WhatsApp contact icon for Nathan ISO Consulting
WhatsApp contact icon for Nathan ISO Consulting

A control system vendor on the other side of the world holds standing remote access to your plant. The account was created at commissioning, it uses shared credentials because a handful of engineers rotate through support, and it connects over a link nobody in your corporate security team has assessed because the plant network was never their responsibility.

That is not hypothetical. It is the most common finding in operational technology assessments here, and it exists because industrial environments were built to different priorities than corporate IT and were then quietly connected to everything.

IEC 62443 is the international series addressing security of industrial automation and control systems. In New Zealand it matters most to port and maritime operators, electricity generation and transmission, water and wastewater utilities, dairy and food processing plant, forestry and wood processing, and manufacturers running process control.

Looking for an IEC 62443 Consultant in New Zealand?

Why Your ISMS Stops at the Plant Fence

Organisations holding ISO 27001 often assume the control environment is covered. It rarely is, because the assumptions that make corporate security work do not survive contact with operational technology.

  • The priority order inverts. Corporate security protects confidentiality first. In OT, availability and integrity come first and safety sits above both. A control improving confidentiality at the cost of availability is the wrong control on a plant.
  • You cannot patch on a schedule. Vendor validation and outage windows measured in years mean a patching policy borrowed from IT will be abandoned within a quarter.
  • Equipment outlives the security model. Corporate hardware turns over in three to five years. Control systems run fifteen to thirty, on protocols designed without authentication because the network was assumed to be isolated.
  • Active scanning can cause the incident. Vulnerability scanning that is routine in IT can crash legacy controllers. Consultants arriving with an IT toolkit have caused the outage they were engaged to prevent.
  • Failure is physical. Data loss is recoverable. A process running outside safe parameters, or a safety system that does not actuate, is not.

Which Parts of the Series Apply to You

You do not certify to “IEC 62443”. You conform to specific parts, and which parts depend on the role you occupy. A provider offering blanket certification without asking whether you are an asset owner, an integrator or a product supplier does not know the series.

PartSubjectWho It Applies To
IEC 62443-2-1Security program requirements for IACS asset ownersAsset owners – the core requirement for operators
IEC 62443-2-4Security program requirements for IACS service providersIntegrators and maintenance providers
IEC 62443-3-2Security risk assessment for system design, zones and conduitsAsset owners and integrators, during design
IEC 62443-3-3System security requirements and security levelsAsset owners and integrators, for the system as built
IEC 62443-4-1Secure product development lifecycle requirementsProduct suppliers and vendors
IEC 62443-4-2Technical security requirements for IACS componentsProduct suppliers, for individual devices

Zones, Conduits and Security Levels

Two concepts carry most of the practical weight. Zones group control system assets sharing common security requirements. Conduits are the controlled communication paths between them. Segmenting this way is what lets a safety instrumented system and a data historian coexist without the historian becoming a route into the safety system.

Security levels describe the capability of the adversary a zone is designed to resist, from casual or coincidental violation through to a sophisticated, well-resourced actor with specific motivation. You assign a target level to each zone based on consequence, then design controls to reach it. That forces a more useful conversation than a maturity score does: not how good is our security, but if this zone is compromised what physically happens, and who are we assuming is trying.

Have a control network you need assessed?

Ports, Maritime and Offshore

New Zealand’s economy moves through a small number of ports. Tauranga, Auckland, Lyttelton, Napier, CentrePort Wellington, Northport, Port Taranaki, Nelson, Timaru, Port Chalmers and Bluff between them handle almost everything the country imports and exports. Container handling, bulk loading, log marshalling, refrigerated cargo and pilotage coordination all run operational technology, frequently supplied by international vendors and maintained remotely.

The concentration matters. A country with a dozen significant ports has less redundancy than one with fifty, and an extended outage at a major port reroutes national supply chains rather than regional ones.

Maritime security obligations sit under the Maritime Security Act 2004, administered by Maritime New Zealand, giving effect to the international ISPS Code through security plans and assessments for port facilities and ships. Those obligations were written with physical security foremost, and the operational technology question has grown considerably since.

The maritime environment adds complications shore-based operators do not face. Remote access across satellite links. Crew rotations changing who holds system access every few weeks. Facilities interfacing with systems belonging to a different operator entirely. Vendor maintenance conducted from a timezone where your response team is asleep.

New Zealand's Regulatory Position

New Zealand has no equivalent to Australia’s Security of Critical Infrastructure Act. Content telling you that SOCI obligations or a critical infrastructure risk management programme requirement applies here is describing Australian law.

What New Zealand has is a voluntary posture supported by National Cyber Security Centre guidance, mandatory requirements for government agencies, and a stated intention to change. The Cyber Security Strategy 2026–2030 and its action plan signalled work toward a regulatory regime for critical infrastructure, and the Government consulted on exactly that between February and April 2026. Submissions have closed and advice is with Cabinet.

The practical implication is straightforward. Operators building OT security capability now will be adapting if a regime lands. Operators waiting will be starting. We will tell you where the proposals sit rather than selling on a regulation that has not arrived.

Alongside that, lifeline utilities carry duties under civil defence emergency management legislation to function during and after an emergency, which is an availability obligation with an operational technology dimension whether or not it is framed that way.

How an Engagement Runs

An asset owner with a substantial control environment should plan for twenty-six to fifty-two weeks. Two phases consistently take longer than clients expect.

