In traditional IT, the confidentiality of data comes first; in OT, the availability of the process, the integrity of the control system and the impact on functional safety dominate. Add to that fundamentally different life cycles: control systems often remain in service for more than 20 years – IEC 62443-2-1 therefore explicitly addresses the handling of legacy systems for which patches or modern protection mechanisms are not available and compensating measures must take effect. Updates can often only be installed during planned maintenance windows, and virus scanners or active scans can disrupt real-time processes. IT security concepts therefore cannot be transferred unchanged to production environments; NIST SP 800-82 Rev. 3 (2023) systematically describes the necessary adaptations.
Security for OT and industrial control systems
How to systematically secure industrial control and automation systems – from IEC 62443 zones and security levels through the Purdue model to the NIS2 obligations for manufacturing.
Production plants, process control technology and building automation have long been networked – and are thus exposed to the same attacks as office IT, without being able to simply adopt its protection mechanisms. Operational technology (OT) follows its own rules: availability and functional safety take precedence, systems run for decades, and even a careless network scan can bring a plant to a standstill. With the IEC 62443 series of standards, the Purdue reference model and passive discovery techniques, an established toolset exists for securing production environments in a structured way. And ever since the NIS 2 Directive began covering the manufacturing sector as well, OT security has also become a regulatory obligation.
The Essentials at a Glance
Six topic blocks — tap to expand.
IEC 62443: roles, zones, security levels
The three dimensions of the ISA/IEC 62443 series of standards — tap a tab to explore.
- Asset owners: IEC 62443-2-1:2024 defines the requirements for the security program — expanded in its second edition by a maturity model.
- Service providers and integrators are addressed by IEC 62443-2-4:2023.
- Product suppliers: parts 4-1 and 4-2 cover secure product development and component requirements.
- The core methodology is the decomposition of the plant into zones: groups of assets with comparable protection needs.
- Conduits connect the zones as controlled communication paths.
- For each zone, a target security level (SL-T) is defined on the basis of a risk assessment.
- The four levels SL 1 to SL 4 range from protection against casual violations to protection against attackers with extensive resources, IACS knowledge and high motivation.
- IEC 62443-3-3 provides the technical system requirements along seven foundational requirements.
- The technically achievable (SL-C) and actually achieved levels (SL-A) make the state of implementation measurable.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
IEC 62443-2-1:2024 – Security for industrial automation and control systems – Part 2-1: Security program requirements for IACS asset owners
Second edition of the asset owner requirements with a new maturity model; explicitly addresses legacy systems and IACS life cycles that often exceed 20 years.
IEC 62443-2-4:2023 – Security for industrial automation and control systems – Part 2-4: Security program requirements for IACS service providers
Second edition (December 2023) with the requirements for security programs of integration and maintenance service providers.
NIST SP 800-82 Rev. 3 – Guide to Operational Technology (OT) Security
US guide to OT security (September 2023) with a scope extended beyond ICS; reference for Purdue-based segmentation and defense in depth.
Industrial Control System Security: Top 10 Bedrohungen und Gegenmaßnahmen 2022
BSI-CS 005 (version 1.5, May 2022); counts intrusion via remote maintenance access and internet-connected control components, among others, among the top threats.
Richtlinie (EU) 2022/2555 (NIS2)
Annex II covers the manufacturing sector (including machinery, vehicles, medical devices); Art. 21 defines the risk management measures.
Ready to approach OT security in a structured way?
If you would like to assess the security posture of your production environment – for example along IEC 62443 or with a view to NIS2 – contact us for a no-obligation initial consultation.