When an Australian utility, manufacturer or council sets out to secure its operational technology, the first question is usually where to start and which framework to follow. The answer, almost universally, is IEC 62443. It is the leading international standard for the cybersecurity of industrial automation and control systems, and it gives asset owners a structured, defensible way to protect environments where safety and availability come before everything else. This guide explains its core concepts in plain English.
What IEC 62443 is and where it came from
IEC 62443 grew out of the ISA-99 work by the International Society of Automation and is now maintained jointly with the International Electrotechnical Commission. Rather than a single document, it is a series organised into four groups: general concepts and terminology, policies and procedures for the asset owner’s security program, system-level requirements for design, and component-level requirements for the products that vendors build. Together they cover the whole lifecycle and every stakeholder, which is precisely why it has become the common language of OT security.
Crucially, IEC 62443 was written for environments where a control system runs a physical process. It accepts that you cannot always patch, that availability is paramount, and that safety functions must never be undermined. That grounding in operational reality is what separates it from IT-centric frameworks.
Zones and conduits: containing risk by design
The heart of IEC 62443 is the zones-and-conduits model. A zone is a logical or physical grouping of assets that share the same security requirements, for example a safety instrumented system, a single production cell, or the supervisory layer of a SCADA network. A conduit is the controlled communication pathway that connects zones and carries traffic between them.
The power of this approach is containment. By drawing boundaries around groups of assets and tightly controlling every conduit, you ensure that a compromise in one zone, say the office network or a single robot cell, cannot spread freely into safety-critical systems. This is the formalised, rigorous version of the network segmentation principle that underpins all sound OT design, and it maps naturally onto the Purdue model we describe in our OT and ICS security fundamentals guide. To apply it, you first conduct a risk assessment, partition the system into zones, identify the conduits, and then assign each zone a target level of protection.
Security levels SL1 to SL4
IEC 62443 defines four security levels that describe how strong a zone’s defences need to be, scaled to the capability of the threat you expect:
- SL1 protects against casual or accidental violation, such as a staff member making a mistake.
- SL2 protects against intentional violation using simple means, low resources and generic skills.
- SL3 protects against intentional violation using sophisticated means, moderate resources and ICS-specific skills.
- SL4 protects against intentional violation using sophisticated means with extended resources, the level associated with well-funded or nation-state actors.
The standard separates the target security level you decide a zone needs, the capability level a product can deliver, and the achieved level once deployed. In practice you assign a target SL to each zone based on the consequences of compromise, then select components and design controls that meet it. A drinking-water dosing control zone in a council plant might warrant SL3, while a non-critical monitoring zone might be fine at SL2. This proportionality stops you over-spending on low-risk areas and under-protecting the parts that can hurt people.
The foundational requirements behind the controls
Beneath the security levels sit seven foundational requirements that IEC 62443 uses to organise its technical controls. Understanding them helps you reason about what each security level actually demands rather than treating SL3 as an abstract number. The seven are: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. Notice that resource availability is a first-class requirement, which is exactly what you would expect from a standard built for environments where keeping the process running is paramount. As a target security level rises from SL1 to SL4, the strength expected within each of these seven areas increases, for example moving from simple passwords to multi-factor authentication and from basic logging to tamper-resistant, monitored event capture.
The three roles: asset owner, integrator and product supplier
One of the most useful contributions of IEC 62443 is that it assigns clear responsibilities to three distinct parties, because OT security failures so often fall through the cracks between them.
- The asset owner operates the facility. They are accountable for the overall security program, defining risk tolerance, setting target security levels, and maintaining the system through its life. This is you, the utility, manufacturer or council.
- The system integrator designs and commissions the control system. They are responsible for combining products into a secure architecture, implementing the zones and conduits, and handing over a system that meets the asset owner’s requirements.
- The product supplier develops the hardware and software components, such as PLCs, HMIs and robots, and must build them with secure development practices and the capability to meet the relevant security levels.
