IEC 62443 in the plant, not in a binder
Zones and conduits derived from the communication that actually runs. With a target security level per zone and an order of work that fits maintenance windows.
A zone concept is a statement about the plant
A zone model can be drawn at a desk, but it only holds once it matches the connections that are actually open. The test of it is a single question: which paths run today between the office network and the control level, and are they all in the concept.
The standard is awkwardly concrete on this point. A zone model to 62443-3-2 is a statement about the architecture: which parts of the plant share a security level, where the boundary runs, and what may cross it. That cannot be written without knowing the plant.
So we start with the communication that really runs, and not with the network plan that ought to hold.
Zones and transitions as they really run
Between office IT and the control level, many plants have a connection that grew there: a remote maintenance path nobody switched off, a historian with two network cards, an access granted to an integrator three years ago. On paper, level 3.5 is a line; in the plant it is a list of exceptions.
We record the actual communication, passively and during operation, and set it against the intended state. Out of that comes the zone and conduit model to 62443-3-2, with a target security level per zone and a list of the transitions that actually exist.
What regularly stands out is not the missing firewall but the path that goes around it.
Which part of 62443 applies to whom
The series is extensive, but for an operator three parts decide it. The rest addresses manufacturers and integrators.
62443-2-1: the programme
What the operator has to build organisationally. Responsibilities, change and patch procedures, dealing with suppliers. The part that most resembles an ISMS and overlaps with NIS2.
62443-3-2: the zones
Risk analysis and the division of the plant into zones and conduits, each with a target security level. This is the part that means architecture and not only documentation.
62443-3-3: the requirements
What a system has to be capable of in order to reach a security level. This is where it shows whether a controller from 2009 can carry the target at all, or whether the compensation has to lie in the zone around it.
From the survey to the zone model
Four steps, with no intervention in the process.
Passive capture
Capture at the handover points, evaluation of the protocols that actually run: IEC 60870-5-104, IEC 61850 with MMS and GOOSE, Modbus, DNP3, OPC UA. No active scan in the production network.
Plant and communication picture
Which devices speak to which, in which direction, how often. Only from that does it become visible which boundaries already exist and which are merely asserted.
Zones and conduits
Division by protection requirement and function, a target security level per zone, and for every transition the question of what it has to carry and what it permits today.
Measures in order
Separated into immediate, next maintenance window, and capital planning. A plant cannot be rebuilt in a quarter, but it can be made safer in a sensible order.
From plants, not from reading standards
Our zone models come out of the same work as our penetration tests and our OT monitoring: substations, control rooms, power plant environments and interlocking landscapes. What we find there in the way of transitions flows back into the question of which zone boundary holds in practice.
Our own research comes on top. Our lab holds real controllers, and in the demonstrators YekTrain, YekCar and YekCity we try attacks and detection on rigs that cost nobody their operation.
Common questions about OT compliance
Products and processes get certified, not the plant as a whole. For operators the usual route is an evidenced programme to 62443-2-1 and a reasoned zone model to 3-2. We prepare both, but we do not audit what we have advised on.
NIS2 says you have to manage risks; 62443 says what that looks like in an automation environment. For operators of critical infrastructure, 62443 is the most workable way to evidence the state of the art.
No. The survey runs passively over mirror ports and captures. Active tests we do only on spare or lab rigs, or in agreed windows with abort criteria fixed beforehand.
That is the normal case and no reason to stop. If a device cannot carry a security level itself, the zone has to carry it. That is exactly what the model is for: it allows old technology to keep running and still lets you explain why that is defensible.
Certifications and memberships.
Talk to us.
A first conversation usually takes 30 minutes. We look at where you stand and tell you frankly whether we are the right partner.