Conduct a cybersecurity risk assessment of an industrial control system following IEC 62443 methodology.
Implementing IEC 62443 Cybersecurity Controls for Industrial Control Systems
Apply IEC 62443 zones, conduits and security levels to assess and harden industrial control systems against cyber threats across the operational technology environment.
Course Overview
Industrial control systems designed for reliability were rarely designed with cybersecurity in mind, and connecting them to enterprise networks and remote access tools has expanded the attack surface faced by plants and process industries. IEC 62443 provides a structured framework for securing operational technology environments, and this course guides engineers and OT security specialists through applying it in practice. Participants learn to conduct a cybersecurity risk assessment of an industrial control system, partition the environment into zones and conduits based on IEC 62443-3-2, and assign target security levels reflecting the consequence of compromise for each zone. The course covers selecting foundational requirements from IEC 62443-3-3, including authentication control, use control, system integrity and restricted data flow, and translating these into controls such as network segmentation, firewall rule sets and secure remote access architecture. Participants also work through vendor requirements under IEC 62443-4-1 and IEC 62443-4-2 for procuring secure components, and practise a security level gap assessment comparing current against target state. By the end, participants can lead a zone and conduit design workshop, specify security requirements in procurement documents, and present a remediation roadmap leadership can prioritise against budget constraints.
Expected Learning Outcomes
Partition a control system environment into zones and conduits based on IEC 62443-3-2 guidance.
Assign target security levels to each zone that reflect the consequence of a cybersecurity compromise.
Select foundational requirements from IEC 62443-3-3 and translate them into network and system controls.
Specify secure remote access architecture that limits exposure of control systems to external networks.
Apply IEC 62443-4-1 and IEC 62443-4-2 requirements when procuring control system components from vendors.
Build a security level gap assessment and present a prioritised remediation roadmap to operations leadership.
Who Should Attend
OT security specialists responsible for hardening industrial control systems.
Control systems engineers designing or maintaining SCADA and DCS architecture.
Plant IT and OT convergence teams managing network segmentation projects.
Procurement engineers specifying cybersecurity requirements in control system contracts.
Risk and compliance managers overseeing industrial cybersecurity programmes.
Automation engineers implementing access control and system hardening on control networks.
Course Modules
Select any module to see its sessions and points.
01IEC 62443 Framework and Risk Assessment
2 sessions · 8 points
Session 1Understanding the IEC 62443 Series and Its Application
- Distinguish the roles of asset owners, integrators and product suppliers defined across the IEC 62443 series.
- Map the relevant parts of IEC 62443 to the lifecycle stage of a specific control system project.
- Identify how IEC 62443 complements rather than replaces existing IT security frameworks for OT environments.
- Establish the scope of a control system to be assessed, including field devices, network and supervisory layers.
Session 2Conducting a Cybersecurity Risk Assessment
- Identify credible threat scenarios relevant to the specific industrial process and control system architecture.
- Assess consequence of compromise in terms of safety, environmental and production impact rather than only data loss.
- Combine likelihood and consequence ratings to prioritise assets and functions requiring stronger protection.
- Document the risk assessment in a form that supports subsequent zone and conduit design decisions.
02Zones, Conduits and Security Levels
2 sessions · 8 points
Session 1Designing Zones and Conduits per IEC 62443-3-2
- Group assets with similar security requirements and consequence profiles into defined security zones.
- Identify conduits that carry communication between zones and specify the controls each conduit requires.
- Separate safety instrumented systems into their own zone with restricted conduits to the process control network.
- Produce a zone and conduit diagram that becomes the reference architecture for subsequent control design.
Session 2Assigning and Validating Security Levels
- Assign target security levels to each zone based on the consequence of compromise identified in the risk assessment.
- Differentiate target security level from achieved security level when assessing current system capability.
- Reconcile conflicting security level requirements where a single asset sits within multiple functional zones.
- Validate assigned security levels with operations and safety stakeholders before finalising the design.
03Implementing Foundational Requirements and Controls
2 sessions · 8 points
Session 1Identification, Authentication and Use Control
- Implement identification and authentication controls appropriate to the assigned security level of each zone.
- Configure role-based use control to restrict operator, engineer and vendor access to defined system functions.
- Apply application allow-listing on engineering workstations to prevent unauthorised software execution.
- Review default vendor accounts and credentials on control system components and remove or restrict them.
Session 2Network Segmentation and Secure Remote Access
- Design firewall rule sets that enforce restricted data flow between zones according to conduit requirements.
- Segment the control network from the enterprise network using an industrial demilitarised zone architecture.
- Specify secure remote access controls, including multi-factor authentication and session recording, for vendor access.
- Test network segmentation controls to confirm unauthorised traffic between zones is actually blocked.
04Procurement, Gap Assessment and Roadmap
2 sessions · 8 points
Session 1Applying Supplier Requirements in Procurement
- Reference IEC 62443-4-1 secure development lifecycle requirements when evaluating control system suppliers.
- Specify IEC 62443-4-2 component security requirements in procurement documents for new control system purchases.
- Request evidence of secure coding practice and vulnerability disclosure processes from system integrators.
- Build supplier security requirements into contract terms and acceptance testing criteria.
Session 2Gap Assessment and Remediation Roadmap
- Compare current achieved security level against target security level for each zone to identify gaps.
- Prioritise remediation actions by risk reduction achieved relative to implementation cost and downtime.
- Sequence remediation to align with planned outages and change windows across the affected control systems.
- Present the remediation roadmap and resource requirements to operations and cybersecurity leadership.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
