Ensuring cybersecurity in an industrial environment (OT—Operational Technology) requires a completely different approach than traditional enterprise IT. The priority in industry is not only data confidentiality, but above all operational continuity, system availability, and the safety of health, lives, and the environment.
The international ISA/IEC 62443 series of standards provides a globally recognized framework for the cybersecurity of Industrial Automation and Control Systems (IACS). It defines comprehensive requirements for the secure design, implementation, and operation of industrial systems. It covers the entire supply chain and allocates responsibilities among asset owners, system integrators, and product suppliers, thereby minimizing risks and building the cybersecurity resilience of industrial infrastructure.
NIS 2 Directive (Network and Information Security)
The EU NIS 2 Directive introduces strict cybersecurity requirements for a wide range of manufacturing, industrial, and energy organizations. Entities falling under its scope must secure both their IT and OT environments. Adopting the IEC 62443 standard series is an optimal and recognized framework to fulfill NIS 2 requirements regarding organizational and technical security measures in industrial control systems and ensure full regulatory compliance.
Cyber Resilience Act (CRA)
With respect to component integration and product development, the Cyber Resilience Act (CRA) is equally crucial for vendors and integrators. The IEC 62443 standard series (specifically parts 4-1 and 4-2) provides the methodical foundation to implement Security-by-Design principles from the development phase of industrial (IoT/IIoT) devices through to their secure deployment.
Key Benefits of IACS Security (IEC 62443) for Your Organization
- Ensuring production and operational continuity while minimizing downtime caused by cyber incidents.
- Protecting health, safety, and the environment (HSE) against physical impacts of cyber threats.
- Regulatory and contractual compliance with NIS 2 requirements and supply chain obligations.
- Clear allocation of roles and responsibilities across the supply chain (Asset Owner – System Integrator – Product Supplier).
- Effective network segmentation and establishing a secure environment for IT/OT convergence.
- Reduction of business risks through a standardized approach to risk assessment in industrial environments.
Scope of Our Professional Services
1 | Current State OT Security Analysis & Planning
- Asset inventory and identification of critical systems within the IACS environment • Gap analysis against IEC 62443 requirements and relevant cybersecurity regulations • Development of a strategic roadmap and project timeline for enhancing IACS cybersecurity
2 | Initial Risk Assessment & Segmentation
- Execution of high-level risk assessments • Design of logical and physical network segmentation (Zones & Conduits concept) • Definition of Target Security Levels (SL-T) for individual zones
3 | Detailed Risk Assessment & Security Countermeasures Design
- Execution of detailed risk assessments for selected Systems Under Control (SUC) • Selection of appropriate technical and organizational countermeasures (Foundational Requirements) to achieve SL-T • Establishment of a Cyber Security Management System (CSMS)
4 | Policy Documentation, Procedures & Implementation Support
Design and documentation of OT-specific policies (e.g., OT vulnerability management, patch management, secure remote access) • Creation of cybersecurity guidelines for suppliers and integrators • Methodological support during the implementation of technical security controls in the IACS environment
5 | Awareness & Training for Industrial Environments
Development of security awareness programs tailored to OT/IACS risks • Specialized technical training for operators, engineers, and plant management • Scenario-based drills and practical exercises for OT security incident response
6 | IACS Security Audits & Supply Chain Audits
Evaluation of the Achieved Security Level (SL-A) in live operations • Execution of internal audits per IEC 62443 requirements (e.g., CSMS audit per IEC 62443-2-1) • Audits and verification of key suppliers and integrators across the IACS supply chain
Advanced GRC applications
The difficulty of executing ISMS processes increases with the size of the organisation and the maturity of the ISMS and security controls. For complex organisations with complex management systems, we recommend using advanced modular tools.
More information can be found in the Applications section.
Quality of our services
During the provision of consulting services, the standards of quality of consultancy services based on ISO 20700, information security based on ISO/IEC 27001 and project management based on ISO 21502 are applied.
Competences of our consultants:
- Certified IEC 62443 Lead Implementer *
- Certified ISO/IEC 27001 Lead Implementer *
- Certified ISO/IEC 27005 Lead Risk Manager *
When conducting an internal audit (first-party audit) or second-party audit, the best practice of auditing management systems, as defined in ISO 19011, and other relevant standards, is applied.
Competences of our auditors:
- Certified ISO/IEC 27001 Lead Auditor *
* NOTE: ISO/IEC 17024 accredited.