IEC 62443: OT Cybersecurity Explained for IT Teams
Table of contents
- Key takeaways
- Why IT teams should know it
- IEC 62443 structure
- Zones and conduits
- The Purdue model
- Security levels (SL)
- The seven foundational requirements
- Available certifications
- IEC 62443 vs ISO 27001
- IT/OT coordination: what IT brings
- Common IT mistakes in OT
- Relevant OT technologies
- Typical implementation phases
- Conclusion
Updated: 2026-07-07
IEC 62443 is the international cybersecurity standard for industrial control systems (ICS) and OT networks. Its four series blocks define security zones and conduits, four protection levels (SL 1-4) and seven foundational requirements. NIS2 pressure is accelerating adoption across Europe. IT teams need to master it to coordinate network segmentation, monitoring and incident response with OT environments.
IEC 62443 is the international standard for cybersecurity in industrial control systems (ICS). It is critical for plants, utilities and infrastructure, and parallels ISO 27001 for IT but adapted to OT specifics: functional safety, real-time requirements and legacy equipment. With the NIS2 push, companies with OT environments must master it. This article offers a view oriented towards IT teams working alongside OT.
Key takeaways
-
IEC 62443 segments industrial networks into zones connected by conduits with defined security controls.
-
Defines four Security Levels (SL 1-4) based on the attacker sophistication the system must resist.
-
Distinguishes three roles with distinct obligations: asset owner, system integrator, and product supplier.
-
The seven Foundational Requirements (FR) are the basis of all compliance assessments.
-
IT/OT coordination is key: IT teams contribute segmentation and monitoring, but must not apply IT practices without understanding the OT impact.
Why IT teams should know it
IT/OT convergence is blurring lines that once separated both worlds. Specific reasons an IT team needs to understand IEC 62443:
-
NIS2 requires many companies to integrate OT security into their overall cybersecurity programme.
-
Effective coordination: IT cybersecurity must align with OT controls to avoid blind spots.
-
Audit: IT teams increasingly audit OT environments under regulatory compliance requests.
-
Incidents: Colonial Pipeline, Oldsmar and others show the risk is not theoretical.
IEC 62443 structure
The standard organises into four series blocks:
-
62443-1-x: general (terminology, concepts, maturity models).
-
62443-2-x: policies and procedures (risk management, patching, third-party access).
-
62443-3-x: system requirements (architecture, risk assessment).
-
62443-4-x: component requirements (secure development lifecycle, product).
This structure allows incremental adoption: a team can start with system requirements (3-3) without waiting to master all blocks.
Zones and conduits
The central concept is segmentation into zones connected by conduits:
-
Zone: grouping of assets with similar security requirements.
-
Conduit: communication path between zones with defined security controls.
-
Trust boundaries: explicit and documented.
Similar to IT DMZ but formalised for industrial environments, where physical topology and availability requirements impose additional constraints.
The Purdue model
IEC 62443 conceptually incorporates the Purdue model as architectural reference:
-
Level 0: sensors, actuators.
-
Level 1: PLCs, RTUs.
-
Level 2: SCADA, HMI.
-
Level 3: manufacturing operations (MES).
-
Level 3.5: industrial DMZ.
-
Levels 4-5: enterprise IT.
This model guides zone segmentation: each level has distinct security requirements and communications between levels must pass through controlled conduits.
Security levels (SL)
62443 defines four target security levels:
-
SL 1: protection against casual or inadvertent access.
-
SL 2: resistance to intentional attacks with simple means.
-
SL 3: resistance to intentional attacks with sophisticated means.
-
SL 4: resistance to sophisticated attacks with extensive resources (nation-state attacker).
The practical exercise involves assessing the target SL for each zone based on incident impact and applying the controls that correspond to that level.
The seven foundational requirements
The standard articulates seven Foundational Requirements (FR) that underlie all assessments:
-
IAC: Identification and Authentication Control.
-
UC: Use Control.
-
SI: System Integrity.
-
DC: Data Confidentiality.
-
RDF: Restricted Data Flow.
-
TRE: Timely Response to Events.
-
RA: Resource Availability.
Each FR breaks down into specific requirements per security level, which allows building a prioritised implementation roadmap.
Available certifications
The certification ecosystem is more mature than it was three years ago. Available paths:
-
IEC 62443-2-4: for system integrators.
-
IEC 62443-3-3: at system level.
-
IEC 62443-4-1: secure development lifecycle for manufacturers.
-
IEC 62443-4-2: at component level.
Certification demand comes from both industrial clients and regulatory requirements in critical infrastructure sectors.
IEC 62443 vs ISO 27001
| Aspect | IEC 62443 | ISO 27001 |
|---|---|---|
| Focus | OT / industrial | IT / information security |
| Functional safety | Critical | Not primary |
| Legacy equipment | Accommodated | Less considered |
| Real-time | Considered | Not applicable |
| Certifications | Multiple routes | ISMS |
| Complementary | Yes | Yes |
The recommendation is to use both: ISO 27001 for the enterprise IT environment and 62443 for OT zones. NIS2 recognises IEC 62443 as a valid framework and its adoption makes demonstrating regulatory compliance more straightforward.
IT/OT coordination: what IT brings
IT teams have valuable capabilities for the OT environment:
-
Network segmentation via VLANs and industrial firewalls.
-
Monitoring: ingestion of OT logs into the corporate SIEM.
-
Incident response: alignment of procedures across domains.
-
Identity management: federation across domains with appropriate protocols.
-
Patch management: with a different but coordinated cadence.
What IT should not do: change OT configurations without validating the impact on functional safety and availability. Control systems are not web servers; an unexpected restart can have physical consequences.
Common IT mistakes in OT
-
Aggressive patching: OT patches require planned maintenance windows and functional safety validation.
-
Hot updates: many OT systems do not support updates without downtime.
-
Standard IT cryptography: OT may need lighter algorithms due to real-time constraints.
-
"IT best practices" without adaptation: applied without context can break real-time or availability guarantees.
Respecting OT team expertise is not optional. Knowledge of the industrial process is as critical as cybersecurity knowledge.
Relevant OT technologies
The technology stack specific to this space includes:
-
Industrial firewalls: Moxa, Hirschmann, Fortinet FortiGate Rugged.
-
Data diodes: for unidirectional communication in critical zones.
-
Industrial IDS: Claroty, Nozomi, Dragos.
-
SIEM integration with OT: Splunk and QRadar OT modules.
-
OT patch management: specialised tools such as Verve.
Typical implementation phases
The usual journey for an organisation adopting IEC 62443 follows these stages:
-
OT asset inventory: often non-existent or incomplete at the start.
-
Zone and conduit diagram: a map of the real industrial network.
-
Risk assessment: per zone and conduit, with target SL levels.
-
Gap analysis against 62443.
-
Prioritised implementation of controls by impact.
-
Continuous improvement with periodic reviews.
This is a multi-year process, not a matter of months. The critical starting point is the inventory and the diagram; without them, every other activity is blind.
Conclusion
IEC 62443 is the reference framework for industrial cybersecurity, and understanding it has become mandatory for IT teams operating in companies with OT environments. IT/OT convergence and NIS2 regulatory pressure make this integration inevitable. The path is not "adopt everything at once" but a gradual process starting with inventory, continuing with zone segmentation, and consolidating with risk-prioritised controls. Industrial infrastructure attacks are not hypothetical: they are an operational risk requiring coordinated response across both domains.