OTRISK
Product · Risk assessment

The IEC 62443-3-2 risk assessment, run as a workflow.

Open a risk assessment in OTRISK and the tabs are the standard: ZCR 1 System under Consideration through ZCR 7 approval, exactly as IEC 62443-3-2 defines them. Your own risk matrix, your own network diagrams, your own tolerable risk. Methodology debates end, because the methodology is on screen.

Assessments Pumping station Zuid dedicated instance · EU hosting
Pumping station Zuid In progress
IEC 62443-3-2 · Matrix v4 (frozen) · Line B, drinking water production
Due 30 Sep 2026 · 62 days remaining
ZCR 1 · System Under Consideration ZCR 2 · Initial risk assessment ZCR 3 · Partition the SUC ZCR 4 · Risk comparison ZCR 5 · Detailed assessment ZCR 6 · Documentation ZCR 7 · Approval
Z1 · Process control network
SL-T 2
Accepted
Z2 · Safety instrumented system
SL-T 3
Pending review
C1 · Plant DMZ conduit
SL-T 2
Accepted
Reviewed · m.dekker · 2026-07-21 09:32 · ZCR 3 partitioning accepted

Illustrative recreation of the workspace · demo data, no customer content.

The seven ZCRs, on screen

IEC 62443-3-2 structures the risk assessment as seven requirements, ZCR 1 through ZCR 7, each with a defined output. OTRISK runs them as gated tabs: one person submits, another accepts, and the next step opens. This is what each step asks, and what the screen gives you.

ZCR 1

Identify the System under Consideration

Scope decides everything downstream, so it comes first. Describe the system and its environment, import the network diagram, and build the asset inventory with criticality per asset: safety, operational and business impact, lifecycle and patch status, access points. The deterministic diagram parser prefills what it can read with certainty and flags the rest. No AI guesswork on your plant data.

Field note: the Polish CHP breach ran on connections nobody drew →

ZCR 1 · Asset inventory source: PFD-B-rev12.pdf
PLC · Line 4 dosing S7-1500 parsed
HMI · Control room WinCC parsed
Historian OSIsoft PI parsed
Remote access gateway unknown flagged
Deterministic parse · nothing guessed · 3 of 41 assets flagged for a human
ZCR 2 · Initial risk assessment Awaiting review
Worst case on the matrix
Nearly impossibleDaily
R-01 Ransomware via vendor remote access · dosing PLCs Operations U
R-04 Unauthorised setpoint change from business network Safety & Health VH
Generate IRA report (draft) Confirm ZCR 2 submitted · j.vandenberg
ZCR 2

Initial risk assessment

Score unmitigated risks on your organisation's own matrix and see them plotted on the heat map, worst case highlighted. This is the moment management sees the whole picture of one installation on one page. Generate the Initial Risk Assessment document directly from this step.

ZCR 3

Partition the SuC into zones and conduits

Draw zones and conduits on the diagram, with the standard's own checks built in: separate business and IACS assets, separate safety systems, account for temporary connections, wireless and external networks. The partitioning isn't a drawing exercise; it's the structure the rest of the assessment hangs on.

Field note: five zone-partitioning mistakes we keep seeing →

ZCR 3 · Zone & conduit partitioning 41 assets · every asset in exactly one zone · 0 orphans
Enterprise network
outside the SuC
C1
plant DMZ
Z1 · Process control network SL-T 2
17 assets · PLC, HMI, historian, switches
C3
SIS gateway
Z2 · Safety instrumented system SL-T 3
own zone · safety separated
Vendor remote access
temporary connection · accounted for
C2
temporary
Z3 · Packaging line SL-T 1
9 assets · separate risk profile
business / IACS separated safety systems own zone temporary connections wireless external networks
ZCR 4

Compare risk to tolerable risk

The standard's gate question: does the initial risk exceed what you tolerate? OTRISK computes the suggestion from your own scores and your own tolerance line. If the answer is no, you're done and documented. If yes, you proceed with exactly the zones that need it.

Initial risk vs. tolerable risk tolerance line · matrix v4
BELOW documented, assessment complete
Z3 · Packaging line M ≤ tolerable
ABOVE proceeds to ZCR 5, this zone only
Z1 · Process control network U > tolerable
computed from your scores and your tolerance line · a suggestion, decided by you
ZCR 5

Detailed risk assessment

Per zone and conduit: threats from a curated library built on the ENISA taxonomy, vulnerabilities referenced to CWE and NIST, impact per consequence category, likelihood before and after existing countermeasures, and a security-level target (SL-T) derived from residual risk. Every number carries its rationale.

T-03 Ransomware via vendor remote access Z1 · Process control network
ENISA · Nefarious activity / Malware CWE-287 · Improper authentication
Likelihood · unmitigated
Incidental
After existing countermeasures
Seldom
Impact per category
S&H 3 · Ops 5 · Fin 4
Residual risk
H · above tolerable
SL-T derived from residual risk SL-T 3 rationale recorded per number
ZCR 6 · Cybersecurity Requirements Specification Completeness · passed
Every asset assigned to a zone or conduit 41 of 41
Zone and conduit characteristics recorded 5 of 5
Threat scenarios documented 12
SL-T set per zone and conduit 5 of 5
Generate CRS (draft) assembled from ZCR 1-5 · nothing written twice
ZCR 6

Document: the Cybersecurity Requirements Specification

The CRS is the work product the standard requires and integrators build against. OTRISK assembles it from what you already did: SuC context, zone and conduit characteristics, threat scenarios, SL-T per zone. A completeness check gates the step: no asset left unassigned, no zone without a target.

