Knowledge base
Knowledge base
Practical explanations, checklists and implementation tips on IEC 62443, OT architecture and vulnerability management — written for engineers, asset owners and security officers.
13
Articles
The Dutch Cybersecurity Act and IEC 62443: from statutory duty of care to OT practice
What the Dutch Cybersecurity Act (NIS2) means for OT environments since 15 August 2026, and which IEC 62443 measures help to demonstrate the statutory duty of care.
From vulnerability to demonstrable risk treatment
A practical step-by-step plan to get from a published vulnerability to a demonstrably treated risk.
KEV, CVE, CVSS and EPSS explained
Four commonly used abbreviations in vulnerability management, what they do and do not say, and how they complement each other.
The seven Foundational Requirements
An overview of the seven fundamental security requirements that form the basis of IEC 62443-3-3 and -4-2.
Patch management in an OT environment
Why patching works differently in OT than in IT, and how to still get a grip on patch status and mitigations.
Zones and conduits explained
The basic principles of network segmentation according to IEC 62443, with an example from an electricity substation.
Securing remote access to substations
Practical measures for secure remote access by vendors and maintenance personnel to substations.
Securing engineering workstations
Why engineering workstations are an attractive target and which measures reduce the risk.
What is IEC 62443?
An introduction to the main international series of standards for cybersecurity of industrial control systems, and why it is relevant to the energy sector.
Security during FAT and SAT
How to actually test security requirements during the Factory and Site Acceptance Test, instead of only after delivery.
Building an OT asset inventory
Why a current asset inventory is the basis of every OT security programme, and how to get started in practice.
What does Security Level Target mean?
How Security Levels work in IEC 62443, the difference between SL-T, SL-C and SL-A, and how to determine an SL-T.
Difference between IEC 62443-2-1 and IEC 62443-2-4
Two parts that are often confused: the security programme of the asset owner versus the requirements for service providers and integrators.