# Zones and conduits

> In IEC 62443 a zone is a grouping of logical or physical assets that share common security requirements, and a conduit is the grouping of communication channels that connects two or more zones and has its own requirements. IEC 62443-3-2 describes how to partition a system under consideration into zones and conduits, assign each a target security level and treat the risk. In practice it is the structured version of network segmentation and the basis of every OT security architecture.

Zones and conduits are the IEC 62443 model for segmenting industrial systems: groups of assets with common security requirements and the controlled links between them.

Source: https://zyberum.com/glossary/zones-and-conduits · Updated: 2026-10-07

## What are zones and conduits?

Zones and conduits are the model IEC 62443 uses to structure an industrial system for security. A **zone** is a grouping of logical or physical assets that share common security requirements: a production cell, the safety system, the engineering workstations, the DMZ between office and plant. A **conduit** is a logical grouping of communication channels that connects two or more zones and has its own security requirements: the OPC UA link from the MES to the line controllers, or the remote maintenance VPN.

The point is to think in groups with the same protection need and the controlled paths between them, not in individual devices. Every conduit is a place where you can inspect, filter, authenticate and log; every zone boundary is a place where an attacker has to work.

## Where is it defined?

The terms are defined in IEC 62443-1-1 and the method in IEC 62443-3-2 (2020), Security risk assessment for system design. Its zone and conduit requirements (ZCR) form a workflow: identify the system under consideration (ZCR 1), perform an initial risk assessment (ZCR 2), partition into zones and conduits (ZCR 3), compare the risk with the tolerable risk (ZCR 4), run a detailed risk assessment where needed (ZCR 5), document the requirements, assumptions and constraints (ZCR 6) and get the asset owner's approval (ZCR 7). ZCR 3 contains concrete partitioning rules: separate business and control system assets, put safety-related assets in their own zones, and separate temporarily connected devices, wireless devices and devices reached through external networks.

Each zone and conduit receives a target security level, which then selects the technical requirements from IEC 62443-3-3. The Purdue reference model (levels 0 to 5) is the usual starting template for zones but is not part of the standard.

## What it means in practice

A zone and conduit diagram is the most useful document in an OT security project, and it is often missing. What we see in plants and on machines:

- **The flat network.** PLCs, HMIs, engineering stations, printers and the office share one broadcast domain. Any phishing success in the office is a direct path to the controllers. The first conduit to build is the one between office and production, with a firewall and a DMZ for everything both sides need.
- **Remote maintenance bypasses everything.** Vendor VPN boxes and cellular routers on individual machines create conduits that nobody drew. They are the most common finding in our OT tests.
- **Safety systems in the same zone as control.** 62443-3-2 says to separate them for a reason: a compromised controller must not be able to silence the safety PLC.
- **Conduits without controls.** A VLAN is a line on a diagram until the router between the VLANs filters something. A conduit needs an enforcement point, protocol awareness (Modbus function codes, S7 write operations) and logging.

For machine builders the model applies inside the machine: the machine is a zone (or several), and the interfaces to the plant (OPC UA server, remote service, USB) are conduits whose security the machine documentation should describe. Zyberum designs zone models with operators and verifies them with penetration tests from the office network and from inside zones, without stopping production.

## Common misunderstandings

Zones are not VLANs: a VLAN is one way to implement a zone boundary, but a zone is defined by protection needs, not by addressing. And segmentation does not replace hardening of the devices inside: it reduces how many attackers reach them, not what happens when one does.

## FAQ

**Is a zone the same as a VLAN or a subnet?**

No. A zone is defined by the protection needs of the assets in it, a VLAN or subnet is one way to implement its boundary. A zone can span several networks, and a network can contain several zones if the boundary is enforced in another way, for example by host firewalls. Start with the risk, then choose the network design.

**How many zones does a typical plant have?**

Usually between five and a few dozen: an enterprise zone, an industrial DMZ, one or more supervisory zones, one zone per production cell or line, separate zones for safety systems, and dedicated zones for remote maintenance and wireless. Too few zones give an attacker free movement, too many become unmanageable; the risk assessment sets the number.

**Can I introduce zones without stopping production?**

Mostly yes. Inventory and traffic analysis are passive. New firewalls and VLANs are introduced in maintenance windows, usually one conduit at a time, first in monitoring mode and then enforcing. Our OT penetration tests verify the result from the office network and from inside the zones without interrupting the process.

## Sources

- [IEC 62443-3-2:2020 Security risk assessment for system design](https://webstore.iec.ch/en/publication/30727)
- [IEC 62443-3-3:2013 System security requirements and security levels](https://webstore.iec.ch/en/publication/7033)
- [ISA: The ISA/IEC 62443 Series of Standards](https://www.isa.org/standards-and-publications/isa-standards/isa-iec-62443-series-of-standards)

## Related

- [IEC 62443](https://zyberum.com/glossary/iec-62443)
- [Security Level (IEC 62443)](https://zyberum.com/glossary/security-level-iec-62443)
- [OT Security](https://zyberum.com/glossary/ot-security)
- [SCADA](https://zyberum.com/glossary/scada)
- [OT Penetration Testing Without Downtime: How It Is Done](https://zyberum.com/insights/ot-pentest-without-downtime)
- [Keep production running when IT and OT converge.](https://zyberum.com/industrial-security)

---
Zyberum GmbH. Canonical page: https://zyberum.com/glossary/zones-and-conduits
