Siam Thanat Hack Co., Ltd.

IEC 62443 Industrial Cybersecurity and Non-Disruptive OT Pentest Guide

An in-depth technical guide to ISA/IEC 62443 standards, Purdue Model architecture, and safe, non-disruptive penetration testing methodologies for industrial automation and critical infrastructure (OT / ICS / SCADA).

Executive Summary and Mandate Overview
Target Audience Manufacturing facilities, utilities, power grids, energy, petrochemicals, and critical infrastructure operators (OT / ICS / SCADA)
Mandatory Frequency Annual risk assessment cycle, major system modifications, and scheduled plant turnaround shutdown windows
Required Scope Purdue Model Levels 0-5, Level 3.5 Industrial DMZ, Zones & Conduits, SCADA, HMIs, PLCs, Historians, and industrial networks
Non-Compliance Risk Unplanned production shutdown (plant trip), catastrophic machinery damage, environmental incidents, and physical personnel safety hazards

The ISA/IEC 62443 Framework and Purdue Enterprise Architecture

Overview of the four-tier IACS security standard and the Purdue reference model for industrial cybersecurity.

Infographic explaining: The ISA/IEC 62443 Framework and Purdue Enterprise Architecture
Visual guide: The ISA/IEC 62443 Framework and Purdue Enterprise Architecture
  • Divided into 4 key tiers: 1-General (terminology and concepts), 2-Policies (security management system), 3-System (system requirements and zones), and 4-Component (hardware and firmware requirements).
  • Purdue Enterprise Reference Architecture (PERA): Stratifies industrial operations from Level 0 (physical processes), Level 1 (PLCs/RTUs), Level 2 (HMIs), Level 3 (SCADA/operations), up to Level 4-5 (enterprise IT).
  • Industrial DMZ (Level 3.5): Mandatory architectural requirement isolating enterprise corporate IT networks from operational industrial control networks.
  • Establishes 4 distinct Security Levels (SL 1 casual/unintentional, SL 2 simple intentional, SL 3 sophisticated intentional, and SL 4 high-resource/nation-state) calibrated against adversary capabilities.

System Partitioning: Zones and Conduits under IEC 62443-3-2

Logical asset segmentation and communication channel protection using industrial deep packet inspection firewalls.

Infographic explaining: System Partitioning: Zones and Conduits under IEC 62443-3-2
Visual guide: System Partitioning: Zones and Conduits under IEC 62443-3-2
  • Security Zones (mandatory): Group cyber assets sharing identical security objectives to contain blast radius and prevent lateral movement.
  • Conduits (mandatory): Dedicated, monitored communication pathways connecting security zones governed by strict access control lists.
  • Deep Packet Inspection (DPI): Industrial firewalls decode function codes across Modbus TCP, DNP3, IEC 60870-5-104, OPC UA, and PROFINET payloads to block malicious commands.
  • Strictly forbids direct routing between corporate Level 4 enterprise networks and Level 0-2 industrial controllers without traversing the Level 3.5 IDMZ.

Safe, Non-Disruptive OT / SCADA Penetration Testing Methodologies

Safety-first rules of engagement for assessing industrial control systems without compromising plant operations or physical safety.

Infographic explaining: Safe, Non-Disruptive OT / SCADA Penetration Testing Methodologies
Visual guide: Safe, Non-Disruptive OT / SCADA Penetration Testing Methodologies
  • Safety-First Cardinal Rule (strictly prohibited): Never execute aggressive port scans or automated denial-of-service/fuzzing payloads against active PLCs, RTUs, or Safety Instrumented Systems (SIS) during live production to prevent controller crashes and plant trips.
  • Recommended baseline: Prioritize passive network monitoring via SPAN/mirror ports and network TAPs for non-intrusive asset discovery and industrial protocol baseline analysis.
  • Active penetration testing scope: Focus active testing on the Level 3.5 Industrial DMZ, auditing jump hosts, testing firewall egress, and assessing historian database vulnerabilities.
  • Invasive controller testing: Confine invasive protocol fuzzing, controller exploitation, and firmware extraction to hardware test benches, digital twins, or scheduled turnaround shutdown periods.
  • Testing teams must hold specialized industrial certifications (e.g. GICSP, GRID, ISA/IEC 62443 Cybersecurity Specialist) and adhere to facility safety induction protocols.

Requirements and Testing Scope Matrix

Summary of the referenced clauses, the testing scope they cover, and the expected evaluation cycle.

Reference Mandate Title Scope Required Testing Cycle
IEC 62443-3-2 Risk Assessment and Partitioning into Zones and Conduits Inventory IACS/SCADA assets, conduct detailed risk assessments, and establish logical zones and monitored conduits Initial design phase and reviewed during plant upgrades or major operational modifications
IEC 62443-3-3 System Security Requirements and Security Levels (SL 1-4) Verify Security Level Target (SL-T) requirements, access enforcement, industrial protocol inspection (DPI), and IDMZ 3.5 controls Periodic configuration audits and annual boundary penetration tests
IEC 62443-2-4 / 4-1 Service Provider Integration and Secure Development Lifecycle Assess vendor remote maintenance security, third-party contractor access, and controller firmware integrity Pre-procurement review and commissioning verification
Non-Disruptive OT Testing Policy Safety-First Non-Disruptive OT Penetration Testing Methodology Deploy passive network capture, validate Level 3.5 IDMZ boundaries, and prohibit aggressive active scanning against live PLCs and safety systems Annual perimeter testing with invasive testing restricted to staging labs or plant turnaround shutdown periods

Compliance Readiness Self-Assessment

Select items your organization has completed to evaluate your readiness score.

0%

Official source documents

Explore the ISA/IEC 62443 industrial automation and control systems security standards series on the ISA website.

Go to the official source