OT CYBERSECURITY

OT Cybersecurity Explained: IEC 62443, the Purdue Model and Where to Start

Why securing a plant is not the same as securing an office, what the Purdue model and ISA/IEC 62443 actually describe, and the first practical steps an automation engineer can take.

By EDWartens engineering team 10 December 2025 Updated 5 October 2026 8 min
OT Cybersecurity Explained: IEC 62443, the Purdue Model and Where to Start

OT cybersecurity protects the systems that run physical processes: PLCs, SCADA, DCS, safety systems and the networks between them. It differs from IT security because safety and availability come first, equipment runs for decades, and many industrial protocols have no authentication. ISA/IEC 62443 is the standard series most plants use to organise it.

“Purdue Model for Industrial Control Systems” by Instrumentation Tools, 9 min. Played from the creator's own YouTube channel; the video belongs to them.

In this lesson by Instrumentation Tools, from the Purdue model module of our free ICS Security Foundations course, you get the Purdue model for industrial control systems, the map almost every OT security design starts from. The rest of this guide explains what to do with that map.

Why OT is not IT

An office network and a plant network can use the same switches and the same Windows versions, but they fail in different ways.

  • Priorities. A leaked spreadsheet is bad; a valve opening at the wrong time can hurt someone. Safety and availability come before confidentiality.
  • Lifetimes. Controllers and HMIs run for decades. Many run operating systems or firmware no longer supported by the vendor.
  • Patching. A patch may need a shutdown, a vendor's approval and a test, so plants patch on a schedule of months or years, not days.
  • Protocols. Modbus and many older industrial protocols accept any well-formed command from anyone who can reach the device. Security has to come from the network around them.
  • Testing. Aggressive scanning can fault fragile devices. OT assessments start passively.

The Purdue model in brief

The Purdue reference model places systems in levels. Level 0 is the process itself: sensors, actuators and motors. Level 1 is basic control: PLCs and controllers. Level 2 is supervision: HMIs, SCADA and DCS operator stations. Level 3 is site operations: historians, MES and engineering servers. Levels 4 and 5 are the business and enterprise networks.

The most important line is between levels 3 and 4. Good practice places an industrial DMZ there, so that nothing on the business network talks directly to anything on the control network. Data leaves through a mirrored historian or a broker in the DMZ, and remote access arrives through a controlled jump host.

What ISA/IEC 62443 covers

ISA/IEC 62443 is a series of standards for the security of industrial automation and control systems. It is organised in four groups: general concepts, policies and procedures for the asset owner, system-level requirements, and component-level requirements for product suppliers. It assigns responsibilities to three roles: the asset owner who runs the plant, the system integrator who builds the system, and the product supplier who makes the components.

Three ideas carry most of the weight:

  • Zones and conduits. Group assets with the same security needs into zones, and define every communication path between zones as a conduit with controls on it.
  • Security levels. A target level from 1 to 4 for each zone, from protection against casual or accidental misuse up to protection against sophisticated, well-resourced attackers with industrial knowledge.
  • Foundational requirements. Seven areas that system and component requirements are grouped under.
The seven foundational requirements of ISA/IEC 62443
The seven foundational requirements of ISA/IEC 62443

In practice, FR1 and FR2 mean unique accounts and roles instead of a shared password on every HMI. FR3 means knowing when PLC logic or firmware has changed. FR5 is segmentation. FR6 is logging and someone looking at the logs. FR7 is making sure security measures, backups and redundancy keep the process running.

Other references are worth knowing. NIST SP 800-82, the US Guide to Operational Technology Security, is freely available and practical. CISA publishes advisories on vulnerabilities in industrial products that are worth following for the brands on your site. In the EU, makers of machines and connected products also face security duties under the Cyber Resilience Act; see Cyber Resilience Act reporting obligations.

How incidents usually reach the plant

You do not need exotic attacks to lose production. The common routes are ordinary:

  • Ransomware on the business network that spreads through a flat network, or forces a shutdown because nobody knows what is connected.
  • Remote access tools installed for convenience and never removed.
  • An engineering workstation, with every project and password on it, that is also used for email.
  • USB sticks and laptops carried between sites.
  • Unauthorised or undocumented changes to PLC logic, including changes made through controllers left reachable from the internet, the route used in the Iran-linked PLC attacks of 2026.

First steps on a running plant

First steps on a running plant
First steps on a running plant

Start with the inventory: you cannot protect what you do not know is there. Draw the network as it actually is, including the forgotten modem and the switch in the MCC room. If IP addressing is new to you, subnetting for PLC and OT networks covers what you need to read the drawing. Then group assets into zones, close any direct path from the business network or the internet, and put remote access through a single gateway with individual accounts. Back up every PLC program and device configuration, and store the backups where ransomware on the business network cannot reach them.

What a PLC engineer can do today

Security is not only a network team's job. In the controller itself you can use CPU access protection and passwords, disable services and ports you do not use, validate values that arrive from HMIs and other systems before acting on them, and keep project files under change control. The Top 20 Secure PLC Coding Practices are a good checklist for this.

Plan for recovery, not only prevention

No plant can guarantee an attacker never gets in, so the question that matters on the day is how fast production can be restored safely. Keep offline copies of every PLC, HMI and drive project, with the software versions needed to open them. Record which systems must come back first and who decides when it is safe to restart. Then rehearse: restore a PLC program from backup onto a spare controller, rebuild an HMI PC from its image, and time both. Teams that have practised recover in hours; teams that have not can take weeks.

Free OT cybersecurity courses

Start with ICS Security Foundations if you are new to the subject: DCS, PLC and SCADA from a security view, the Purdue model, defence in depth and the seven 62443 foundational requirements one at a time. Then OT and ICS Cybersecurity with ISA/IEC 62443 goes into zones and conduits, security levels, risk assessment, vulnerability management and incident response. OT Security Assessment teaches how to test a plant without stopping it. The IIoT and security path and the OT security courses page list the rest. For the other no-cost options, from CISA's ICS courses to ISA's overview guide, see free IEC 62443 training.

Every course is free in full, with credited video lessons, notes, practice tasks and one final assessment; no card is needed. The optional EDWartens Certificate of Completion is a small one-off fee, US$8.99 for the beginner course and a little more for the intermediate ones. It can be checked at edwartens.com/verification. It is not an ISA/IEC 62443 or vendor certification and is not accredited. Create a free account to start.

Take the free course

Questions

What is the difference between OT and IT security?

IT security usually puts confidentiality first. OT security puts safety and availability first, because the systems control physical processes, run for decades, often cannot be patched or rebooted on demand, and use protocols that were designed without authentication.

What is ISA/IEC 62443?

A series of standards for the security of industrial automation and control systems, developed by the ISA99 committee and published by the IEC. It covers the asset owner's security programme, system-level risk assessment and requirements, and secure product development and component requirements.

What are zones and conduits?

A zone is a group of assets with the same security requirements, such as one production line's controllers. A conduit is the defined communication path between zones, where traffic is controlled and monitored.

Is the Purdue model still relevant?

Yes, as a reference for where systems sit and where boundaries belong, even though cloud connections and IIoT devices now cross the levels. Most OT security designs still start by placing assets on it and putting a DMZ between the enterprise and control networks.

Can I run a network scan on a live plant?

Not without permission, a plan and an agreed window. Some older controllers and devices can fault when scanned. Passive monitoring of existing traffic is the safe place to start.

Sources

Written by the EDWartens engineering team for general education. Product names are trademarks of their owners; mentioning them does not imply endorsement. Prices and terms of other providers were checked on the date shown and can change.