently managing the overall safety of the plant. In this context, the LIFE20 ENV/IT/000436 LIFE
SECURDOMINO project aims at developing a tool to visualize a three-dimensional, real-time, integrated safety
and security (3D-RT-ISS) risk assessment. This work presents the methodology behind the tool, which was
developed by our interdisciplinary team. The tool was applied to a case study to show its potentialities. The
results highlight how real-time conditions of the plant allow for a more precise visualization of risk, which could
be used in different settings, from employee training to emergency response. Moreover, the possibility of storing
process documentation in the tool allows for an easier retrieval in case of third-party inspections. The tool will
be improved by including other risk indexes, such as the LSIR, which allows a complete vision of all possible
scenarios in the plant (including domino effect chains). We believe that the tool developed could help in
understanding the nature of intentional attacks and boosting a more effective and integrated management of
risks in process plants.
Acknowledgments
This study was in part developed within the project LIFE20 ENV/IT/000436 –LIFE SECURDOMINO “Seveso
sites: assessment of integrated safety-security hazards and risks and related domino effects” with the
contribution of LIFE program of the European Union.
References
Agisoft, 2024, Agisoft Metashape Professional Edition: Features,
, accessed 10.12.2024.
American Petroleum Institute (API), 2008, ANSI/API Standard 581 – Risk-Based Inspection Technology,
American Petroleum Institute, Washington D.C., U.S.
Casson Moreno V., Marroni G., Landucci G., 2022, Probabilistic assessment aimed at the evaluation of
escalating scenarios in process facilities combining safety and security barriers, Reliability Engineering and
System Safety, 228, 108762.
Google, 2019, Google Maps 101: how imagery powers our map, , accessed 11.12.2024.
Jones S., 2019, Managing Process Safety in the Age of Digital Transformation, Chemical Engineering
Transactions, 77, 619-624.
Landucci G., Bonvicini S., Cozzani V., 2017, A methodology for the analysis of domino and cascading events
in Oil & Gas facilities operating in harsh environments, Safety Science, 95, 182-197.
Laurent A., Pey A., Gurtel P., Fabiano B., 2021, A critical perspective on the implementation of the EU Council
Seveso Directive in France, Germany, Italy and Spain, Process Safety and Environmental Protection, 148,
47-74.
Lee S., Haskins C., Paltrinieri N., 2022, Digital Twin Concept for Risk Analysis of Oil Storage Tanks in
Operations: a Systems Engineering Approach, Chemical Engineering Transactions, 90, 157-162.
Marroni G., Casini L., Kuipers S., Dentone D., Mossa Verre M., Overdijk W., Casson Moreno V., Landucci G.,
2023, Real-Time Assessment of Integrated Safety-Security Scenarios Triggering Cascading Events in the
Process Industries, Chemical Engineering Transactions, 99, 349-354.
Securdomino, 2024, Open repository of models and barriers data, , accessed 15.12.2024.
Vairo T., Bragatto P., Milazzo M.F., Pettinato M., Fabiano B., 2022, DYN-RISK – Design and Development of a
Dynamic Risk Assessment Tool, Chemical Engineering Transactions, 90, 325-330.
Wahlster W., 2012, From Industry 1.0 to Industry 4.0: Towards the 4th Industrial Revolution, Forum Business
meets Research.
558
54marroni.pdf
A Practical Three-Dimensional Tool for Real-Time Safety-Security Risk Assessment of Process Facilities