Skip to content
IACS RadarIndustrial Cyber Exposure & Intelligence

Knowledge base

Knowledge base

Practical explanations, checklists and implementation tips on IEC 62443, OT architecture and vulnerability management — written for engineers, asset owners and security officers.

13

Articles

Governanceadvanced

The Dutch Cybersecurity Act and IEC 62443: from statutory duty of care to OT practice

What the Dutch Cybersecurity Act (NIS2) means for OT environments since 15 August 2026, and which IEC 62443 measures help to demonstrate the statutory duty of care.

9 min16 August 2026
Governanceexpert

From vulnerability to demonstrable risk treatment

A practical step-by-step plan to get from a published vulnerability to a demonstrably treated risk.

8 min20 June 2026
Vulnerability Managementbasic

KEV, CVE, CVSS and EPSS explained

Four commonly used abbreviations in vulnerability management, what they do and do not say, and how they complement each other.

7 min18 June 2026
IEC 62443basic

The seven Foundational Requirements

An overview of the seven fundamental security requirements that form the basis of IEC 62443-3-3 and -4-2.

8 min15 June 2026
Vulnerability Managementadvanced

Patch management in an OT environment

Why patching works differently in OT than in IT, and how to still get a grip on patch status and mitigations.

7 min12 June 2026
IEC 62443basic

Zones and conduits explained

The basic principles of network segmentation according to IEC 62443, with an example from an electricity substation.

7 min10 June 2026
OT Architectureadvanced

Securing remote access to substations

Practical measures for secure remote access by vendors and maintenance personnel to substations.

7 min8 June 2026
Secure Engineeringadvanced

Securing engineering workstations

Why engineering workstations are an attractive target and which measures reduce the risk.

6 min5 June 2026
IEC 62443basic

What is IEC 62443?

An introduction to the main international series of standards for cybersecurity of industrial control systems, and why it is relevant to the energy sector.

6 min2 June 2026
Secure Engineeringadvanced

Security during FAT and SAT

How to actually test security requirements during the Factory and Site Acceptance Test, instead of only after delivery.

6 min1 June 2026
Secure Engineeringbasic

Building an OT asset inventory

Why a current asset inventory is the basis of every OT security programme, and how to get started in practice.

7 min30 May 2026
IEC 62443advanced

What does Security Level Target mean?

How Security Levels work in IEC 62443, the difference between SL-T, SL-C and SL-A, and how to determine an SL-T.

6 min25 May 2026
IEC 62443advanced

Difference between IEC 62443-2-1 and IEC 62443-2-4

Two parts that are often confused: the security programme of the asset owner versus the requirements for service providers and integrators.

5 min18 May 2026