Select Page

Australian manufacturers are increasingly asked to demonstrate cybersecurity maturity in their operational technology (OT) and industrial control systems (ICS), whether by regulators, customers, or their own risk management processes. IEC 62443, now formally adopted in Australia as AS IEC 62443, is the international standard purpose-built for this environment.

This guide covers what AS IEC 62443 actually requires, how it fits within Australia’s regulatory landscape, and the practical steps involved in working toward it. Esis is an industrial electronics supplier, not an OT cybersecurity consultancy. This guide can help manufacturers understand the standard and the hardware considerations involved in securing an industrial environment. For risk assessments, architecture design, and formal conformity work, a qualified OT cybersecurity specialist should be engaged directly.

What Is IEC 62443 and Why Does It Matter?

IEC 62443 is a series of international standards developed by the International Electrotechnical Commission specifically for industrial automation and control systems (IACS). Unlike general-purpose cybersecurity frameworks, it’s designed for the operational technology environments found in manufacturing plants, utilities, oil and gas facilities, water treatment plants, and other industrial settings.

The standard addresses the lifecycle of an industrial control system, from design and procurement through to ongoing operations and decommissioning, providing a common language for asset owners, system integrators, and product suppliers to discuss security requirements.

In July 2025, Standards Australia officially adopted the AS IEC 62443 series as national standards for protecting operational technology in critical infrastructure. The standards are modular and role-based, meaning organisations can apply the parts relevant to their specific responsibilities rather than the entire series at once. National adoption raises the standard’s profile in Australia, but it does not make IEC 62443 mandatory for every manufacturer, and applicability depends on an organisation’s specific role and regulatory obligations.

Understanding the Structure of IEC 62443

The Four Series Explained

IEC 62443 is organised into four series:

  • Series 1 (General): Foundational concepts, terminology, and security metrics that apply across the standard.
  • Series 2 (Policies and Procedures): Guidance for asset owners, service providers, and other responsible parties on establishing and governing an IACS security programme, including patch management requirements.
  • Series 3 (System Requirements): Technical and procedural requirements that asset owners, system integrators, and other responsible parties use for designing and evaluating secure control systems.
  • Series 4 (Component Requirements): Requirements for product suppliers developing secure IACS components and software.

Security Levels: The Backbone of the Framework

IEC 62443 defines Security Levels (SL) from SL 1 to SL 4, representing increasing protection against increasingly capable threat sources:

  • SL 1: Protection against casual or unintentional violations.
  • SL 2: Protection against intentional violation using simple means, low resources, generic skills, and low motivation.
  • SL 3: Protection against intentional violation using sophisticated means, moderate resources, IACS-specific skills, and moderate motivation.
  • SL 4: Protection against intentional violation using sophisticated means, extended resources, IACS-specific skills, and high motivation.

There is no universal target level that applies across Australian manufacturing. The appropriate target Security Level for a given zone or conduit (see below for definitions) follows from a documented risk assessment specific to each zone, not a generic industry default.

The Australian Regulatory Landscape

The SOCI Act: What It Actually Covers

The Security of Critical Infrastructure Act 2018 (SOCI Act) applies to organisations connected with 11 defined critical infrastructure sectors: communications, financial services and markets, data storage or processing, defence industry, higher education and research, energy, food and grocery, healthcare and medical, space technology, transport, and water and sewerage.

General manufacturing is not one of the Act’s 11 named sectors. A manufacturer does not automatically fall under SOCI Act obligations simply by supplying into a critical sector. Coverage depends on the specific organisation’s role and its connection to a defined critical infrastructure asset. Manufacturers should assess their own position against the Act’s asset definitions rather than assume coverage or exemption based on their general industry.

CIRMP Obligations

Certain organisations responsible for defined critical infrastructure assets must meet SOCI Act obligations, which may include cyber-incident reporting and maintaining a written risk management programme. Not every responsible entity has identical Critical Infrastructure Risk Management Programme (CIRMP) obligations. Applicable duties depend on the specific asset class and the organisation’s legal role, and a CIRMP itself covers more than cybersecurity, extending to supply-chain, personnel, physical, and natural hazards as well.

AS IEC 62443 can support OT cybersecurity planning, but using the standard does not automatically satisfy every SOCI Act or CIRMP requirement. Organisations with SOCI Act obligations should confirm their specific requirements directly rather than assuming standard adoption is sufficient on its own.

What the Threat Data Actually Shows

The Australian Signals Directorate’s Annual Cyber Threat Report 2023-24 found that healthcare and social assistance rose to become the most frequently reported non-government sector, not manufacturing specifically. Business email compromise was a significant self-reported business cybercrime category, and ransomware remained a pervasive threat across sectors more broadly.

The more recent 2024-25 report identifies ransomware as the most disruptive cybercrime threat facing Australian organisations, alongside compromised accounts, malware, and infrastructure attacks. Manufacturers should assess their own specific exposure and risk profile rather than relying on broad, unqualified sector claims about attack frequency.