ZCR 7

Approval

The asset owner approves or rejects with reasons, on the record: who, when, why. Rejection reopens exactly the steps that need rework. From here on, the assessment is a living document with a signature, not a PDF in a drawer.

ZCR 7 · Asset owner approval
Approved
Approved · T. Bakker, asset owner
2026-07-24 14:05 · "partitioning and targets match operational reality"
2026-07-22 16:40 · j.vandenberg · submitted for approval
2026-07-11 10:12 · t.bakker · rejected · "safety PLCs must be their own zone (ZCR 3.4)"
rejection reopens only the affected steps · log permanent

Your matrix, not ours

Risk managers rightly distrust tools that impose a risk model. In OTRISK your organisation's matrix is configured once: impact levels, likelihood scale, consequence categories such as Safety & Health, Environment, Operations, Financial and Product Quality, tolerable-risk bands and the mapping to security-level targets. Every assessment freezes its own copy, so results stay comparable across years even when the matrix evolves.

Risk matrix · 5 × 7 v4 · frozen per assessment
5 · Disastrous
M
H
VH
VH
U
U
U
4 · Serious
L
M
H
VH
VH
U
U
3 · Significant
L
L
M
H
VH
VH
U
2 · Limited
N
L
L
M
H
H
VH
1 · Small
N
N
L
L
M
M
H
Nearly impossible
Exceptional
Seldom
Incidental
Yearly
Monthly
Daily
Safety & Health
Operations
Environment
Financial
Legal & Regulatory
Reputation
Product Quality
risk classes N · L · M · H · VH · U · the worst-scoring category drives the class
ZCR 5 · Detailed risk assessment
Pending review
submitted · j.vandenberg · 2026-07-18 16:04
Accept ZCR 5 Reject with reason
j.vandenberg cannot review this submission · reviewer must differ from submitter · enforced

Nobody accepts their own submission

Every ZCR step is submitted by one person and accepted by another; the platform enforces it. Every change of state carries a name, a timestamp and a comment, permanently. When the auditor asks "who reviewed the zone partitioning, and when", the answer is a click, not an archaeology project.

The artifacts

The workflow ends in two documents, and neither is written by hand. Both are assembled from the live assessment, so what they say is what the workspace holds.

INITIAL RISK ASSESSMENT · GENERATED REPORT
Pumping station Zuid
IEC 62443-3-2 · matrix v4 · generated 2026-07-21 09:32
Executive summary
Initial risk · worst case per zone
Ranked risk register
R-01
U
R-04
VH
R-07
H
OTRISK · regenerated from live dataPage 1 of 14

Initial Risk Assessment (IRA)

Executive summary, the plotted risk matrix, the ranked risk register, scales and method, all generated from live data.

CYBERSECURITY REQUIREMENTS SPECIFICATION
Pumping station Zuid
IEC 62443-3-2 · CRS · version 1.0 · 24 Jul 2026
Approved · T. Bakker, asset owner · 24 Jul 2026 · on the record
Zones, conduits and targets
Z1 · Process control networkSL-T 2
Z2 · Safety instrumented systemSL-T 3
Z3 · Packaging lineSL-T 1
C1 · Plant DMZ conduitSL-T 2
completeness · every asset assigned · characteristics provided · SL-T per zone & conduit
Approval status on the coverPage 1 of 9

Cybersecurity Requirements Specification (CRS)

The mandatory IEC 62443-3-2 work product, with the approval status on the cover.

Both regenerate on demand. Your assessment ages; the documents don't. Request the sample IRA report →

Works alongside your monitoring platform. Claroty, Nozomi or Dragos tell you what's on the network and what it's doing. They do not perform or document a risk assessment; that's not their job. OTRISK is the layer where observations become assessed, owned, reviewed risk, and where the proof is produced. No sensors, no hardware, no six-figure prerequisite: your first assessment starts from a network drawing and a workshop.

Questions your team will ask

How long does a IEC 62443-3-2 risk assessment take in OTRISK?

Scope-dependent. The workflow is built so the initial risk assessment of a first System under Consideration is measured in weeks, not months, and re-assessments become review passes because nothing is rebuilt.

Do we need to have IEC 62443 expertise in-house?

The workflow encodes the method, which lowers the bar considerably, but risk decisions remain yours. If you want guidance, our OT security experts co-run the first assessment and train your team until it runs alone. If you work with an OT security consultancy, they can work inside your environment with their own accounts and roles. Onboarding & enablement →

Will our auditor or certification body accept the output?

The IRA and CRS follow the structure the standard prescribes, and every verdict in them is traceable to a person and a date. Auditors can be given their own access instead of an export.

What do you need from us to start?

A network drawing (any common format), a list of the people involved, and one system you care about. That's the first workshop.

Where does our data live?

On a dedicated application instance and database per client, hosted in the EU, behind role-based access and MFA. Details on the Security & architecture page.

See your own system in it.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.