Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryOT

Zones and conduits

Zones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.

Updated This page as Markdown

In short

In IEC 62443 a zone is a grouping of logical or physical assets that share common security requirements, and a conduit is the grouping of communication channels that connects two or more zones and has its own requirements. IEC 62443-3-2 describes how to partition a system under consideration into zones and conduits, assign each a target security level and treat the risk. In practice it is the structured version of network segmentation and the basis of every OT security architecture.

What are zones and conduits?

Zones and conduits are the model IEC 62443 uses to structure an industrial system for security. A zone is a grouping of logical or physical assets that share common security requirements: a production cell, the safety system, the engineering workstations, the DMZ between office and plant. A conduit is a logical grouping of communication channels that connects two or more zones and has its own security requirements: the OPC UA link from the MES to the line controllers, or the remote maintenance VPN.

The point is to think in groups with the same protection need and the controlled paths between them, not in individual devices. Every conduit is a place where you can inspect, filter, authenticate and log; every zone boundary is a place where an attacker has to work.

Where is it defined?

The terms are defined in IEC 62443-1-1 and the method in IEC 62443-3-2 (2020), Security risk assessment for system design. Its zone and conduit requirements (ZCR) form a workflow: identify the system under consideration (ZCR 1), perform an initial risk assessment (ZCR 2), partition into zones and conduits (ZCR 3), compare the risk with the tolerable risk (ZCR 4), run a detailed risk assessment where needed (ZCR 5), document the requirements, assumptions and constraints (ZCR 6) and get the asset owner’s approval (ZCR 7). ZCR 3 contains concrete partitioning rules: separate business and control system assets, put safety-related assets in their own zones, and separate temporarily connected devices, wireless devices and devices reached through external networks.

Each zone and conduit receives a target security level, which then selects the technical requirements from IEC 62443-3-3. The Purdue reference model (levels 0 to 5) is the usual starting template for zones but is not part of the standard.

What it means in practice

A zone and conduit diagram is the most useful document in an OT security project, and it is often missing. What we see in plants and on machines:

  • The flat network. PLCs, HMIs, engineering stations, printers and the office share one broadcast domain. Any phishing success in the office is a direct path to the controllers. The first conduit to build is the one between office and production, with a firewall and a DMZ for everything both sides need.
  • Remote maintenance bypasses everything. Vendor VPN boxes and cellular routers on individual machines create conduits that nobody drew. They are the most common finding in our OT tests.
  • Safety systems in the same zone as control. 62443-3-2 says to separate them for a reason: a compromised controller must not be able to silence the safety PLC.
  • Conduits without controls. A VLAN is a line on a diagram until the router between the VLANs filters something. A conduit needs an enforcement point, protocol awareness (Modbus function codes, S7 write operations) and logging.

For machine builders the model applies inside the machine: the machine is a zone (or several), and the interfaces to the plant (OPC UA server, remote service, USB) are conduits whose security the machine documentation should describe. Zyberum designs zone models with operators and verifies them with penetration tests from the office network and from inside zones, without stopping production.

Common misunderstandings

Zones are not VLANs: a VLAN is one way to implement a zone boundary, but a zone is defined by protection needs, not by addressing. And segmentation does not replace hardening of the devices inside: it reduces how many attackers reach them, not what happens when one does.

FAQ

Frequently asked questions

Is a zone the same as a VLAN or a subnet?

No. A zone is defined by the protection needs of the assets in it, a VLAN or subnet is one way to implement its boundary. A zone can span several networks, and a network can contain several zones if the boundary is enforced in another way, for example by host firewalls. Start with the risk, then choose the network design.

How many zones does a typical plant have?

Usually between five and a few dozen: an enterprise zone, an industrial DMZ, one or more supervisory zones, one zone per production cell or line, separate zones for safety systems, and dedicated zones for remote maintenance and wireless. Too few zones give an attacker free movement, too many become unmanageable; the risk assessment sets the number.

Can I introduce zones without stopping production?

Mostly yes. Inventory and traffic analysis are passive. New firewalls and VLANs are introduced in maintenance windows, usually one conduit at a time, first in monitoring mode and then enforcing. Our OT penetration tests verify the result from the office network and from inside the zones without interrupting the process.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab