International

IEC 62443

Asset owners, integrators and product suppliers of industrial automation and control systems, in every sector.

The international series for control-system security: vocabulary, the asset owner's security programme (2-1), service provider requirements (2-4), risk assessment and zone-and-conduit design (3-2), system requirements by security level (3-3), and product development and component requirements (4-1, 4-2).

Security levels 1 to 4 describe the adversary a zone must resist. Seven foundational requirements group the technical controls.

How we use it. Our design vocabulary. Risk assessments produce a zone and conduit model with target levels; architecture and network work is specified and verified against 3-2 and 3-3.

Read more: IEC 62443 explained for asset owners

NIST SP 800-82 Rev 3

Anyone building or assessing an OT security programme. Published by the US National Institute of Standards and Technology in 2023 as the Guide to Operational Technology Security.

An end-to-end guide: how OT differs from IT, threats and vulnerabilities specific to control systems, risk management, recommended architectures, and an overlay that tailors the SP 800-53 control catalogue to OT.

How we use it. The reference we use for programme structure and for control selection where a client is not bound to a sector framework. Paired with IEC 62443 for the system-level design.

Read more: The Purdue model and OT network segmentation, without the religion

NIST Cybersecurity Framework

Organisations of any size that want a common language for cyber risk with the board. One of the frameworks accepted under Australia's CIRMP rules.

A framework of functions, categories and outcomes, from governing and identifying through protecting, detecting, responding and recovering. Version 2.0 added governance as a function of its own.

How we use it. A programme framework we map OT controls under when a client has adopted it enterprise-wide, so the plant is reported in the same language as the rest of the business.

MITRE ATT&CK for ICS

Defenders and assessors who want to reason from observed adversary behaviour against control systems.

A knowledge base of tactics and techniques used against industrial control systems, drawn from real intrusions. Twelve tactics, ending in the three unique to OT: inhibit response function, impair process control, and impact.

How we use it. The backbone of our threat assessment: which techniques are realistic against your plant, ranked by consequence, and the controls that break the most paths. Also the reference for monitoring use cases.

Read more: How a threat assessment uses MITRE ATT&CK for ICS

ISO/IEC 27001

Organisations running a certified information security management system. Accepted under the CIRMP rules in Australia; named for critical systems in India's CEA power sector regulations (a deferred provision).

The management-system standard: risk assessment, a statement of applicability, controls from Annex A, and continual improvement, audited by a certification body.

How we use it. Where a client's ISMS scope includes the plant, we make sure the OT risks, assets and controls are actually inside it rather than assumed, and we supply the control-system evidence the auditor asks for.

Australia

SOCI Act and the CIRMP rules

Responsible entities for critical infrastructure assets in eleven sectors, including energy, water and sewerage, transport, and food and grocery.

The Security of Critical Infrastructure Act 2018, as amended in 2021, 2022 and 2024: an asset register, mandatory cyber incident reporting (12 hours for a significant impact on availability, 72 hours for a relevant impact), a critical infrastructure risk management program for named asset classes, and enhanced obligations for systems of national significance.

The CIRMP rules require material risks to be managed across cyber, personnel, supply chain and physical hazards, and a recognised cyber framework to be maintained: AESCSF SP-1, the Essential Eight at Maturity Level One, ISO/IEC 27001, the NIST CSF, C2M2 MIL-1, or an equivalent.

How we use it. We build and test the OT side of the program: the asset inventory, the material risks in the plant, the framework assessment, and an incident plan with the clocks built in.

Read more: The SOCI Act and CIRMP: what they ask of your operational technology

AESCSF

Electricity, gas and liquid fuel operators. Developed by AEMO with industry and government; Security Profile 1 is an accepted CIRMP framework.

The Australian Energy Sector Cyber Security Framework: domains of practices at three maturity indicator levels, with a criticality assessment that sets each entity's security profile (SP-1 to SP-3) and so the practices it must meet. Version 2 is current.

