A control system vendor on the other side of the world holds standing remote access to your plant. The account was created at commissioning, it uses shared credentials because a handful of engineers rotate through support, and it connects over a link nobody in your corporate security team has assessed because the plant network was never their responsibility.
That is not hypothetical. It is the most common finding in operational technology assessments here, and it exists because industrial environments were built to different priorities than corporate IT and were then quietly connected to everything.
IEC 62443 is the international series addressing security of industrial automation and control systems. In New Zealand it matters most to port and maritime operators, electricity generation and transmission, water and wastewater utilities, dairy and food processing plant, forestry and wood processing, and manufacturers running process control.
Looking for an IEC 62443 Consultant in New Zealand?
Why Your ISMS Stops at the Plant Fence
Organisations holding ISO 27001 often assume the control environment is covered. It rarely is, because the assumptions that make corporate security work do not survive contact with operational technology.
Which Parts of the Series Apply to You
You do not certify to “IEC 62443”. You conform to specific parts, and which parts depend on the role you occupy. A provider offering blanket certification without asking whether you are an asset owner, an integrator or a product supplier does not know the series.
| Part | Subject | Who It Applies To |
|---|---|---|
| IEC 62443-2-1 | Security program requirements for IACS asset owners | Asset owners – the core requirement for operators |
| IEC 62443-2-4 | Security program requirements for IACS service providers | Integrators and maintenance providers |
| IEC 62443-3-2 | Security risk assessment for system design, zones and conduits | Asset owners and integrators, during design |
| IEC 62443-3-3 | System security requirements and security levels | Asset owners and integrators, for the system as built |
| IEC 62443-4-1 | Secure product development lifecycle requirements | Product suppliers and vendors |
| IEC 62443-4-2 | Technical security requirements for IACS components | Product suppliers, for individual devices |
Zones, Conduits and Security Levels
Two concepts carry most of the practical weight. Zones group control system assets sharing common security requirements. Conduits are the controlled communication paths between them. Segmenting this way is what lets a safety instrumented system and a data historian coexist without the historian becoming a route into the safety system.
Security levels describe the capability of the adversary a zone is designed to resist, from casual or coincidental violation through to a sophisticated, well-resourced actor with specific motivation. You assign a target level to each zone based on consequence, then design controls to reach it. That forces a more useful conversation than a maturity score does: not how good is our security, but if this zone is compromised what physically happens, and who are we assuming is trying.
Have a control network you need assessed?
Ports, Maritime and Offshore
New Zealand’s economy moves through a small number of ports. Tauranga, Auckland, Lyttelton, Napier, CentrePort Wellington, Northport, Port Taranaki, Nelson, Timaru, Port Chalmers and Bluff between them handle almost everything the country imports and exports. Container handling, bulk loading, log marshalling, refrigerated cargo and pilotage coordination all run operational technology, frequently supplied by international vendors and maintained remotely.
The concentration matters. A country with a dozen significant ports has less redundancy than one with fifty, and an extended outage at a major port reroutes national supply chains rather than regional ones.
Maritime security obligations sit under the Maritime Security Act 2004, administered by Maritime New Zealand, giving effect to the international ISPS Code through security plans and assessments for port facilities and ships. Those obligations were written with physical security foremost, and the operational technology question has grown considerably since.
The maritime environment adds complications shore-based operators do not face. Remote access across satellite links. Crew rotations changing who holds system access every few weeks. Facilities interfacing with systems belonging to a different operator entirely. Vendor maintenance conducted from a timezone where your response team is asleep.
New Zealand's Regulatory Position
New Zealand has no equivalent to Australia’s Security of Critical Infrastructure Act. Content telling you that SOCI obligations or a critical infrastructure risk management programme requirement applies here is describing Australian law.
What New Zealand has is a voluntary posture supported by National Cyber Security Centre guidance, mandatory requirements for government agencies, and a stated intention to change. The Cyber Security Strategy 2026–2030 and its action plan signalled work toward a regulatory regime for critical infrastructure, and the Government consulted on exactly that between February and April 2026. Submissions have closed and advice is with Cabinet.
The practical implication is straightforward. Operators building OT security capability now will be adapting if a regime lands. Operators waiting will be starting. We will tell you where the proposals sit rather than selling on a regulation that has not arrived.
Alongside that, lifeline utilities carry duties under civil defence emergency management legislation to function during and after an emergency, which is an availability obligation with an operational technology dimension whether or not it is framed that way.
