Book an Appointment

Security for OT and industrial control systems

How to systematically secure industrial control and automation systems – from IEC 62443 zones and security levels through the Purdue model to the NIS2 obligations for manufacturing.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

4security levels: SL 1 to SL 4, defined per zone on the basis of a risk assessment
20+years — control systems often remain in service that long
10top threats counted by the German BSI (version 1.5, 2022) — incl. intrusion via remote maintenance access
50employees: the threshold from which NIS2 generally applies (Annex II)

Production plants, process control technology and building automation have long been networked – and are thus exposed to the same attacks as office IT, without being able to simply adopt its protection mechanisms. Operational technology (OT) follows its own rules: availability and functional safety take precedence, systems run for decades, and even a careless network scan can bring a plant to a standstill. With the IEC 62443 series of standards, the Purdue reference model and passive discovery techniques, an established toolset exists for securing production environments in a structured way. And ever since the NIS 2 Directive began covering the manufacturing sector as well, OT security has also become a regulatory obligation.

The Essentials at a Glance

Six topic blocks — tap to expand.

IEC 62443: roles, zones, security levels

The three dimensions of the ISA/IEC 62443 series of standards — tap a tab to explore.

3 roles
  • Asset owners: IEC 62443-2-1:2024 defines the requirements for the security program — expanded in its second edition by a maturity model.
  • Service providers and integrators are addressed by IEC 62443-2-4:2023.
  • Product suppliers: parts 4-1 and 4-2 cover secure product development and component requirements.
Asset ownersService providersIntegratorsProduct suppliersIACSMaturity model

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

IEC · 2024

IEC 62443-2-1:2024 – Security for industrial automation and control systems – Part 2-1: Security program requirements for IACS asset owners

Second edition of the asset owner requirements with a new maturity model; explicitly addresses legacy systems and IACS life cycles that often exceed 20 years.

IEC · 2023

IEC 62443-2-4:2023 – Security for industrial automation and control systems – Part 2-4: Security program requirements for IACS service providers

Second edition (December 2023) with the requirements for security programs of integration and maintenance service providers.

NIST · 2023

NIST SP 800-82 Rev. 3 – Guide to Operational Technology (OT) Security

US guide to OT security (September 2023) with a scope extended beyond ICS; reference for Purdue-based segmentation and defense in depth.

BSI / Allianz für Cybersicherheit · 2022

Industrial Control System Security: Top 10 Bedrohungen und Gegenmaßnahmen 2022

BSI-CS 005 (version 1.5, May 2022); counts intrusion via remote maintenance access and internet-connected control components, among others, among the top threats.

Amtsblatt der EU / EUR-Lex · 2022

Richtlinie (EU) 2022/2555 (NIS2)

Annex II covers the manufacturing sector (including machinery, vehicles, medical devices); Art. 21 defines the risk management measures.

Ready to approach OT security in a structured way?

If you would like to assess the security posture of your production environment – for example along IEC 62443 or with a view to NIS2 – contact us for a no-obligation initial consultation.