Risk assessment (3-2)
Asset inventory, zones and conduits, and target security levels for each zone.
IEC 62443
The standard for industrial cybersecurity has parts for operators, integrators and manufacturers. We help you find the parts that apply to you, implement them without stopping production, and test whether they hold.
In short
IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems. It defines requirements for plant operators (62443-2-1, 3-2, 3-3), system integrators (2-4, 3-3) and component manufacturers (4-1 for secure development, 4-2 for component requirements), and uses zones, conduits and security levels SL 1 to SL 4. Zyberum provides risk assessments, gap analyses, component security tests and secure development processes according to IEC 62443.
For operators
Asset inventory, zones and conduits, and target security levels for each zone.
Network architecture, firewalls and remote access designed so an office incident stays in the office.
Roles, patching, backup, incident handling and supplier requirements for the plant.
For manufacturers
Penetration tests of devices, firmware and interfaces against the component requirements and your target security level.
Threat modelling, secure coding, security testing and vulnerability handling in your development process.
Secure developmentIEC 62443-4-1 and 4-2 cover much of what the Cyber Resilience Act demands from industrial products.
CRA complianceHow we work
Industrial systems run for decades and must not fail. We use passive analysis on live systems, agree every active test with your operations team, and move attacks that could cause trouble into the lab or a maintenance window.
You get measures ordered by their effect on safety and availability, not by chapter number.
FAQ
Operators start with 62443-2-1 and 3-2. System integrators work with 2-4 and 3-3. Manufacturers of components need 4-1 for their development process and 4-2 for the product requirements.
Security levels SL 1 to SL 4 describe the strength of attacker a zone or component must resist, from casual misuse (SL 1) to attackers with extensive resources and specific knowledge (SL 4).
Yes, by accredited certification bodies under schemes such as IECEE or ISASecure. We prepare you: gap analysis, fixes and a test against the requirements before the certification lab sees the product.
Get started
We clarify which parts of the standard apply to you and what the sensible first step is.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy