Back

Explore every episode of the podcast IEC 62443 — Industrial Cybersecurity

Dive into the complete episode list for IEC 62443 — Industrial Cybersecurity. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–15 of 15

TitlePub. DateDuration
IEC 62443: SDLC-Document Security Guidelines22 août 202600:03:45

Industrial control systems power critical infrastructure worldwide—water treatment, power grids, manufacturing. Yet they face unprecedented cyber threats from nation-state actors and opportunistic attackers. The IEC 62443 standard establishes comprehensive security principles for industrial automation and control systems.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • IEC 62443 is the international standard for industrial automation and control systems security.
  • The standard mandates that security be integrated from the start, not bolted on afterward.
  • Each S-D-L-C phase requires specific security activities: threat modeling in design, secure coding in development, security testing before release, and continuous monitoring after deployment.
  • Not all documents need identical protection levels.
  • IEC 62443 requires systematic risk assessment at each lifecycle stage, rating threats by likelihood and impact.
  • IEC 62443 Part 4-one defines mandatory secure coding practices: peer code review before release, static analysis and vulnerability scanning, patch tracking, and protection of development tools.

Reference: IEC 62443-4-2:2019 Clause 6.3.3 specifies technical security measures for components, including documented SDLC requirements

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: Definitions Security Safety22 août 202600:05:30

Today we zoom into one of the most misunderstood boundaries in industrial safety: the line between keeping systems safe and keeping them secure. They are not the same thing. A safety system protects you from a machine malfunctioning all by itself. A security system protects you from someone trying to break in and make it malfunction on purpose.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • Today we are inside IEC 62443, the industrial cybersecurity standard.
  • Here is the story the standard tells.
  • So let us start with the word security itself.
  • Now the thing that attacks it.
  • So IEC 62443 draws a scope.
  • Now climb this ladder.

Reference: IEC 62443 is a multi-part standard for industrial automation and control systems security, maintained by IEC TC65. The full title is 'Security for Industrial Automation and Control

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Security Requirements Specification22 août 202600:03:13

IEC 62443 defines security for industrial control systems. Part 4 dash one focuses on secure development practices. Building security in, not bolting it on. You'll learn how to craft security requirements from conception. We walk through design requirements that lock down systems. Then verify every claim.

Part of the Critical Systems Analysis functional-safety series on IEC 62443.

In this episode:

  • IEC 62443 dash four dash one establishes a framework for secure development of industrial control system components.
  • IEC 62443 defines four security levels based on threat sophistication.
  • The standard follows a logical flow: identify assets, assess threats, specify requirements, design solutions, implement, then verify.
  • Security requirements fall into four domains: access control, system hardening, secure communications, and lifecycle support.
  • Start with a threat model and define mitigation requirements for each identified threat.
  • Secure design applies principles: least privilege, defense-in-depth, fail securely.

Reference: IEC 62443 standard reference: Published by ISA (International Society of Automation) with IEC (International Electrotechnical Commission). Core parts: IEC 62443-1-1 (overview), IEC

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: Security Verification22 août 202600:04:52

In industrial cybersecurity, designing a secure system isn't enough—you must rigorously verify it actually works. IEC 62443 defines how to systematically test and validate security controls across industrial automation and control systems.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • We're diving into the verification requirements of IEC 62443, the international standard for industrial automation and control systems cybersecurity.
  • The V-model shows how verification mirrors your system development.
  • A typical IEC 62443 verification workflow starts with threat modeling to identify what you're protecting against.
  • IEC 62443 verification operates at four testing levels, each adding rigor.
  • Verification activities fall into four categories based on their automation and scope.
  • IEC 62443 verification focuses on specific security control areas: cryptographic implementations, authentication and access controls, network segmentation, and patch management procedures.

Reference: Security Levels (SL 1-4) defined in IEC 62443-1-1 sections 5.2.1 through 5.2.4; SL is the target security capability, verified through documented evidence.

More in this series: The V-Model and Safety Lifecycle

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: Management Plan22 août 202600:03:25

Industrial control systems face unprecedented cybersecurity threats. The IEC 62443 standard addresses this challenge with a comprehensive governance framework where the Management Plan forms the critical foundation of any security program.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • Welcome to this deep dive into IEC 62443 Management Plan requirements, the foundational governance framework for industrial cybersecurity.
  • A Security Management Plan is the documented program through which an organization establishes its cybersecurity vision, objectives, and governance model.
  • The Management Plan encompasses several critical components.
  • Effective governance requires a clear hierarchy of responsibility.
  • Security must be integrated throughout the system lifecycle, not applied after design is complete.
  • Risk assessment and treatment form the heart of the Management Plan.

