The IEC 62443 risk analysis of an industrial site, step by step
Risk analysis is the heart of industrial cybersecurity: it turns a network map into decisions - what to protect first, against what, and how far. IEC 62443 provides the reference method for industrial systems. Here is how it unfolds in practice.
Step 1 - Start from reality: the map
Everything starts from the site's real map: equipment inventory, layered architecture, observed flows. An analysis based on a theoretical diagram scores a site that does not exist; an analysis based on real traffic scores yours.
Step 2 - Partition into zones and conduits
The standard organises the site into zones - groups of equipment sharing the same security requirements (a production line, SCADA, the industrial DMZ...) - linked by conduits, the controlled communication channels between zones. This partition, validated with your teams, becomes the structure of everything that follows: analysis proceeds zone by zone, not device by device.
Step 3 - Identify scenarios: functional analysis, then impact analysis
For each zone, a workshop with the people who know the process - production, maintenance, automation - starts with the functional analysis: what the zone does, what it depends on, what is expected from it. Then comes the impact analysis: what happens if this SCADA is unavailable? If this recipe parameter is modified? If this remote-maintenance access is hijacked? The method draws on the hazard studies industry already practises: the vocabulary is familiar, the exercise moves fast.
Step 4 - Score: inherent, then residual risk
Each scenario is scored - likelihood and severity - against your own corporate risk matrix, not an imposed scale. The inherent risk is scored first (before measures), then the residual risk once countermeasures are decided. The gap between the two is the value of the action plan; what remains above the tolerable threshold is the decision that goes up to management.
Step 5 - Set target security levels
The standard assigns each zone a target security level (SL-T) and derives measurable technical requirements. That is what makes the analysis auditable: you can verify, requirement by requirement, where each zone stands.
Step 6 - The report, and the yearly review
The final deliverable documents everything: scope, map, zones and conduits, scenarios, scores, countermeasures, rationale. It can be presented as-is to management, an auditor, an insurer or a principal. And since the site lives on, the analysis gets reviewed - yearly at minimum, which is what NIS2 will require. When the analysis lives in a tool rather than a frozen document, that review becomes an update, not a new project.
With whom, and how
This is exactly the workflow tooled by UMX Risk Manager, fed by the UMX Explorer map - and the workflow our experts co-produce with your teams when you prefer to be guided: we bring the method and the tool, your teams bring the process knowledge, and the site walks away with a living analysis and its autonomy.