OTRISK
Product

The method is the workspace.

Open an assessment in OTRISK and the tabs are the standard: risk-assessment steps, requirement sets, maturity levels, exactly as the IEC 62443 series structures them. Your own risk matrix, your own network diagrams, your own targets. Methodology debates end, because the methodology is on screen.

Assessments Pumping station Zuid dedicated instance · EU hosting
Pumping station Zuid In progress
IEC 62443-3-2 · Matrix v4 (frozen) · Line B, drinking water production
Two-person review Due 30 Sep 2026 · 62 days remaining
ZCRs completed
2 of 7
zone & conduit requirements confirmed
In progress
1
step with recorded work
Not started
4
steps still open
Progress
34%
Overview ZCR 1 · System Under Consideration ZCR 2 · Initial risk assessment ZCR 3 · Partition the SUC ZCR 4 · Risk comparison ZCR 5 · Detailed assessment ZCR 6 · Documentation ZCR 7 · Approval
Zones & conduits 41 assets · 0 orphans
Z1 · Process control network SL-T 2
Z2 · Safety instrumented system SL-T 3
Z3 · Packaging line SL-T 1
C1 · Plant DMZ conduit SL-T 2
C2 · Vendor remote access
Z1 · Process control network Accepted reviewed · m.dekker · 21 Jul 2026
Assets
17 · PLC, HMI, historian, switches
Worst-case unmitigated risk
Class U · above tolerable
Conduits
C1 plant DMZ · C2 vendor remote
Separation checks 3.2–3.6
Recorded · 5 of 5
business/IACS · safety · temporary connections · wireless · external networks

Illustrative recreation of the workspace · demo data, no customer content.

One engine, whatever the standard

Every law and every customer audit ends in the same demand: show that your risks are managed. A standard defines what "show" looks like, and OTRISK runs the standard as a workflow. The loop never changes: each requirement gets an owner, a deadline, evidence and an independent verdict. Whichever framework you're held to, the proof comes out the same shape.

Set a target first, and only the requirements your target demands enter the assessment. Nobody works through 400 clauses because a checklist said so.

IEC 62443-2-1
Your security program
Policies, roles, incident handling, supplier management: the asset owner's program, checked requirement by requirement.
IEC 62443-2-4
Your service providers
Integrators and maintenance partners evidence their capabilities in your own environment, in third-party mode, with their verdicts and yours kept separate.
IEC 62443-3-2
The OT risk assessment
Scope, zones and conduits, security-level targets, and the two generated deliverables: IRA and CRS. Walked step by step below.
IEC 62443-3-3
System requirements
Assess the installed system against its security-level target; requirements above the target stay out of scope.
IEC 62443-4-1
Secure development
Product makers evidence their development lifecycle, vulnerability handling and patch delivery included.
IEC 62443-4-2
Component requirements
Component capabilities per security level: what customers quote in RFPs and certifications test against.
ISO/IEC 27001
The office domain
The IT management system, run beside the OT work: same evidence store, same review discipline, one system for both worlds.
NIST SP 800-82
OT security programs
The OT guidance many corporate frameworks mandate, run as a requirement assessment like the rest.
Your next standard
Same loop, new clauses

New frameworks join as requirement sets: same owners, same review, same permanent log. Your team doesn't relearn a thing.

References, not reprints: the standards' own text stays in your licensed copies.

The risk assessment, step by step

IEC 62443-3-2 structures the OT risk assessment as seven gated steps, and the workspace walks them in order, each one submitted by one person and accepted by another. If a law brought you here, this is the piece it asks for first: the demonstrable, per-installation risk analysis that decides what "appropriate measures" means for you. In our own words:

1
Scope. Define the system and its environment; import the network drawing; the asset inventory builds itself, deterministically. What the parser can't read with certainty, it flags for a human.
2
Initial risk. Score unmitigated risk on your own matrix; the worst case surfaces on one page, and the IRA generates from this step.
3
Partition. Group assets into zones, name the conduits between them, with the separation checks built in.
4
Gate. Compare against your tolerance line. Below it: done and documented. Above it: proceed, only where needed.
5
Detail. Threats and vulnerabilities per zone, impact per consequence category, and a security-level target derived from residual risk. Every number carries its rationale.
6
Document. The requirements specification assembles itself from the work already done; a completeness check gates the step: no asset unassigned, no zone without a target.
7
Approve. The asset owner signs, on the record: who, when, why. Rejection reopens exactly the steps that need rework.
ZCR 2 · Initial cyber security risk assessment Awaiting review
Matrix Unmitigated Risks 12 Likelihood 7
Worst case on the matrix
Nearly impossibleDaily
R-01 Ransomware via vendor remote access · dosing PLCs Operations U
R-04 Unauthorised setpoint change from business network Safety & Health VH
R-07 Historian data loss · batch records Financial H
Generate IRA report (draft) Confirm ZCR 2 submitted · j.vandenberg · awaiting a second pair of eyes

Deep dive: the full IEC 62443-3-2 risk assessment workflow →

Your matrix, not ours

Risk managers rightly distrust tools that impose a risk model. In OTRISK your organisation's matrix is configured once: impact levels, likelihood scale, consequence categories such as Safety & Health, Environment, Operations, Financial and Product Quality, tolerable-risk bands and the mapping to security-level targets. Every assessment freezes its own copy, so results stay comparable across years even when the matrix evolves.