Defining these roles explicitly in contracts and acceptance testing is one of the highest-value moves an asset owner can make. It is exactly the discipline we apply when supporting clients with robot and automation integration, where the supplier, integrator and owner boundaries must be nailed down before a single machine is installed.
How IEC 62443 fits the Australian regulatory picture
IEC 62443 is not named in Australian law as mandatory, but it has become the de facto reference for OT security and is increasingly expected by regulators and within the risk management program obligations of the Security of Critical Infrastructure Act. For councils running water and SCADA assets, and for energy, transport and food operators, aligning to IEC 62443 demonstrates genuine due diligence. Our guidance for government and council cyber security and the Essential Eight baseline both complement an IEC 62443 program rather than competing with it. At the enterprise level, many operators also run ISO 27001, which governs the management system, while IEC 62443 governs the plant.
Common pitfalls when adopting the standard
In practice, Australian operators stumble in a few predictable places. The first is treating IEC 62443 as a procurement checkbox, demanding a certified product and assuming the job is done; certification of a component tells you its capability, not whether your integrator deployed it securely or whether you maintain it. The second is over-engineering, assigning every zone SL4 because it feels safer, which drives cost and operational friction without matching real risk. The third is ignoring the people and process parts of the series in favour of the technical requirements, when the asset owner’s security program, including patch management decisions, change control and incident response, is what sustains protection over a system’s twenty-year life. Avoid these by letting a clear-eyed risk assessment, not vendor marketing, drive your target levels.
Putting IEC 62443 to work
You do not adopt IEC 62443 overnight. Begin with an asset inventory and a risk assessment, define your zones and conduits, set a target security level for each, and identify the gaps between where you are and where you need to be. From there, build a prioritised roadmap that respects your safety and availability constraints, sequencing quick wins such as removing internet exposure and brokering remote access ahead of larger architectural changes. A Virtual CISO can lead this work without the cost of a permanent hire, translating the standard into a practical programme for your environment and reporting progress to your board in language they understand.
CISO Advisory provides IEC 62443-aligned OT security assessments, zone and conduit design, and secure robot integration for Australian utilities, manufacturers, logistics operators and councils. To get started, visit our contact page or call 07 2112 8502 for same-day or next-business-day support, on-site or remote Australia-wide.
Frequently asked questions
What is IEC 62443?
IEC 62443 is a series of international standards for the cybersecurity of industrial automation and control systems. Developed from the ISA-99 work, it provides a common framework covering policies, system design and component requirements, and is widely regarded as the leading global standard for securing OT environments across utilities, manufacturing and infrastructure.
What are zones and conduits in IEC 62443?
A zone is a grouping of assets that share the same security requirements, such as a safety system or a production cell. A conduit is the controlled communication path between zones. The model lets you contain incidents and apply controls proportionate to each zone's risk, rather than treating a whole plant as one flat network.
What do the security levels SL1 to SL4 mean?
Security levels describe the strength of protection a zone needs against increasingly capable attackers. SL1 defends against casual or accidental misuse, SL2 against intentional simple means, SL3 against sophisticated means with moderate resources, and SL4 against sophisticated means with extended resources such as a nation state. You set a target level per zone based on risk.
Is IEC 62443 mandatory in Australia?
It is not legally mandated by name, but it is the de facto reference for OT security and is increasingly expected by regulators and in critical infrastructure risk management programs under the SOCI Act. Aligning to IEC 62443 demonstrates due diligence and gives utilities, manufacturers and councils a defensible, structured approach.
How is IEC 62443 different from ISO 27001?
ISO 27001 governs an information security management system for an organisation, focused on IT and data. IEC 62443 is purpose-built for industrial control systems, where safety and availability dominate. They are complementary: many Australian operators run ISO 27001 at the enterprise level and IEC 62443 in the plant.
Need this handled for your organisation?
Confidential and no obligation. We respond the same business day — on-site same day / next business day, or remote, Australia-wide. Prefer to talk now? Call us 24/7 on 07 2112 8502.