OTRISK
Resources

The useful kind of resources.

Written in the same voice as the product: mechanism over marketing, clause numbers over adjectives. We publish when a piece is worth an engineer’s time. Below: what exists today, and what’s in the works.

Available now

Sample artifact
A generated IRA
An Initial Risk Assessment generated from demo data: executive summary, plotted risk matrix, ranked register, scales and method. Request the sample IRA report →
Interactive
The regulation map
Law → duty → standard → proof, click-to-trace, facts dated and sourced. Open the map →
Nederlandstalig
Cyberbeveiligingswet, uitgelegd
Registratieplicht, zorgplicht, meldplicht en bestuursverantwoordelijkheid. In het Nederlands, met bronnen. Lees de gids →

In the works

IEC 62443-3-2 readiness self-check
A scored questionnaire with an emailed report: where your current assessment stands against the seven steps.
IN PROGRESS
How to write a CRS
The mandatory IEC 62443-3-2 work product, with a worked example.
PLANNED
Certification vs conformance
What "IEC 62443 certified" can and cannot mean, and what auditors actually accept.
PLANNED
IEC 62443 vs ISO 27001 for OT
Where each carries the load, and how the evidence overlaps.
PLANNED
OTRISK vs spreadsheets
The honest comparison, including where the spreadsheet wins.
PLANNED

No content mill

Two pieces a month once we publish, each answering a question a real assessment raised. Nothing generated to fill a calendar. Want one of the pieces above prioritised? Tell us at info@otrisk.io.

OT compliance glossary

SL-T, zones & conduits, CRS, SuC, ZCR, ML: the vocabulary, defined once, properly.

IACS

Industrial automation and control system: the PLCs, SCADA, DCS and networks that run a physical process. The systems IEC 62443 exists to secure.

System under Consideration (SuC)

The scope of an assessment: the installation, its assets and its connections, fixed before any risk work starts (ZCR 1).

Zone

A group of assets with shared security requirements, such as a process cell or a control-room network. Each zone gets its own risk assessment and its own target level.

Conduit

A communication path between zones. Conduits carry requirements of their own, because that is where traffic crosses a trust boundary.

ZCR

Zone and conduit requirement: the seven steps of IEC 62443-3-2, from defining the SuC (ZCR 1) to approval by the asset owner (ZCR 7).

IRA

Initial risk assessment (ZCR 2): the first system-wide risk picture, used to decide where detailed assessment is worth the effort.

DRA

Detailed risk assessment (ZCR 5): the per-zone assessment of threats, likelihood and consequence that produces the SL-T.

CRS

Cybersecurity Requirements Specification (ZCR 6): the mandatory end product of IEC 62443-3-2. Integrators build against it and auditors ask for it.

Security level (SL 1-4)

A four-step scale of attacker strength. SL 1 covers honest mistakes, SL 2 commodity attacks, SL 3 targeted attacks with IACS-specific skills, SL 4 attackers with extended resources.

SL-T, SL-C, SL-A

Target, capability, achieved. SL-T is what a zone must reach, the output of the risk assessment. SL-C is what a product can deliver when configured right. SL-A is what the deployment verifiably reaches.

Foundational requirement (FR)

One of the seven groups every technical requirement in 3-3 and 4-2 hangs off: authentication, use control, system integrity, confidentiality, restricted data flow, timely response to events, resource availability.

Requirement enhancement (RE)

An addition that raises a base requirement to a higher security level. The same requirement grows stricter as the SL climbs.

Maturity level (ML)

A 1 to 4 score for how well a process is run: initial, managed, defined, improving. Used to score IEC 62443-4-1 and 2-4 assessments.

Asset owner

The organisation that operates the IACS and owns the risk, always. Outsourcing the work never outsources the accountability.

System integrator

Designs, builds and maintains the automation solution. IEC 62443-2-4 covers the provider's way of working, 3-3 the system it delivers.

Product supplier

Builds the components: PLCs, RTUs, network gear, software. IEC 62443-4-1 covers the development process, 4-2 the component itself.

CSMS

Cyber security management system: the asset owner's standing OT security program per IEC 62443-2-1. Policies, roles, risk process, supplier management, continuous improvement.

DMZ

A buffer zone between networks that trust each other differently, typically between the enterprise network and the control network. Traffic terminates there instead of crossing directly.

Defense in depth

Layered countermeasures, so one failing layer does not expose the process. The design principle behind zones and conduits.

Compensating countermeasure

A control around a device that cannot meet a requirement itself. A firewall in front of a legacy PLC is the classic example.

Essential function

A function whose loss endangers view, control or safety of the process. Security measures may never break one: locking out an operator during an incident is a design error.

Zorgplicht

The duty of care in the Dutch Cyberbeveiligingswet, in force from 15 August 2026, with risk analysis as its explicit foundation.

Component vs system certification

A component certificate (4-2) says a product can enforce a security level. A system certificate (3-3) covers the integrated whole. Neither replaces the asset owner's own risk assessment.

Tolerable risk

The risk level the asset owner is prepared to accept. ZCR 4 compares assessed risk against it; whatever exceeds it goes into detailed assessment.

From standard to signed-off.

Bring one installation in mind. In thirty minutes we show you which parts of OTRISK fit your situation and how the way of working looks. You leave with concrete next steps and pricing.

Skip reading, see it live →