Reference: IEC 62443-2-1:2019 Part 2 defines Security Management in industrial automation and control systems

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Module Implementation22 août 202600:03:00

Industrial systems face unprecedented cyber threats, and traditional development approaches leave them dangerously exposed. IEC 62443 mandates a Secure Development Lifecycle—embedding security into every stage of software creation, from initial requirements through deployment and ongoing operations.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • This module builds security into every stage of software development.
  • Secure Development Lifecycle, or S-D-L, is the systematic approach embedded in IEC 62443 .
  • An effective Secure Development Lifecycle flows through five key phases.
  • IEC 62443 mandates that security requirements be documented early and remain traceable.
  • Threat modeling identifies attack vectors before code is written.
  • Security testing is mandatory throughout development, not a final step.

Reference: IEC 62443-4-1 applies to product development for components used in industrial automation and control systems. Four Security Levels (SL1-SL4) are defined, with escalating requireme

More in this series:

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: Motivation Cyber Security22 août 202600:03:23

Industrial systems—power grids, water treatment, manufacturing—are increasingly connected. Yet many were designed before cybersecurity was a concern. A single breach doesn't just lose data; it can halt production, endanger lives, or compromise national infrastructure. I.E.C. 62443 is the international standard designed to bridge this gap.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • Welcome to this module on industrial cybersecurity fundamentals.
  • Industrial systems operate the infrastructure we depend on every day.
  • Industrial systems face mounting threats.
  • Without a consistent framework, organizations approach cybersecurity inconsistently.
  • The standard rests on foundational principles.

Reference: IEC 62443-3-3 defines security levels SL1 through SL4, with level 4 designed to protect against sophisticated, well-resourced attackers with insider knowledge

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Security Risk Assessment and Threat Modeling22 août 202600:03:20

IEC 62443 is the international standard for industrial automation and control systems cybersecurity. In this episode, we focus on the security development lifecycle and threat modeling components—critical practices for building secure industrial systems from the ground up.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • Introducing IEC 62443: the international standard governing cybersecurity for industrial automation and control systems worldwide.
  • The Security Development Lifecycle integrates security into every phase of software and system development.
  • Risk assessment is the systematic process of identifying assets, threats, and vulnerabilities in your industrial control environment.
  • Threat modeling uses structured techniques to anticipate how adversaries might compromise your systems.
  • IEC 62443 defines comprehensive security controls spanning defense in depth, secure architecture, access controls, and cryptography.
  • The V-Model mirrors functional safety testing: requirements drive design, design drives implementation, and testing mirrors each phase.

Reference: Security Levels (SL-1 to SL-4) defined in IEC 62443-1-1:2010: SL-1 = protection against inadvertent disclosure or casual misuse; SL-2 = protection against disclosure and simple att

More in this series:

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Security Defect and Update Management22 août 202600:04:47

Industrial cybersecurity isn't just about walls and gates—it's about what happens when flaws are found. IEC 62443 demands a rigorous, lifecycle approach to defects and updates: from the moment a vulnerability is discovered through secure disclosure, coordinated testing, controlled deployment, and thorough documentation.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • We're exploring IEC 62443 's framework for security defects and updates—two pillars that hold industrial systems secure even as threats evolve.
  • A defect in production is a crisis: it's already affecting thousands of devices, and fixes take weeks to deploy across industrial networks.
  • IEC 62443 builds defect and patch management into the entire software development lifecycle.
  • Defects come from code review, testing, threat modeling, and external reports.
  • Patches and updates must be tested, documented, and delivered with clear release notes.
  • What makes a patch 'security' versus 'feature'? IEC 62443 distinguishes them by impact.

Reference: IEC 62443 Part 3 (System Security Levels and Requirements Specification) governs the overall security program and SDLC requirements across SL0–SL3.

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Security Tools22 août 202600:04:22

Industrial control systems face mounting cyber threats demanding security built into products from day one. The IEC standard sixty-two four four three defines how to construct secure automation and control products throughout their entire development lifecycle. Part 4-one specifically prescribes a structured S D L C—a Software Development Life Cycle—that embeds security tooling at each phase.

Part of the Critical Systems Analysis functional-safety series on IEC 62443.

In this episode:

  • Industrial automation systems require rigorous security from design through deployment.
  • The S D L C-Security framework integrates security into every stage of product development, not as an afterthought but as a core requirement.
  • IEC 62443 prescribes four sequential phases.
  • Security tool integration spans four main categories.
  • IEC 62443 defines four Security Levels, each demanding more rigorous tool deployment.
  • Effective security validation confirms that tools actually reduce risk in the final product.

Reference: IEC 62443-4-1 Clause 7.6 mandates secure configuration management and build procedures; security tools are the mechanisms that implement these requirements.