Building an IEC 62443 Understanding: Step by Step

Step 1: Conduct a Thorough Asset Inventory

The starting point for engaging with IEC 62443 is a comprehensive inventory of industrial assets, including programmable logic controllers (PLCs), human-machine interfaces (HMIs), SCADA systems, industrial networking equipment, engineering workstations and historian servers, and remote access solutions and vendor connections. Many organisations discover undocumented legacy systems and unapproved external network connections during this process.

Step 2: Perform a Risk Assessment

IEC 62443-3-2 guides conducting a risk assessment for industrial systems, identifying critical assets, understanding the threats they face, and assessing the likelihood and consequences of a successful attack. A proper risk assessment involves operational staff, engineers, and cybersecurity specialists working together, and this is specialist work that a qualified OT cybersecurity practitioner should lead.

Step 3: Define Your Zones and Conduits

IEC 62443 introduces zones (groupings of assets with similar security requirements) and conduits (communication paths between zones). Proper segmentation is the industrial equivalent of network segmentation in IT environments. Grouping assets by criticality and applying appropriate controls at the conduits between zones can reduce unauthorised access and limit how far a security incident propagates through connected systems. It’s important to understand that  segmentation reduces risk rather than eliminating it.

A typical zone structure for a manufacturing facility might include an enterprise zone for business systems, a manufacturing operations zone for MES and production planning, a control zone for SCADA and PLC networks, a safety zone for safety instrumented systems, and a remote access zone for vendor and engineer connections. Each zone is assigned a target Security Level based on its own risk assessment, and conduits between zones are controlled with safeguards appropriate to the assessed risk, which may include industrial firewalls, data diodes, or protocol-aware inspection depending on the specific requirement.

Step 4: Implement Security Controls

IEC 62443-3-3 defines seven foundational requirements for system-level controls:

  • Identification and Authentication Control (IAC): Ensuring only authorised users and devices can access the system.
  • Use Control (UC): Enforcing least-privilege principles.
  • System Integrity (SI): Protecting the IACS against unauthorised changes.
  • Data Confidentiality (DC): Protecting sensitive operational data from unauthorised disclosure.
  • Restricted Data Flow (RDF): Controlling data flow between zones.
  • Timely Response to Events (TRE): Detecting, responding to, and recovering from security events.
  • Resource Availability (RA): Maintaining system availability under attack or adverse conditions.

Step 5: Build an OT-Specific Incident Response Capability

An IT incident response plan is not sufficient for OT environments, which have different priorities to IT. In OT, safety and availability typically take priority alongside confidentiality, and shutting down a control system managing a chemical process or production line carries implications well beyond IT downtime. An OT incident response plan needs procedures for isolating affected zones without disrupting safety systems, clear communication between OT and IT teams, and recovery procedures that prioritise safe restart of production processes.

Common Challenges Australian Manufacturers Face

Legacy Systems and the Brownfield Problem

Many Australian manufacturers operate legacy OT systems that were not designed with cybersecurity in mind. Some of these systems lack current vendor support, and others have limited update options even where support exists. IEC 62443 accommodates this reality through compensating controls such as network segmentation, unidirectional gateways, and enhanced monitoring, rather than requiring wholesale infrastructure replacement.

Skills Shortages in Australian Industry

Australia faces a shortage of professionals with combined OT and cybersecurity expertise. Manufacturers without this capability in-house typically need to engage a qualified OT cybersecurity specialist for the risk assessment, architecture, and implementation work involved.

Supply Chain Security

IEC 62443 Series 2 includes guidance on managing cybersecurity requirements through the supply chain, including vendor risk assessments, contractual security obligations, and secure remote access management. For manufacturers with globally dispersed supply chains, this is a genuine area of focus that requires dedicated attention.

How AS IEC 62443 Compares to Other Frameworks

The NIST Cybersecurity Framework (CSF) is widely used across IT and OT environments, and NIST also publishes SP 800-82 specifically for OT security, covering performance, reliability, and safety requirements relevant to industrial systems. ISO/IEC 27001 establishes an information security management system that organisations can scope around relevant information assets and risks, and is not limited to traditional IT systems.

ISO/IEC 27001 supports organisation-wide information security management. NIST CSF supports broader cyber-risk governance. AS IEC 62443 provides detailed requirements and methods specifically for industrial automation and control systems. Organisations frequently use these frameworks together rather than choosing one over the others.

Practical Starting Points

For manufacturers beginning this process:

  • Begin with a gap assessment led by a qualified OT cybersecurity specialist to understand the current state honestly.
  • Prioritise the most critical assets and highest-risk zones first.
  • Build internal awareness among operational staff, not just IT and security teams.
  • Engage a specialist for the technical risk assessment, architecture, and implementation work.
  • Treat the process as an ongoing programme rather than a fixed destination.

Early actions that can meaningfully reduce risk while a fuller programme is developed include enforcing network segmentation between IT and OT environments, implementing strong authentication for remote access to OT systems, establishing a basic asset inventory, conducting a tabletop incident response exercise involving both OT and IT teams, and reviewing vendor remote access permissions.