Why it matters for compliance: "appropriate" is measured against your own tolerance. When the auditor asks why a zone's target is what it is, the answer traces to a matrix your management approved, not a vendor default.

Risk matrix · 5 × 7 v4 · frozen per assessment
5 · Disastrous
M
H
VH
VH
U
U
U
4 · Serious
L
M
H
VH
VH
U
U
3 · Significant
L
L
M
H
VH
VH
U
2 · Limited
N
L
L
M
H
H
VH
1 · Small
N
N
L
L
M
M
H
Nearly impossible
Exceptional
Seldom
Incidental
Yearly
Monthly
Daily
Safety & Health
Operations
Environment
Financial
Legal & Regulatory
Reputation
Product Quality
risk classes N · L · M · H · VH · U; the worst-scoring category drives the class
ZCR 3 · Zone & conduit partitioning
Accepted
2026-07-21 09:32 · m.dekker · accepted · "partitioning matches drawing rev12"
2026-07-18 16:04 · j.vandenberg · submitted for review
2026-07-18 15:40 · j.vandenberg · edited · "added C2 vendor remote access"
2026-07-11 10:12 · t.bakker · rejected · "safety PLCs must be their own zone (ZCR 3.4)"
process log · permanent

Nobody accepts their own submission

Every submission, whether a piece of evidence, an assessment step or a document, is accepted by someone other than its author; the platform enforces it. Every change of state carries a name, a timestamp and a comment, permanently. When the auditor asks "who reviewed the zone partitioning, and when", the answer is a click, not an archaeology project.

Why it matters for compliance: the laws put accountability on management. A permanent record of who decided and who verified is what "accountable" looks like on paper.

The artifacts

Compliance ends as paper: the document you hand the regulator, the customer or the auditor. These two are generated, not written. In plain terms they say "we know our risks" and "here is what our system must meet".

INITIAL RISK ASSESSMENT · GENERATED REPORT
Pumping station Zuid
IEC 62443-3-2 · matrix v4 · generated 2026-07-21 09:32
Executive summary
Initial risk · worst case per zone
Ranked risk register
R-01
U
R-04
VH
R-07
H
OTRISK · regenerated from live dataPage 1 of 14

Initial Risk Assessment (IRA)

The risk picture your management signs: executive summary, the plotted matrix, the ranked register, scales and method, all generated from live data.

CYBERSECURITY REQUIREMENTS SPECIFICATION
Pumping station Zuid
IEC 62443-3-2 · CRS · approved · 24 Jul 2026
Approved · T. Bakker, asset owner · 24 Jul 2026 · on the record
Zones, conduits and targets
Z1 · Process control networkSL-T 2
Z2 · Safety instrumented systemSL-T 3
Z3 · Packaging lineSL-T 1
C1 · Plant DMZ conduitSL-T 2
completeness · every asset assigned · characteristics provided · SL-T per zone & conduit
Approval status on the coverPage 1 of 9

Cybersecurity Requirements Specification (CRS)

The spec your integrators build against: the work product IEC 62443-3-2 requires, with the approval status on the cover.

Both regenerate on demand, and requirement assessments export their own report the same way. Your assessment ages; the documents don't. Request the sample IRA report →

Works alongside your monitoring platform. Claroty, Nozomi or Dragos tell you what's on the network and what it's doing. They do not perform or document a risk assessment; that's not their job. OTRISK is the layer where observations become assessed, owned, reviewed risk, and where the proof is produced. No sensors, no hardware, no six-figure prerequisite: your first assessment starts from a network drawing and a workshop.

Questions your team will ask

How long does a IEC 62443-3-2 risk assessment take in OTRISK?

Scope-dependent. The workflow is built so the initial risk assessment of a first System under Consideration is measured in weeks, not months, and re-assessments become review passes because nothing is rebuilt.

Do we need to have IEC 62443 expertise in-house?

The workflow encodes the method, which lowers the bar considerably, but risk decisions remain yours. If you want guidance, our OT security experts co-run the first assessment and train your team until it runs alone; and if you work with an OT security consultancy, they can deliver inside your environment with their own roles. Onboarding & enablement →

Will our auditor or certification body accept the output?

The IRA and CRS follow the structure the standard prescribes, and every verdict in them is traceable to a person and a date. Auditors can be given their own access instead of an export.

What do you need from us to start?

A network drawing (any common format), a list of the people involved, and one system you care about. That's the first workshop.

Where does our data live?

On a dedicated application instance and database per client, hosted in the EU, behind role-based access and MFA. Prefer evidence files not to move at all? Register a reference to your SharePoint, Tresorit or DMS instead of uploading; OTRISK keeps the pointer and the verdict. Details on the Security & architecture page.

See your own system in it.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.