One question continually arises in customer discussions: "How much segmentation is enough?”.
In the IEC 62443 framework, the concept of Zones and Conduits forms the basis of network segmentation. Going from a flat network to a segmented network is a recurring nightmare for OT CIOs/CISOs, as using IT-oriented solutions results in significant downtime, re-architecture, and expense.
IEC 62443 emphasizes the importance of keeping the zones and conduits consistent with their network architecture to avoid complexity, but the architecture is based on the Purdue model. We see many manufacturing networks today that need to be migrated to the Purdue model, and making that shift is a significant project by itself without even considering internal segmentation.
The process of managing risk is at the core of all cybersecurity decisions, and IEC 62443 defines target security levels that are part of the decision-making process for network segmentation. The standard provides three levels of SLs:
In this webinar replay, we examine IEC 62443’s concepts of Zones and Conduits and explore how to determine the appropriate level of segmentation based on risk and security-level requirements.
You will also learn how modern segmentation approaches can reduce risk without forcing a disruptive network redesign or creating unnecessary operational complexity.
Watch the webinar replay, "Reducing Risk with IEC 62443’s Network Segmentation,"
Russian hacktivists compromised a Polish hydropower plant through exposed ports. BlastWave cloaks OT networks, eliminating reconnaissance, exposed endpoints, credentials, and lateral movement entirely.
Explore the complete analysis of 23 OT attacks that defeated firewalls, VPNs, and air gaps.