Skip to main content
Security & Safety

Stop Treating Security as an Add-On: Why OT Needs ISA/IEC 62443 Now

We can't bolt security onto aging industrial networks. The only way forward is to bake it into every layer, and that means adopting ISA/IEC 62443 as our common language.

The Myth of the Air Gap

We've all heard it: "Our OT network is air-gapped, so we're safe." That's wrong. It was never true, and it's even less true today. The moment we connect a sensor to a gateway, a PLC to a historian, or a controller to the cloud, we've opened a door. The real question isn't whether we're connected—it's whether we're prepared.

Our Thesis: Security Cannot Be an Afterthought

Here's what we believe: security in industrial networking isn't a feature you add; it's a property you design. The old way—build the network, then bolt on a firewall—is failing. We need a different approach, and the only credible one is to adopt the ISA/IEC 62443 series as the backbone of our OT security posture. It's not a silver bullet, but it's the best framework we've got, and it's gaining real traction.

Why the Old Protocols Aren't Enough

Look at the protocols we grew up with. Modbus, born in the late 1970s, uses a master-slave register model with no built-in security (OPC Foundation). PROFINET and EtherNet/IP are real-time workhorses, but they rely on the network's physical security. These protocols are fine for moving data fast, but they were designed for a closed world. The moment we open that world to IIoT and cloud analytics, we're exposed.

That's why the industry is shifting. The global industrial automation market is projected to hit $326.48 billion by 2032 (Maximize Market Research), and the Industrial IoT market is growing even faster, at a CAGR of 12.2% (Maximize Market Research). As we connect more, we expose more. We can't keep running on trust.

ISA/IEC 62443: Not Just Another Standard

ISA/IEC 62443 is different. It defines requirements and processes for securing industrial automation and control systems (IACS), bridging the gap between OT and IT (ISA/IEC 62443). It's not a checklist; it's a framework that covers the entire lifecycle, from design to decommissioning. It's been recognized by the IEC as a horizontal standard, and it's endorsed by the United Nations (ISA/IEC 62443). That's not trivial.

And it's not just for the big guys. The ISA Global Cybersecurity Alliance, founded in 2019, now has more than 50 member companies with over $1.5 trillion in aggregate revenue (ISA/IEC 62443). That's a lot of weight behind this approach.

Addressing the Counter-Argument: "We Don't Have Time for Another Standard"

I hear the pushback: "We're already overloaded with standards—why add another?" Fair point. But consider this: CISA's Secure by Demand guidance warns that threat actors exploit weak authentication, insecure settings, and outdated protocols (CISA Industrial Control Systems). We're not just checking boxes; we're protecting physical assets. The cost of a breach isn't just data loss—it could be a fire, an explosion, or worse.

And yes, 62443 is a lot to absorb. But you don't have to do it all at once. Start with the foundational requirements—asset identification, risk assessment, and access control. Build from there. The alternative is waiting for an incident to force your hand, and that's a much more expensive teacher.

A Concrete Example: Retrofitting a Legacy Line

Let's make this real. Imagine a mid-sized plant with a dozen Modbus RTU devices feeding a legacy PLC. The network is flat, and there's no segmentation. To comply with 62443, you'd first inventory every device, then segment the network into zones and conduits. You'd put a firewall between the PLC and the HMI, and require authentication for any remote access. It's work, but it's doable. The standard gives you a roadmap, not a blank page.

And here's the kicker: you don't have to rip out your existing protocols. 62443 is protocol-agnostic. It works with Modbus, PROFINET, EtherNet/IP, and OPC UA. You can still run your real-time motion control over PROFINET, but you'll do it inside a secured zone.

The Way Forward

We can't keep pretending security is optional. The data is clear: the industrial automation market is booming, and so are the threats. The only way to stay ahead is to embed security into every layer of our industrial networks. That means adopting ISA/IEC 62443 as our common language, and doing it now. It's not glamorous, but it's necessary. Let's get to work.

Sources

  • OPC Foundation - https://opcfoundation.org/
  • Maximize Market Research - https://www.maximizemarketresearch.com/
  • ISA/IEC 62443 - https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards
  • CISA Industrial Control Systems - https://www.cisa.gov/topics/industrial-control-systems

Share this article:

Comments (0)

No comments yet. Be the first to comment!