WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

A control system vendor in another country holds standing remote access to your plant. The account was created during commissioning, it uses shared credentials because three engineers rotate through support, and it connects over a link that your corporate security team has never assessed because the plant network is not their responsibility.

That is not a hypothetical. It is the single most common finding in Australian OT security assessments, and it exists because industrial environments were built to a different set of priorities than corporate IT and were then quietly connected to everything.

IEC 62443 is the international series addressing the security of industrial automation and control systems. In Australia it matters most to operators of ports, offshore energy facilities, water and electricity networks, mining fixed plant, rail signalling and manufacturing process control.

Why your ISMS stops at the plant fence

Organisations holding ISO 27001 frequently assume the control environment is covered. It rarely is, because the assumptions that make corporate security work do not survive contact with operational technology.

  • The priority order inverts. Corporate security protects confidentiality first. In OT, availability and integrity come first, and safety sits above all of it. A control that improves confidentiality at the cost of availability is the wrong control on a plant.
  • You cannot patch on a schedule. Vendor validation requirements and outage windows measured in years mean a patching policy borrowed from IT will be abandoned within a quarter.
  • The equipment outlives the security model. Corporate hardware turns over in three to five years. Control systems run fifteen to thirty, sometimes longer, on protocols like Modbus and DNP3 that were designed without authentication because the network was assumed to be physically isolated.
  • Active scanning can cause the incident. Vulnerability scanning that is routine in IT can crash legacy controllers. Consultants who arrive with an IT toolkit have been known to cause the outage they were engaged to prevent.
  • Failure has physical consequences. Data loss is recoverable. A process that runs outside safe parameters, or a safety system that does not actuate, is not.

Which parts of the series apply to you

You do not certify to “IEC 62443”. You conform to specific parts, and which parts depend on the role you occupy. A provider offering blanket IEC 62443 certification without asking whether you are an asset owner, an integrator or a product supplier does not know the series.

PartSubjectWho it applies to
IEC 62443-2-1Security program requirements for IACS asset ownersAsset owners — the core requirement for operators
IEC 62443-2-4Security program requirements for IACS service providersIntegrators and maintenance providers
IEC 62443-3-2Security risk assessment for system design, zones and conduitsAsset owners and integrators, during design
IEC 62443-3-3System security requirements and security levelsAsset owners and integrators, for the system as built
IEC 62443-4-1Secure product development lifecycle requirementsProduct suppliers and vendors
IEC 62443-4-2Technical security requirements for IACS componentsProduct suppliers, for individual devices

Zones, conduits and security levels

Two concepts carry most of the practical weight. Zones group control system assets that share common security requirements. Conduits are the controlled communication paths between them. Segmenting this way is what allows a safety instrumented system and a data historian to coexist without the historian becoming a route into the safety system.

Security levels describe the capability of the adversary a zone is designed to resist, running from casual or coincidental violation up to a sophisticated, well-resourced actor with specific motivation and skills. You assign a target level to each zone based on consequence, then design controls to reach it.

This is more useful than a maturity score because it forces a specific conversation. Not “how good is our security”, but “if this zone is compromised, what physically happens, and who are we assuming is trying?”

Maritime, ports and offshore

Australia's ports and offshore energy facilities carry a concentration of OT risk that has drawn increasing regulatory attention. Container terminal operations, bulk loading systems, tug and pilotage coordination, platform control systems and subsea infrastructure all run operational technology, frequently supplied by international vendors and maintained remotely.

The maritime environment adds complications that shore-based operators do not face. Remote access across satellite links with variable bandwidth. Crew rotations that change who holds system access every few weeks. Facilities that interface with port systems belonging to a different operator entirely. Vendor maintenance conducted from a timezone where your incident response team is asleep.

Australian maritime and offshore facility security obligations sit under federal transport security legislation, and cyber provisions within that framework have been strengthened. Where a facility is also a critical infrastructure asset, SOCI Act obligations apply in parallel rather than instead.

The Australian regulatory picture

The Security of Critical Infrastructure Act 2018 requires responsible entities in declared sectors to maintain a critical infrastructure risk management program addressing all hazards that could affect asset availability. Cyber is one hazard category among several. The Act does not mandate IEC 62443, but for operational technology environments it is the most technically appropriate framework available and provides strong evidence of a structured approach.

Energy sector participants also work within the Australian Energy Sector Cyber Security Framework, and IEC 62443 supplies the technical depth behind an AESCSF maturity assessment for control system environments. Rail transport operators carry signalling and control system security obligations within their safety management systems under rail safety national law. Port facilities and offshore facilities carry obligations under transport security legislation.

Beneath the regulation sits commercial pressure. Customers in critical supply chains, and insurers, increasingly ask operators to evidence OT security capability specifically rather than accepting a corporate ISO 27001 certificate as covering the plant.

How an engagement runs

An asset owner with a substantial control environment should plan for twenty-six to fifty-two weeks. Two phases consistently take longer than clients expect.

Phase one — Role, scope and asset discovery

Determining whether you are an asset owner, integrator, product supplier or more than one, then finding out what is actually on the control network. We use passive discovery methods appropriate to live environments. In most first engagements this phase alone surfaces devices nobody knew were connected, which is why it runs three to six weeks rather than one.

