“…Formal methods have been used in order to develop systems from parts of Amazon Web Services (Newcombe et al, 2015) to assurance of the software powering safety-critical aspects of a line of the Paris Metro system (Behm et al, 1999). We pay particular attention to a development of the B-method, known as Event-B (Abrial, 2010), which has been leveraged for both security analysis (Gawanmeh et al, 2012) as well as safety analysis (Rezazadeh et al, 2007) and has therefore proven itself useful in both domains. Furthermore, Event-B has been paired with an STPA methodology in the past which has demonstrated synergies between STPA's constraint-based approach and Event-B's modelling techniques (Colley and Butler, 2013).…”