How we use it. The assessment we run most often: SP-1 assessments for new and existing sites, SP-2 roadmaps for entities moving up, using AEMO's toolkit and evidence from the plant, not just the policy shelf.

Read more: AESCSF explained: security profiles, maturity levels and what an assessment involves

Essential Eight

Australian organisations following the Australian Signals Directorate's baseline mitigation strategies. Maturity Level One is an accepted CIRMP framework.

Eight mitigations, each at maturity levels one to three: application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups.

How we use it. Written for corporate IT, so we translate it for the plant: what patching, application control and MFA mean on an HMI or an engineering workstation, and which compensating controls apply where the vendor says no.

India

CEA Cyber Security in Power Sector Regulations, 2026

Every entity with OT on India's interconnected power system: generators, captive plants and storage at 50 MW or more, all transmission and distribution licensees, load despatch centres, exchanges and vendors. In force 1 April 2027.

A ring-fenced CISO, an annually approved cyber security policy, a cyber asset register, six-monthly risk plans, VAPT before commissioning, OT isolated from IT and the internet and segmented by trust level, control traffic confined to India, remote access for emergencies only, six-hour incident reporting to CSIRT-Power and CERT-In, and audits every nine to fifteen months with one month to close critical and high findings.

How we use it. From our Hyderabad base we build the register, design the trust levels, bring remote access under control and prepare the incident plan and the audit evidence, with the clause references the auditor expects.

Read more: India's CEA cyber security regulations 2026: what power sector OT has to do by April 2027

CERT-In Directions and NCIIPC

Every service provider, intermediary, data centre, body corporate and government organisation in India, in every sector.

The CERT-In Directions of 28 April 2022: cyber incidents, including attacks on critical infrastructure, SCADA and OT, reported within six hours of noticing; 180 days of ICT logs kept within India; clocks synchronised to NIC or NPL time; a designated point of contact.

NCIIPC, the national agency for critical information infrastructure under the IT Act, can have systems notified as protected systems, which brings its own controls and a security operations expectation.

How we use it. We make sure the OT is inside the logging, time and reporting arrangements, and that the six-hour clock has an owner in the plant's incident plan.

Read more: India's CEA cyber security regulations 2026: what power sector OT has to do by April 2027

Sector-specific

API Standard 1164

Pipeline operators. The American Petroleum Institute's standard for pipeline control system cyber security, widely referenced in oil and gas outside the United States.

Requirements for a pipeline control-system security programme: governance, risk assessment, asset management, access control, network architecture, monitoring, incident response and recovery, aligned with IEC 62443 concepts.

How we use it. Our reference for pipeline SCADA assessments, mapped to IEC 62443 zones and conduits for the design work.

IMO MSC.428(98) and maritime cyber guidance

Ship owners and operators, and the port and terminal operators who work with them.

The International Maritime Organization's resolution that cyber risk be addressed in ships' safety management systems under the ISM Code, supported by the IMO guidelines on maritime cyber risk management.

How we use it. For ports and terminals we assess the OT that vessels touch: navigation and positioning, vessel traffic services, cargo handling and terminal automation, and the interfaces with shipping lines and stevedores.

RISSB AS 7770 and EN 50159

Rail operators, infrastructure managers and rolling stock owners.

AS 7770 is the Australian rail cyber security standard from the Rail Industry Safety and Standards Board. EN 50159 covers safety-related communication in transmission systems, the basis for securing signalling and train control links.

How we use it. The frame for assessing signalling, train control, onboard and station systems, where safety assurance and cyber security have to be argued together.

IEC 61511 and process safety

Operators of safety instrumented systems in the process industries: chemical, oil and gas, water treatment.

The functional safety standard for the process sector. Its 2016 edition requires a security risk assessment of the safety instrumented system, which is where process safety and cyber security formally meet.

How we use it. We treat the safety system as its own zone with the highest consequence, assess it against both IEC 61511 and IEC 62443, and design its conduits so that a cyber event cannot become a loss of safety.

Bound by a standard we have not named? Ask.

Sector regulators and customers add their own. The method is the same: read what it asks, map it to the plant, prove it.