The Business Case for Engaging with AS IEC 62443

Any cybersecurity investment needs to be justified to the business. A successful cyberattack on an industrial system can carry high costs in lost production, remediation, and potential regulatory exposure, though the specific financial impact varies considerably by organisation and incident. Some customers and government clients are increasingly requesting evidence of OT cybersecurity maturity from suppliers, which can be a factor in commercial relationships. As the SOCI Act and associated regulations continue to evolve, manufacturers who have engaged with a recognised framework like AS IEC 62443 are generally better positioned to respond to specific compliance requirements than those starting from nothing.

Implementation timelines and costs vary significantly by organisation, current security posture, and operational complexity, and manufacturers should develop a specific plan and cost estimate with a qualified OT cybersecurity specialist rather than relying on generic industry timeframes.

How Esis Supports Australian Manufacturers with Secure Industrial Hardware

Esis is an industrial electronics supplier, with engineering services covering custom industrial PC design and building, data logger programming, wireless monitoring system integration, industrial router configuration, remote I/O module configuration, custom software development, and equipment calibration arrangements. Within an IEC 62443 programme, hardware selection is one practical area where Esis can assist directly.

When specifying industrial computing hardware for a security-conscious OT environment, relevant considerations include:

  • Supported operating systems and the vendor’s patching and update commitment for that platform
  • TPM (Trusted Platform Module) availability, confirmed per specific product model rather than assumed across a range
  • Industrial router capabilities, including firewall and VPN features where the specific model supports them
  • Managed networking equipment for zone segmentation at the network layer
  • Remote access requirements, matched to the connectivity and authentication needs of the application
  • Hardware lifecycle and patching support, since long-deployment industrial hardware needs a realistic update path
  • Vendor security documentation, requested and reviewed for the specific product being specified

Esis does not claim that a given product meets IEC 62443 requirements without the manufacturer’s exact certification or documentation to support that claim. Where product-level security evidence exists for a specific model, it should be requested and reviewed directly rather than assumed from a general product category. For industrial PC and industrial networking hardware selection within a broader OT security programme, Esis’s engineering team can help identify suitable hardware options for a specific application.

Frequently Asked Questions

What is IEC 62443 and is it mandatory for Australian manufacturers?

AS IEC 62443 is an international cybersecurity standard for industrial automation and control systems, formally adopted as a national standard in Australia in 2025. It is not universally mandatory for Australian manufacturers. Certain businesses may have SOCI Act obligations when they own, operate, or hold interests in defined critical infrastructure assets. Contractual or procurement requirements may also require specific IEC 62443 evidence.

Does general manufacturing fall under the SOCI Act?

Not automatically. The SOCI Act applies to 11 defined critical infrastructure sectors, and general manufacturing is not one of the named sectors. Coverage depends on an organisation’s specific role and connection to a defined critical infrastructure asset, which should be assessed individually rather than assumed.

How long does engaging with AS IEC 62443 typically take for a manufacturer?

Timelines vary significantly based on current security posture, operational complexity, and the specific scope involved. There is no reliable generic timeframe that applies across all manufacturers, and a realistic plan should be developed with a qualified OT cybersecurity specialist based on the organisation’s specific circumstances.

Can IEC 62443 be applied to legacy OT systems that can’t be easily updated?

Yes. IEC 62443 accommodates legacy systems through compensating controls. Some legacy systems lack current vendor support, and others have limited update options, but network segmentation, monitoring, and access controls can reduce risk without requiring immediate system replacement.

Does Esis provide IEC 62443 compliance services?

No. Esis is an industrial electronics supplier providing hardware such as industrial PCs, routers, remote I/O modules, and data loggers, along with engineering services for configuring and integrating this equipment. Risk assessments, security architecture, and formal IEC 62443 conformity work should be undertaken by a qualified OT cybersecurity specialist. Esis can assist with selecting industrial hardware suited to a security-conscious application as part of a broader programme.

What is the difference between IEC 62443 and frameworks like NIST CSF or ISO 27001?

ISO/IEC 27001 supports organisation-wide information security management and is not limited to IT systems. NIST CSF supports broader cyber-risk governance, with NIST SP 800-82 addressing OT security specifically. AS IEC 62443 provides detailed, industrial-specific requirements and methods for automation and control systems. These frameworks are commonly used together rather than as alternatives to one another.

Does having AS IEC 62443-compliant hardware satisfy SOCI Act obligations?

Not automatically. AS IEC 62443 can support OT cybersecurity planning, but SOCI Act and CIRMP obligations, where they apply, cover requirements beyond cybersecurity alone, including supply-chain, personnel, and physical hazards. Adopting the standard is one part of a broader compliance picture, not a complete substitute for it.

Conclusion

AS IEC 62443 provides a structured, industrial-specific framework for understanding and reducing OT cybersecurity risk, and its formal adoption as an Australian national standard in 2025 reflects its growing relevance to local manufacturers. It is not automatically mandatory for every manufacturer, and it does not by itself satisfy SOCI Act or CIRMP obligations where those apply.

Working through asset inventories, risk assessments, zone and conduit design, and OT-specific incident response is specialist work best undertaken with a qualified OT cybersecurity practitioner. Where the programme involves selecting industrial computing, networking, or monitoring hardware, Esis can help identify equipment suited to the application, based on verified product specifications.

 

Call Now Button