OT CybersecurityBy AzertyUI Team

IEC 62443 (or ISA/IEC 62443) is the international family of standards for the cybersecurity of industrial automation and control systems. It is often cited as the recognised way to meet NIS2 expectations on the OT side. Here is what you need to find your way.
One standard, three audiences
- The site operator (asset owner): organise the security of its installations, e.g. with IEC 62443-2-1.
- The integrator: design and commission a secure system, with IEC 62443-3-2 (risk assessment) and 3-3 (system requirements).
- The component manufacturer: build secure products, with IEC 62443-4-1 (development lifecycle) and 4-2 (component requirements).
Zones
A zone groups equipment sharing the same security requirements: for instance the PLCs of a line, or a workshop’s SCADA. Everything in a zone is treated the same way.
Conduits
A conduit is a communication channel between two zones. That is where controls go: firewalls, protocol filtering, monitoring. The fewer and better defined the conduits, the more controlled the architecture.
Security levels
The standard defines security levels (SL 1 to SL 4), according to the kind of attacker a zone must resist: from unintentional error up to a well-resourced attacker. The risk assessment sets a target level per zone; the gap with the achieved level gives the roadmap.
Where to start?
No need to apply the whole standard at once. The most cost-effective approach is to map the site, define zones and conduits, then prioritise the gaps. That is exactly how our OT cybersecurity assessment runs. For a practical view, see also our 7 first actions.
Related Tags
- Analyse de risques
- Cybersécurité OT
- IEC 62443
- NIS2
- OT Cybersecurity
- Risk assessment
- Zones and conduits
- Zones et conduits