Phase One – Role, Scope and Asset Discovery

Determining which role you occupy, then finding out what is actually on the control network. We use passive discovery methods appropriate to live environments. In most first engagements this phase alone surfaces devices nobody knew were connected.

Phase Two – Zone Design and Consequence Analysis

Segmentation developed under 62443-3-2, with zones defined by what happens if the zone is compromised rather than by whatever VLANs currently exist. Target security levels assigned per zone. This requires engineering input rather than network input.

Phase Three – Gap Assessment

Current state assessed against the applicable parts and the target security levels you have set.

Phase Four – Programme Build

Policies, access control, remote access governance, patch and change management designed around real outage windows, monitoring, backup and recovery. Remote access is usually where the largest single risk reduction sits.

Phase Five – Vendor and Integrator Controls

Security requirements written into procurement and maintenance contracts under 62443-2-4, so they are enforceable rather than aspirational.

Phase Six – Assurance

Internal assessment, and support through third-party conformity assessment where a customer or regulator requires it.

What We Do That a General Cyber Consultancy Does Not

  • We ask which role you occupy before quoting. Asset owner, integrator and product supplier are three different projects.
  • We do not scan live control networks. Passive discovery first, and any active testing planned into an agreed outage window with engineering approval.
  • We design segmentation around consequence. Zones defined by physical outcome, not by inherited network topology.
  • We build programmes that survive an outage schedule. A patch policy ignoring vendor validation and long turnaround cycles gets abandoned and leaves you worse off than none.
  • We treat remote access as the primary exposure. In New Zealand OT environments with offshore vendor support, it usually is, and it is also the fastest thing to fix.
  • We write incident response for a physical process. Isolating a network segment may not be available when the process is running. Response has to account for plant state and safety systems.
  • We do not import Australian regulation. There is no SOCI Act here. Building an OT programme against obligations that do not apply wastes money and misses the ones that do.

Environments and Locations

Port and terminal work spans Tauranga, Auckland, Lyttelton, Napier, CentrePort Wellington, Northport, Port Taranaki, Nelson, Timaru, Port Chalmers and Bluff. Energy work covers geothermal generation around Taupō and Kawerau, hydro in the Waitaki, Clutha and Manapōuri catchments, and transmission and distribution networks across both islands.

Dairy and food processing plant, which is among the most heavily automated industrial environment in the country, takes us to the Waikato, Taranaki, Manawatū, Canterbury and Southland. Forestry and wood processing work concentrates in the central North Island, Northland, Nelson and the East Coast. We also work with water and wastewater utilities nationally, manufacturers running process control, and refining and bulk fuel infrastructure.

Preparing for a customer or regulator conformity assessment?

Send Us Your Control Network Diagram

Send us your control network architecture, or the closest thing you have to a current version. The gap between the diagram and reality is usually where the useful conversation starts.

Ready to start your IEC 62443 programme?

FAQ'S

No. New Zealand has no critical infrastructure security statute and no mandated OT security framework. The Government consulted during 2026 on measures including potential legislation, and submissions have closed. Operators adopt IEC 62443 for risk and commercial reasons rather than regulatory ones.

Only if you also operate a critical infrastructure asset in Australia. New Zealand has no equivalent statute, and guidance suggesting a critical infrastructure risk management programme obligation applies here is describing Australian law rather than New Zealand law.

Conformity assessment is available against specific parts rather than the series as a whole. Product suppliers commonly pursue 62443-4-1 and 62443-4-2 assessment. Asset owners more often seek assessed conformance to 62443-2-1 or independent assurance against target security levels.

ISO 27001 is a management system standard covering information security organisation-wide. IEC 62443 is a technical and programme series specific to industrial control systems. They complement each other, and organisations with both IT and OT environments generally need both.

Because ISO 27001 rarely reaches into the control environment with enough specificity. Patching cadence, industrial protocol security, safety system separation and vendor remote access all need OT-specific treatment a corporate ISMS is not designed to provide.

Zones group control system assets sharing common security requirements. Conduits are the controlled communication paths between zones. Segmenting this way lets you apply strong controls where consequence is highest rather than protecting everything to a uniform level.

They describe the capability of the adversary a zone is designed to resist, ranging from casual or coincidental violation through to a sophisticated, well-resourced actor with specific motivation and skills. Target levels are assigned per zone based on consequence of compromise.

Port control systems are industrial automation environments, so the series applies directly. Maritime security plans under the Maritime Security Act 2004 were framed around physical security, and the operational technology dimension generally needs addressing separately.

Active scanning of legacy control systems can cause device failure or process disruption. We use passive discovery appropriate to live environments, and any active testing is planned into an agreed outage window with engineering approval beforehand.

That is a normal OT constraint rather than an obstacle. Where patching is unavailable, compensating controls apply: segmentation, restricted access paths, monitoring and detection. The series is written to accommodate exactly this reality.

If they build or maintain your control systems, yes. IEC 62443-2-4 sets security programme requirements for service providers, and those requirements belong in your contracts rather than being left to the integrator’s discretion.

Typically 26 to 52 weeks for an asset owner with a substantial control environment. Asset discovery and zone design take longer than expected in nearly every engagement, because the actual network rarely matches the documented one.

CONTACT
Reach out to us for any inquiries, collaborations,
or just to say hello!

Contact information for Nathan ISO Consulting

CLIENTELE
Our Valuable Client

WHEN NUMBERS MATTER
Empowering Insights into our Business Performance