Modern, high functionality networks support an ever-increasing range o
f sophisticated services; but this strength is also a weakness due to
the fragility of the complex distributed-processing capability. Unexpe
cted perturbations can cause widespread network outages, i.e. 'brownou
t'. The risks to network integrity are exacerbated by regulatory polic
ies that demand open network interconnection between competing network
operators and service providers; and the increasing complexity where
single experts cannot comprehend the whole problem space. This paper p
roposes a design methodology for a formal and systematic framework to
assess the risk to network integrity and hence minimise network and se
rvice failure probability.