A control system vendor in another country holds standing remote access to your plant. The account was created during commissioning, it uses shared credentials because three engineers rotate through support, and it connects over a link that your corporate security team has never assessed because the plant network is not their responsibility.
That is not a hypothetical. It is the single most common finding in Australian OT security assessments, and it exists because industrial environments were built to a different set of priorities than corporate IT and were then quietly connected to everything.
IEC 62443 is the international series addressing the security of industrial automation and control systems. In Australia it matters most to operators of ports, offshore energy facilities, water and electricity networks, mining fixed plant, rail signalling and manufacturing process control.
Why your ISMS stops at the plant fence
Organisations holding ISO 27001 frequently assume the control environment is covered. It rarely is, because the assumptions that make corporate security work do not survive contact with operational technology.
Which parts of the series apply to you
You do not certify to “IEC 62443”. You conform to specific parts, and which parts depend on the role you occupy. A provider offering blanket IEC 62443 certification without asking whether you are an asset owner, an integrator or a product supplier does not know the series.
| Part | Subject | Who it applies to |
|---|---|---|
| IEC 62443-2-1 | Security program requirements for IACS asset owners | Asset owners — the core requirement for operators |
| IEC 62443-2-4 | Security program requirements for IACS service providers | Integrators and maintenance providers |
| IEC 62443-3-2 | Security risk assessment for system design, zones and conduits | Asset owners and integrators, during design |
| IEC 62443-3-3 | System security requirements and security levels | Asset owners and integrators, for the system as built |
| IEC 62443-4-1 | Secure product development lifecycle requirements | Product suppliers and vendors |
| IEC 62443-4-2 | Technical security requirements for IACS components | Product suppliers, for individual devices |
Zones, conduits and security levels
Two concepts carry most of the practical weight. Zones group control system assets that share common security requirements. Conduits are the controlled communication paths between them. Segmenting this way is what allows a safety instrumented system and a data historian to coexist without the historian becoming a route into the safety system.
Security levels describe the capability of the adversary a zone is designed to resist, running from casual or coincidental violation up to a sophisticated, well-resourced actor with specific motivation and skills. You assign a target level to each zone based on consequence, then design controls to reach it.
This is more useful than a maturity score because it forces a specific conversation. Not “how good is our security”, but “if this zone is compromised, what physically happens, and who are we assuming is trying?”
Maritime, ports and offshore
Australia's ports and offshore energy facilities carry a concentration of OT risk that has drawn increasing regulatory attention. Container terminal operations, bulk loading systems, tug and pilotage coordination, platform control systems and subsea infrastructure all run operational technology, frequently supplied by international vendors and maintained remotely.
The maritime environment adds complications that shore-based operators do not face. Remote access across satellite links with variable bandwidth. Crew rotations that change who holds system access every few weeks. Facilities that interface with port systems belonging to a different operator entirely. Vendor maintenance conducted from a timezone where your incident response team is asleep.
Australian maritime and offshore facility security obligations sit under federal transport security legislation, and cyber provisions within that framework have been strengthened. Where a facility is also a critical infrastructure asset, SOCI Act obligations apply in parallel rather than instead.
The Australian regulatory picture
The Security of Critical Infrastructure Act 2018 requires responsible entities in declared sectors to maintain a critical infrastructure risk management program addressing all hazards that could affect asset availability. Cyber is one hazard category among several. The Act does not mandate IEC 62443, but for operational technology environments it is the most technically appropriate framework available and provides strong evidence of a structured approach.
Energy sector participants also work within the Australian Energy Sector Cyber Security Framework, and IEC 62443 supplies the technical depth behind an AESCSF maturity assessment for control system environments. Rail transport operators carry signalling and control system security obligations within their safety management systems under rail safety national law. Port facilities and offshore facilities carry obligations under transport security legislation.
Beneath the regulation sits commercial pressure. Customers in critical supply chains, and insurers, increasingly ask operators to evidence OT security capability specifically rather than accepting a corporate ISO 27001 certificate as covering the plant.
How an engagement runs
An asset owner with a substantial control environment should plan for twenty-six to fifty-two weeks. Two phases consistently take longer than clients expect.
