June 4, 2025
December 17, 2024
 —  
Blog

IEC 62443 Zones and Conduits: How Much Network Segmentation Is Enough?

IEC 62443 Zones and Conduits: How Much Network Segmentation Is Enough?

One question continually arises in customer discussions: "How much segmentation is enough?”. 

In the IEC 62443 framework, the concept of Zones and Conduits forms the basis of network segmentation. Going from a flat network to a segmented network is a recurring nightmare for OT CIOs/CISOs, as using IT-oriented solutions results in significant downtime, re-architecture, and expense. 

IEC 62443  emphasizes the importance of keeping the zones and conduits consistent with their network architecture to avoid complexity, but the architecture is based on the Purdue model. We see many manufacturing networks today that need to be migrated to the Purdue model, and making that shift is a significant project by itself without even considering internal segmentation.

The process of managing risk is at the core of all cybersecurity decisions, and IEC 62443 defines target security levels that are part of the decision-making process for network segmentation. The standard provides three levels of SLs:

  • Target Security Levels (SL-T): The desired level of security for a particular automation component. These define how much protection the asset owner believes is needed to protect the system, zone, or conduit, particularly considering the known vulnerabilities and cybersecurity posture of the devices in the zone (i.e., does it contain a “forever vulnerability”). 
  • Capability Security Levels (SL-C): The security countermeasures available within a system or component designed to protect the automation component without any additional countermeasures (i.e., can it automatically restrict what systems it is allowed to communicate with)
  • Achieved Security Levels (SL-A): The actual, measured SLs for a particular automation component, generally determined after operation.

In this webinar replay, we examine IEC 62443’s concepts of Zones and Conduits and explore how to determine the appropriate level of segmentation based on risk and security-level requirements.

You will also learn how modern segmentation approaches can reduce risk without forcing a disruptive network redesign or creating unnecessary operational complexity.

Watch the webinar replay, "Reducing Risk with IEC 62443’s Network Segmentation,"

OT Secure Remote Access
Network Cloaking
Network Segmentation

Russian hacktivists compromised a Polish hydropower plant through exposed ports. BlastWave cloaks OT networks, eliminating reconnaissance, exposed endpoints, credentials, and lateral movement entirely.

Explore the complete analysis of 23 OT attacks that defeated firewalls, VPNs, and air gaps.