Zones and conduits
Zones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.
Updated This page as Markdown
In short
In IEC 62443 a zone is a grouping of logical or physical assets that share common security requirements, and a conduit is the grouping of communication channels that connects two or more zones and has its own requirements. IEC 62443-3-2 describes how to partition a system under consideration into zones and conduits, assign each a target security level and treat the risk. In practice it is the structured version of network segmentation and the basis of every OT security architecture.
What are zones and conduits?
Zones and conduits are the model IEC 62443 uses to structure an industrial system for security. A zone is a grouping of logical or physical assets that share common security requirements: a production cell, the safety system, the engineering workstations, the DMZ between office and plant. A conduit is a logical grouping of communication channels that connects two or more zones and has its own security requirements: the OPC UA link from the MES to the line controllers, or the remote maintenance VPN.
The point is to think in groups with the same protection need and the controlled paths between them, not in individual devices. Every conduit is a place where you can inspect, filter, authenticate and log; every zone boundary is a place where an attacker has to work.
Where is it defined?
The terms are defined in IEC 62443-1-1 and the method in IEC 62443-3-2 (2020), Security risk assessment for system design. Its zone and conduit requirements (ZCR) form a workflow: identify the system under consideration (ZCR 1), perform an initial risk assessment (ZCR 2), partition into zones and conduits (ZCR 3), compare the risk with the tolerable risk (ZCR 4), run a detailed risk assessment where needed (ZCR 5), document the requirements, assumptions and constraints (ZCR 6) and get the asset owner’s approval (ZCR 7). ZCR 3 contains concrete partitioning rules: separate business and control system assets, put safety-related assets in their own zones, and separate temporarily connected devices, wireless devices and devices reached through external networks.
Each zone and conduit receives a target security level, which then selects the technical requirements from IEC 62443-3-3. The Purdue reference model (levels 0 to 5) is the usual starting template for zones but is not part of the standard.
What it means in practice
A zone and conduit diagram is the most useful document in an OT security project, and it is often missing. What we see in plants and on machines:
- The flat network. PLCs, HMIs, engineering stations, printers and the office share one broadcast domain. Any phishing success in the office is a direct path to the controllers. The first conduit to build is the one between office and production, with a firewall and a DMZ for everything both sides need.
- Remote maintenance bypasses everything. Vendor VPN boxes and cellular routers on individual machines create conduits that nobody drew. They are the most common finding in our OT tests.
- Safety systems in the same zone as control. 62443-3-2 says to separate them for a reason: a compromised controller must not be able to silence the safety PLC.
- Conduits without controls. A VLAN is a line on a diagram until the router between the VLANs filters something. A conduit needs an enforcement point, protocol awareness (Modbus function codes, S7 write operations) and logging.
For machine builders the model applies inside the machine: the machine is a zone (or several), and the interfaces to the plant (OPC UA server, remote service, USB) are conduits whose security the machine documentation should describe. Zyberum designs zone models with operators and verifies them with penetration tests from the office network and from inside zones, without stopping production.
Common misunderstandings
Zones are not VLANs: a VLAN is one way to implement a zone boundary, but a zone is defined by protection needs, not by addressing. And segmentation does not replace hardening of the devices inside: it reduces how many attackers reach them, not what happens when one does.
FAQ
Frequently asked questions
Is a zone the same as a VLAN or a subnet?
No. A zone is defined by the protection needs of the assets in it, a VLAN or subnet is one way to implement its boundary. A zone can span several networks, and a network can contain several zones if the boundary is enforced in another way, for example by host firewalls. Start with the risk, then choose the network design.
How many zones does a typical plant have?
Usually between five and a few dozen: an enterprise zone, an industrial DMZ, one or more supervisory zones, one zone per production cell or line, separate zones for safety systems, and dedicated zones for remote maintenance and wireless. Too few zones give an attacker free movement, too many become unmanageable; the risk assessment sets the number.
Can I introduce zones without stopping production?
Mostly yes. Inventory and traffic analysis are passive. New firewalls and VLANs are introduced in maintenance windows, usually one conduit at a time, first in monitoring mode and then enforcing. Our OT penetration tests verify the result from the office network and from inside the zones without interrupting the process.
Sources
Related pages
- GlossaryIEC 62443IEC 62443 is the standard series for the cybersecurity of industrial automation and control systems (IACS). Parts, the three roles, and how it is used in practice.
- GlossarySecurity Level (IEC 62443)Security Levels in IEC 62443 rate the attacker a zone or component must withstand, from SL 1 to SL 4. Target, capability and achieved levels (SL-T, SL-C, SL-A).
- GlossaryOT SecurityOT security protects the operational technology that controls physical processes: PLCs, SCADA, HMIs, drives. How it differs from IT security and what typically fails.
- GlossarySCADASCADA systems supervise and control distributed processes such as power grids, water networks and pipelines. Architecture, protocols and the security issues they bring.
- InsightsOT Penetration Testing Without Downtime: How It Is DoneHow to test a plant without stopping production: passive analysis, test benches and twins, what belongs in a maintenance window, what is never done on a live plant.
- ServicesKeep production running when IT and OT converge.Security assessments, pentests and IEC 62443 consulting for PLC, SCADA and DCS. Protect production and critical infrastructure against cyberattacks.
