OT risk analysis following IEC/EN 62443
For plants, utilities and industrial control systems. Zybercomply follows the IEC 62443-3-2 flow from system under consideration to target security levels, with an AI assistant suggesting assets, zones, conduits, threats and ratings for you to review.
The IEC 62443 series at a glance
- IEC 62443-2-1 — security program requirements for asset owners.
- IEC 62443-3-2 — security risk assessment and system design: system under consideration, zones and conduits, initial and detailed risk assessment, target security levels.
- IEC 62443-3-3 — system security requirements and security levels across seven foundational requirements.
- IEC 62443-4-1 — secure product development lifecycle for suppliers.
- IEC 62443-4-2 — technical security requirements for components.
Zones and conduits first
Assets are grouped into zones by Purdue level. A conduit is the controlled communication path between zones — not just a cable, but the logical relationship crossing a zone boundary.
For each conduit you record source and destination zones, permitted protocols and direction, the assets using it, the trust boundary, threats, existing controls and the required security level.
Initial and detailed risk assessment
Threat scenarios come from MITRE ATT&CK for ICS, with countermeasures mapped to MITRE D3FEND. Each scenario is rated for likelihood, consequence, control effectiveness and residual risk.
Security levels SL 1–4
- SL 1 — protection against casual or coincidental violation.
- SL 2 — intentional violation using simple means, low resources, generic skills and low motivation.
- SL 3 — intentional violation using sophisticated means, moderate resources, IACS-specific skills and moderate motivation.
- SL 4 — intentional violation using sophisticated means, extended resources, IACS-specific skills and high motivation.
Target security levels
Set SL-T 1–4 per zone across the seven foundational requirements of IEC 62443-3-3 (FR 1 identification and authentication through FR 7 resource availability), each with a documented justification, followed by a sign-off log.
Frequently asked questions
- What is IEC 62443?
- IEC 62443 is an international series of standards for the cybersecurity of industrial automation and control systems (IACS), covering asset owners, system integrators and product suppliers.
- What is a conduit in IEC 62443?
- A conduit is the controlled communication path between two or more zones — the logical communication relationship crossing a zone boundary, not simply a cable — with its own protocols, controls and required security level.
- What is the difference between SL-T, SL-C and SL-A?
- SL-T is the target security level a zone or conduit should reach, SL-C is the capability level the components can deliver, and SL-A is the level actually achieved in the installed system.
- Which part of IEC 62443 covers risk assessment?
- IEC 62443-3-2 describes the security risk assessment: defining the system under consideration, partitioning it into zones and conduits, assessing initial and detailed risk and setting target security levels.
- How does IEC 62443 relate to NIS2?
- NIS2 requires essential and important entities to manage cybersecurity risk. For operators of industrial systems, an IEC 62443-3-2 risk assessment is a recognised way to document that work.