How an Engagement Runs
An asset owner with a substantial control environment should plan for twenty-six to fifty-two weeks. Two phases consistently take longer than clients expect.
Determining which role you occupy, then finding out what is actually on the control network. We use passive discovery methods appropriate to live environments. In most first engagements this phase alone surfaces devices nobody knew were connected.
Segmentation developed under 62443-3-2, with zones defined by what happens if the zone is compromised rather than by whatever VLANs currently exist. Target security levels assigned per zone. This requires engineering input rather than network input.
Current state assessed against the applicable parts and the target security levels you have set.
Policies, access control, remote access governance, patch and change management designed around real outage windows, monitoring, backup and recovery. Remote access is usually where the largest single risk reduction sits.
Security requirements written into procurement and maintenance contracts under 62443-2-4, so they are enforceable rather than aspirational.
Internal assessment, and support through third-party conformity assessment where a customer or regulator requires it.
What We Do That a General Cyber Consultancy Does Not
Environments and Locations
Port and terminal work spans Tauranga, Auckland, Lyttelton, Napier, CentrePort Wellington, Northport, Port Taranaki, Nelson, Timaru, Port Chalmers and Bluff. Energy work covers geothermal generation around Taupō and Kawerau, hydro in the Waitaki, Clutha and Manapōuri catchments, and transmission and distribution networks across both islands.
Dairy and food processing plant, which is among the most heavily automated industrial environment in the country, takes us to the Waikato, Taranaki, Manawatū, Canterbury and Southland. Forestry and wood processing work concentrates in the central North Island, Northland, Nelson and the East Coast. We also work with water and wastewater utilities nationally, manufacturers running process control, and refining and bulk fuel infrastructure.
Preparing for a customer or regulator conformity assessment?
Send Us Your Control Network Diagram
Send us your control network architecture, or the closest thing you have to a current version. The gap between the diagram and reality is usually where the useful conversation starts.
Ready to start your IEC 62443 programme?
FAQ'S
No. New Zealand has no critical infrastructure security statute and no mandated OT security framework. The Government consulted during 2026 on measures including potential legislation, and submissions have closed. Operators adopt IEC 62443 for risk and commercial reasons rather than regulatory ones.
Only if you also operate a critical infrastructure asset in Australia. New Zealand has no equivalent statute, and guidance suggesting a critical infrastructure risk management programme obligation applies here is describing Australian law rather than New Zealand law.
Conformity assessment is available against specific parts rather than the series as a whole. Product suppliers commonly pursue 62443-4-1 and 62443-4-2 assessment. Asset owners more often seek assessed conformance to 62443-2-1 or independent assurance against target security levels.
ISO 27001 is a management system standard covering information security organisation-wide. IEC 62443 is a technical and programme series specific to industrial control systems. They complement each other, and organisations with both IT and OT environments generally need both.
Because ISO 27001 rarely reaches into the control environment with enough specificity. Patching cadence, industrial protocol security, safety system separation and vendor remote access all need OT-specific treatment a corporate ISMS is not designed to provide.
Zones group control system assets sharing common security requirements. Conduits are the controlled communication paths between zones. Segmenting this way lets you apply strong controls where consequence is highest rather than protecting everything to a uniform level.
They describe the capability of the adversary a zone is designed to resist, ranging from casual or coincidental violation through to a sophisticated, well-resourced actor with specific motivation and skills. Target levels are assigned per zone based on consequence of compromise.
Port control systems are industrial automation environments, so the series applies directly. Maritime security plans under the Maritime Security Act 2004 were framed around physical security, and the operational technology dimension generally needs addressing separately.
Active scanning of legacy control systems can cause device failure or process disruption. We use passive discovery appropriate to live environments, and any active testing is planned into an agreed outage window with engineering approval beforehand.
That is a normal OT constraint rather than an obstacle. Where patching is unavailable, compensating controls apply: segmentation, restricted access paths, monitoring and detection. The series is written to accommodate exactly this reality.
If they build or maintain your control systems, yes. IEC 62443-2-4 sets security programme requirements for service providers, and those requirements belong in your contracts rather than being left to the integrator’s discretion.
Typically 26 to 52 weeks for an asset owner with a substantial control environment. Asset discovery and zone design take longer than expected in nearly every engagement, because the actual network rarely matches the documented one.





















0
Projects
0
Services
0
Clients Serving
0
Countries Serving