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: Security Level22 août 202600:04:37

Industrial systems demand protection from cyber threats that can impact safety, production, and assets. The IEC 62443 standard defines a structured framework for evaluating and implementing cybersecurity across manufacturing and critical infrastructure.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • The IEC 62443 standard is the international framework for industrial cybersecurity.
  • At the foundation of IEC 62443 is the concept of Security Level.
  • The framework defines four progressive Security Levels that address different threat scenarios.
  • IEC 62443 encompasses several key areas beyond just Security Levels.
  • Assessing an organization's Security Level involves two key dimensions: systematic measurement of current capabilities and capability maturity levels.
  • Each Security Level has distinct characteristics reflecting different threat scenarios and organizational needs.

Reference: IEC 62443-3-3:2013 defines four Security Levels: SL 1 (protection against casual or coincidental violation), SL 2 (intentional violation using simple means with low attack potentia

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Module Testing22 août 202600:03:43

Industrial Control Systems protect critical infrastructure globally, but without secure software development practices, they remain vulnerable to sophisticated cyber threats and attacks. IEC 62443 outlines mandatory lifecycle controls—including rigorous module testing—that bridge cybersecurity and functional safety requirements.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • This episode covers IEC 62443 S D L C module testing requirements.
  • Module testing is unit-level verification performed during development.
  • IEC 62443 identifies three core testing objectives: validate security requirement implementation, identify vulnerabilities before integration, and establish traceability between code and requirements.
  • Two complementary strategies drive effective module testing.
  • The standard emphasizes testing for category vulnerability classes: buffer overflows, injection attacks, authentication bypasses, cryptographic weaknesses, and state management flaws.
  • Module testing bridges cybersecurity and functional safety in industrial systems.

Reference: IEC 62443-3-3 Section 4.3 defines the SDLC phase for module security testing. Security Levels one through four apply escalating rigor to test scope, depth, and documentation.

More in this series: The V-Model and Safety Lifecycle

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Software Design22 août 202600:03:53

Building secure industrial control systems requires more than hoping developers write safe code. IEC 62443, the international standard for industrial cybersecurity, mandates that security become part of every step in software development, from the initial requirements through design, implementation, testing, and deployment.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • IEC 62443 is the international standard for cybersecurity of industrial automation and control systems.
  • The secure software design lifecycle, or S-D-L-C, is a systematic approach that integrates security from initial concept through deployment.
  • IEC 62443 Part 4-one identifies six critical phases that must incorporate security.
  • Threat modeling is fundamental to the S-D-L-C.
  • When security is integrated from the start, threats are caught early when fixes are cheapest.
  • IEC 62443 requires multiple testing methods to validate security.

Reference: IEC 62443-3-1 defines the Secure Software Development Lifecycle requirements for industrial control systems; design phase is a mandatory stage in the S-D-L-C process.

More in this series:

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: SDLC-Software Architecture Design22 août 202600:04:13

In industrial automation, architecture decisions made during design directly determine your security posture. IEC 62443, the International Electrotechnical Commission's cybersecurity standard, mandates that secure software development begins before a single line of code is written.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • Secure software development starts before code is written.
  • IEC 62443 is a comprehensive security framework developed by the International Electrotechnical Commission.
  • The secure development lifecycle in IEC 62443 spans five essential phases.
  • Software architecture under IEC 62443 is built on five core principles: separation of concerns, defense in depth, fail-safe defaults, regular reviews, and minimal privilege.
  • IEC 62443 defines four security levels, each with increasing requirements and threat assumptions.
  • Threat modeling feeds directly into architecture decisions.

Reference: IEC 62443-4-1 defines SDLC requirements and gates at each phase; architecture risk analysis is mandatory before design approval.

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

IEC 62443: Legal Aspects22 août 202600:03:43

When industrial control systems face cyber threats, organizations can't simply hope for the best. The IEC 62443 standard defines the legal and organizational requirements for securing critical infrastructure. This functional-safety micro-lecture explores what compliance really means: from board-level accountability to engineering lifecycle decisions.

Part of the Critical Systems Analysis functional-safety series on Industrial Cybersecurity.

In this episode:

  • IEC 62443 is the international standard for Industrial Automation and Control Systems security.
  • The standard defines security as a managed discipline, not just a technical feature.
  • Legal compliance under this standard requires organizations to define who bears responsibility and how.
  • Accountability flows from the top down through distinct organizational levels.
  • The standard mandates that security cannot be added after design is complete.
  • Proof of compliance depends on comprehensive documentation.

Reference: IEC 62443 part 1 establishes scope and overview for industrial automation and control systems security governance

More in this series: IEC 62443 — Industrial Cybersecurity

Explore more from Critical Systems Analysis.

All shows on Apple Podcasts: AI & ML Safety | Fault Tree Analysis | FS Assessment | Safety Analysis | IEC 61508 | IEC 62443 | ISO 10218 | ISO 12100 | ISO 13849 | ISO 26262 | ISO/PAS 8800 | ISO 26262-11 | V-Model | UL 4600.

© My Podcast Data · Independent project · Data from Apple & Spotify