Phase two — Zone design and consequence analysis

Segmentation developed under 62443-3-2, with zones defined by what happens if the zone is compromised rather than by whatever VLANs currently exist. Target security levels assigned per zone. Six to nine weeks, and it requires engineering input rather than network input.

Phase three — Gap assessment

Current state assessed against the applicable parts and the target security levels you have set. Three to four weeks.

Phase four — Program build

Policies, access control, remote access governance, patch and change management designed around real outage windows, monitoring, backup and recovery. Eight to sixteen weeks, and remote access is where the largest single risk reduction usually sits.

Phase five — Vendor and integrator controls

Security requirements written into procurement and maintenance contracts under 62443-2-4, so they are enforceable rather than aspirational.

Phase six — Assurance

Internal assessment, and support through third-party conformity assessment where a customer or regulator requires it.

What we do that a general cyber consultancy does not

  • We ask which role you occupy before quoting. Asset owner, integrator and product supplier are three different projects with three different cost profiles.
  • We do not scan live control networks. Passive discovery first, and any active testing planned into an agreed outage window with engineering approval.
  • We design segmentation around consequence. Zones defined by physical outcome, not by the network topology someone inherited.
  • We build programs that survive an outage schedule. A patch policy that ignores vendor validation and two-year turnaround cycles is abandoned within a quarter and leaves you worse off than having none.
  • We treat remote access as the primary exposure. In Australian OT environments with overseas vendor support, it usually is, and it is also the fastest thing to fix.
  • We write incident response for a physical process. Isolating a network segment may not be an available option when the process is running. Response plans have to account for plant state and safety systems.
  • We map to SOCI and AESCSF as we go. You already carry regulatory obligations. The OT program should discharge them rather than generating a parallel evidence set.

Environments and locations we work in

Port and terminal work spans Port Botany, the Port of Melbourne, the Port of Brisbane, Fremantle, Port Hedland, Dampier, Gladstone, Newcastle, Townsville and Darwin. Offshore energy and LNG work covers the North West Shelf, Karratha, Dampier, Darwin, Bass Strait and Gladstone.

Utility work covers electricity and gas networks and water and wastewater operators in every state, with concentration in New South Wales, Victoria, Queensland and Western Australia. Mining fixed plant and processing takes us to the Pilbara, the Goldfields, the Bowen Basin, the Hunter Valley, Mount Isa and Roxby Downs.

Rail and signalling work follows the metropolitan networks and freight corridors out of Sydney, Melbourne, Brisbane, Perth and Adelaide. Manufacturing process control clients sit in Melbourne, Geelong, Sydney, Wollongong, Adelaide and Kwinana.

FAQ'S

Conformity assessment is available against specific parts rather than the series as a whole. Product suppliers commonly pursue 62443-4-1 and 62443-4-2 assessment. Asset owners more often seek assessed conformance to 62443-2-1 or independent assurance against target security levels.

ISO 27001 is a management system standard covering information security organisation-wide. IEC 62443 is a technical and program series specific to industrial automation and control systems. They complement each other, and organisations with both IT and OT environments generally need both.

Because ISO 27001 rarely reaches into the control environment with enough specificity. Patching cadence, industrial protocol security, safety system separation and vendor remote access all require OT-specific treatment that a corporate ISMS is not designed to provide.

They describe the capability of the adversary a zone is designed to resist, from casual or coincidental violation through to a sophisticated, well-resourced actor with specific motivation. Target levels are assigned per zone based on the consequence of compromise.

Zones group control system assets sharing common security requirements. Conduits are the controlled communication paths between zones. Segmenting this way lets you apply strong controls where consequence is highest rather than protecting everything to a uniform level.

No. The Act requires a critical infrastructure risk management program addressing all hazards including cyber, and permits different frameworks. IEC 62443 is the most technically appropriate choice for operational technology and provides strong evidence of a structured approach.

Active scanning of legacy control systems can cause device failure or process disruption. We use passive discovery appropriate to live environments, and any active testing is planned into an agreed outage window with engineering approval beforehand.

That is a normal OT constraint rather than an obstacle. Where patching is unavailable, compensating controls apply: network segmentation, restricted access paths, monitoring and detection. The series is written to accommodate exactly this reality.

Port and offshore control systems are industrial automation environments, so the series applies directly. Additional complications include satellite-linked remote access, crew rotation affecting access management, and interfaces with systems owned by a different operator.

If they build or maintain your control systems, yes. IEC 62443-2-4 sets security program requirements for service providers, and those requirements belong in your contracts rather than being left to the integrator's own discretion.

Typically 26 to 52 weeks for an asset owner with a substantial control environment. Asset discovery and zone design take longer than expected in almost every engagement, because the actual network rarely matches the documented one.

Industrial and maritime environments nationally, including North West Shelf and Pilbara facilities, Queensland ports and coal infrastructure, New South Wales and Victorian networks and terminals, and remote operations across Western Australia and the Northern Territory.

Send us your control network diagram

Send us your control network architecture, or the closest thing you have to a current version. The gap between the diagram and reality is usually where the useful conversation starts.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance