Written in the same voice as the product: mechanism over marketing, clause numbers over adjectives. We publish when a piece is worth an engineer’s time. Below: what exists today, and what’s in the works.
Two pieces a month once we publish, each answering a question a real assessment raised. Nothing generated to fill a calendar. Want one of the pieces above prioritised? Tell us at info@otrisk.io.
SL-T, zones & conduits, CRS, SuC, ZCR, ML: the vocabulary, defined once, properly.
Industrial automation and control system: the PLCs, SCADA, DCS and networks that run a physical process. The systems IEC 62443 exists to secure.
The scope of an assessment: the installation, its assets and its connections, fixed before any risk work starts (ZCR 1).
A group of assets with shared security requirements, such as a process cell or a control-room network. Each zone gets its own risk assessment and its own target level.
A communication path between zones. Conduits carry requirements of their own, because that is where traffic crosses a trust boundary.
Zone and conduit requirement: the seven steps of IEC 62443-3-2, from defining the SuC (ZCR 1) to approval by the asset owner (ZCR 7).
Initial risk assessment (ZCR 2): the first system-wide risk picture, used to decide where detailed assessment is worth the effort.
Detailed risk assessment (ZCR 5): the per-zone assessment of threats, likelihood and consequence that produces the SL-T.
Cybersecurity Requirements Specification (ZCR 6): the mandatory end product of IEC 62443-3-2. Integrators build against it and auditors ask for it.
A four-step scale of attacker strength. SL 1 covers honest mistakes, SL 2 commodity attacks, SL 3 targeted attacks with IACS-specific skills, SL 4 attackers with extended resources.
Target, capability, achieved. SL-T is what a zone must reach, the output of the risk assessment. SL-C is what a product can deliver when configured right. SL-A is what the deployment verifiably reaches.
One of the seven groups every technical requirement in 3-3 and 4-2 hangs off: authentication, use control, system integrity, confidentiality, restricted data flow, timely response to events, resource availability.
An addition that raises a base requirement to a higher security level. The same requirement grows stricter as the SL climbs.
A 1 to 4 score for how well a process is run: initial, managed, defined, improving. Used to score IEC 62443-4-1 and 2-4 assessments.
The organisation that operates the IACS and owns the risk, always. Outsourcing the work never outsources the accountability.
Designs, builds and maintains the automation solution. IEC 62443-2-4 covers the provider's way of working, 3-3 the system it delivers.
Builds the components: PLCs, RTUs, network gear, software. IEC 62443-4-1 covers the development process, 4-2 the component itself.
Cyber security management system: the asset owner's standing OT security program per IEC 62443-2-1. Policies, roles, risk process, supplier management, continuous improvement.
A buffer zone between networks that trust each other differently, typically between the enterprise network and the control network. Traffic terminates there instead of crossing directly.
Layered countermeasures, so one failing layer does not expose the process. The design principle behind zones and conduits.
A control around a device that cannot meet a requirement itself. A firewall in front of a legacy PLC is the classic example.
A function whose loss endangers view, control or safety of the process. Security measures may never break one: locking out an operator during an incident is a design error.
The duty of care in the Dutch Cyberbeveiligingswet, in force from 15 August 2026, with risk analysis as its explicit foundation.
A component certificate (4-2) says a product can enforce a security level. A system certificate (3-3) covers the integrated whole. Neither replaces the asset owner's own risk assessment.
The risk level the asset owner is prepared to accept. ZCR 4 compares assessed risk against it; whatever exceeds it goes into detailed assessment.
Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.