Lumiar
Home/ Services/ Security architecture and IEC 62443
SERVICE

Security architecture and IEC 62443

A security architecture that can be built and operated, not just drawn. We divide the facility into zones and conduits according to IEC 62443 and set requirements proportionate to the risk.

Typical situations

If one of these sounds familiar, it is worth a conversation.

You are building new or upgrading the OT/control system, and want security in from the start.
The network has grown organically for years, or inorganically, and no one has the full picture any more.
IT and OT are being connected more tightly, and you need clear boundaries.
A client, management or authority requires documented security and architecture according to IEC 62443 or regulations such as NIS2, CRA and CER.

Delivery and method

We map the current architecture together with your people, divide the systems into zones and conduits and set security level requirements based on the risk assessment. The result is a target picture with a realistic path to it, in steps that fit turnarounds and ordinary projects. Some set SL requirements too low, others too high and unrealistic. The art is finding the right, balanced level for the system as a whole, in the context it operates in. We make sure the whole chain holds together: the level actually needed, what can be delivered, how the requirements are set towards suppliers, how deliveries are followed up, and how the level is maintained in operations.

01Zone model with conduits and SL requirements
02Target architecture and gaps against the current solution
03Prioritised action plan in feasible steps
04Basis for setting requirements towards vendors
05Development and adaptation of methods, processes, management systems, tools and checklists
METHODOLOGICAL BASIS
IEC 62443-3-2 (zones, risk)
IEC 62443-3-3 (system requirements)
The Purdue model

Scope and format

DURATION
2 to 6 weeks
depending on the size of the facility and the quality of the documentation.
WAY OF WORKING
Workshops and document review
on site or remote. A site visit is recommended for the first review.
PREREQUISITES
Documentation and key personnel
network documentation at whatever level you have, and people who know the systems.

Frequently asked questions

Does the whole facility have to be done at once?
No. Many start with one sub-facility or production line, and reuse the model from there.
What if the documentation does not match reality?
That is common. We map what is actually there, and the deviations become part of the findings.
Can you set requirements towards our vendors?
Yes. The zone model and SL requirements are written so they can go into contracts and requirement specifications.

Want to know how your facility should be zoned?

Book an introductory call
ANDRE SERVICES
Risk assessment and barrier analysisAudit and compliance assessmentTraining and competence