Determining whether you are an asset owner, integrator, product supplier or more than one, then finding out what is actually on the control network. We use passive discovery methods appropriate to live environments. In most first engagements this phase alone surfaces devices nobody knew were connected, which is why it runs three to six weeks rather than one.
Segmentation developed under 62443-3-2, with zones defined by what happens if the zone is compromised rather than by whatever VLANs currently exist. Target security levels assigned per zone. Six to nine weeks, and it requires engineering input rather than network input.
Current state assessed against the applicable parts and the target security levels you have set. Three to four weeks.
Policies, access control, remote access governance, patch and change management designed around real outage windows, monitoring, backup and recovery. Eight to sixteen weeks, and remote access is where the largest single risk reduction usually sits.
Security requirements written into procurement and maintenance contracts under 62443-2-4, so they are enforceable rather than aspirational.
Internal assessment, and support through third-party conformity assessment where a customer or regulator requires it.
What we do that a general cyber consultancy does not
Environments and locations we work in
Port and terminal work spans Port Botany, the Port of Melbourne, the Port of Brisbane, Fremantle, Port Hedland, Dampier, Gladstone, Newcastle, Townsville and Darwin. Offshore energy and LNG work covers the North West Shelf, Karratha, Dampier, Darwin, Bass Strait and Gladstone.
Utility work covers electricity and gas networks and water and wastewater operators in every state, with concentration in New South Wales, Victoria, Queensland and Western Australia. Mining fixed plant and processing takes us to the Pilbara, the Goldfields, the Bowen Basin, the Hunter Valley, Mount Isa and Roxby Downs.
Rail and signalling work follows the metropolitan networks and freight corridors out of Sydney, Melbourne, Brisbane, Perth and Adelaide. Manufacturing process control clients sit in Melbourne, Geelong, Sydney, Wollongong, Adelaide and Kwinana.
FAQ'S
Conformity assessment is available against specific parts rather than the series as a whole. Product suppliers commonly pursue 62443-4-1 and 62443-4-2 assessment. Asset owners more often seek assessed conformance to 62443-2-1 or independent assurance against target security levels.
ISO 27001 is a management system standard covering information security organisation-wide. IEC 62443 is a technical and program series specific to industrial automation and control systems. They complement each other, and organisations with both IT and OT environments generally need both.
Because ISO 27001 rarely reaches into the control environment with enough specificity. Patching cadence, industrial protocol security, safety system separation and vendor remote access all require OT-specific treatment that a corporate ISMS is not designed to provide.
They describe the capability of the adversary a zone is designed to resist, from casual or coincidental violation through to a sophisticated, well-resourced actor with specific motivation. Target levels are assigned per zone based on the consequence of compromise.
Zones group control system assets sharing common security requirements. Conduits are the controlled communication paths between zones. Segmenting this way lets you apply strong controls where consequence is highest rather than protecting everything to a uniform level.
No. The Act requires a critical infrastructure risk management program addressing all hazards including cyber, and permits different frameworks. IEC 62443 is the most technically appropriate choice for operational technology and provides strong evidence of a structured approach.
Active scanning of legacy control systems can cause device failure or process disruption. We use passive discovery appropriate to live environments, and any active testing is planned into an agreed outage window with engineering approval beforehand.
That is a normal OT constraint rather than an obstacle. Where patching is unavailable, compensating controls apply: network segmentation, restricted access paths, monitoring and detection. The series is written to accommodate exactly this reality.
Port and offshore control systems are industrial automation environments, so the series applies directly. Additional complications include satellite-linked remote access, crew rotation affecting access management, and interfaces with systems owned by a different operator.
If they build or maintain your control systems, yes. IEC 62443-2-4 sets security program requirements for service providers, and those requirements belong in your contracts rather than being left to the integrator's own discretion.
Typically 26 to 52 weeks for an asset owner with a substantial control environment. Asset discovery and zone design take longer than expected in almost every engagement, because the actual network rarely matches the documented one.
Industrial and maritime environments nationally, including North West Shelf and Pilbara facilities, Queensland ports and coal infrastructure, New South Wales and Victorian networks and terminals, and remote operations across Western Australia and the Northern Territory.
Send us your control network diagram
Send us your control network architecture, or the closest thing you have to a current version. The gap between the diagram and reality is usually where the useful conversation starts.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving