Why segmentation is the starting point, not an afterthought
IEC 62443 is often introduced through its security levels, since these are the part most easily summarised in a slide. In practice, security levels only make sense once an organisation has done the harder work of defining its zones and conduits. Segmentation comes first, both in the standard’s logic and in the order a real implementation should follow.
What a zone actually is
A zone, in IEC 62443 terms, is a grouping of assets that share common security requirements. This is not the same as a physical area of a plant, though the two often overlap. A zone might contain a set of PLCs and the HMI that controls them, a safety instrumented system kept deliberately separate from the basic process control system, or a historian and its associated reporting infrastructure. What defines a zone is not proximity but shared risk profile: assets in the same zone should tolerate the same level of exposure and require the same baseline protections.
Getting zone boundaries right requires understanding both the process and the network. Two devices on the same physical network segment might reasonably belong in different zones if a compromise of one should not be allowed to affect the other, for instance where one device sits within a safety function. Conversely, devices on physically separate networks might belong in the same zone if they share the same trust level and operational purpose. This is where the earlier point about asset inventory matters again: you cannot draw sensible zone boundaries without an accurate picture of what exists and how it is used.
What a conduit does
A conduit is the defined communication pathway between zones. Where a zone answers the question of what needs protecting, a conduit answers the question of what is allowed to cross the boundary, and under what conditions. A conduit is not simply a network cable or a firewall rule; it is a governed pathway with defined protocols, defined direction of communication where possible, and defined controls applied to traffic passing through it.
In practice, conduits are where a lot of OT security work concentrates, because they are the points where risk from one zone can propagate into another. A conduit between the corporate IT network and the OT environment carries different risk, and needs different controls, from a conduit between two OT zones of similar sensitivity. Firewalls, data diodes, protocol-aware filtering, and jump servers for remote access all function as conduit controls, applied according to what that specific conduit needs to allow through and what it needs to keep out.
Security levels give the requirement a number
Once zones and conduits are defined, IEC 62443 assigns each a target security level, from SL-1 through SL-4, reflecting the sophistication of adversary the zone or conduit needs to withstand. SL-1 addresses casual or coincidental exposure. SL-4 addresses a well-resourced, highly motivated adversary with specific knowledge of the target, the kind of threat model appropriate for the most safety-critical or nationally significant systems. Most industrial zones sit somewhere between SL-2 and SL-3 in practice, reflecting a realistic assessment of who is likely to target them and with what capability.
The standard also distinguishes between capability security level, what a component or system is inherently capable of achieving, and achieved security level, what is actually delivered once the component is deployed, configured, and operated within its environment. A device rated for SL-3 capability does not deliver SL-3 protection if it is deployed with default credentials and no monitoring. This distinction is frequently lost in vendor marketing, where capability ratings are sometimes presented as though they were guarantees of achieved protection.
Putting it together in a real environment
A practical implementation typically starts with process understanding: mapping out what the plant does, where safety functions sit, and which failures would have the most serious consequences. From there, zones are drawn around assets with shared risk profiles, informed by the asset inventory. Conduits are then identified between every pair of zones that need to communicate, including the conduit to the corporate IT network, which is very often the highest-risk conduit in the entire environment. Target security levels are assigned to each zone and conduit based on a realistic threat assessment, not a default assumption that everything needs the highest level available. Finally, controls are selected and implemented to close the gap between the achieved security level and the target.
This is iterative work. Zone and conduit definitions that made sense during initial design often need revisiting as the environment changes, which is another reason continuous asset visibility matters more than a one-off segmentation project. Organisations that treat zones and conduits as a living structure, reviewed as the network evolves, get considerably more value from IEC 62443 than those that document it once and file it away.

