Every sensor you add for predictive maintenance, every camera you connect for vision-based quality inspection, and every model you plug into your historian is also a new door into your control systems. The old assumption that operational technology was physically isolated from the outside world has quietly stopped being true — remote maintenance links, cloud-connected analytics, and IIoT sensors all dissolve the air gap most security plans still assume exists. Manufacturing AI is not the enemy of OT security, but bolting it on without a framework is how a predictive maintenance project becomes a way into a safety instrumented system. IEC 62443 is the standard built to prevent exactly that, and our team can walk your security lead through how iFactory deploys inside a zoned architecture.
IEC 62443 · OT Cybersecurity
OT Cybersecurity for Manufacturing AI: The IEC 62443 Path
Connecting AI to your control systems creates a new attack surface every time. Here is how zones, conduits, and security levels let you deploy predictive AI without opening a path to your safety systems.
The Attack Surface AI Quietly Creates
Manufacturing AI needs data, and data needs a path out of the control network. Every one of those paths — a wireless vibration sensor, a cloud-based analytics feed, a remote support connection for the vendor's engineers — is a potential conduit for an attacker as well as a signal for your model. In 2026, regulators caught up to this reality: the EU Cyber Resilience Act now requires vulnerability reporting for connected industrial products, and IEC 62443 has become the reference framework manufacturers use to prove they have actually addressed it, not just claimed to.
The traditional hierarchical view of a plant network — process at the bottom, enterprise systems at the top, with clean layers in between — was a reasonable model as long as data only moved vertically through a small number of controlled interfaces. That is no longer how a modern plant behaves. IIoT sensors send readings directly to cloud platforms, bypassing several layers at once. Digital twin tools pull raw data from field devices and aggregate it into dashboards several levels removed from where it originated. Remote maintenance links connect an external technician's laptop straight to a Level 1 controller. None of these connections are inherently unsafe. Left undocumented and unmanaged, each one is an unplanned door.
The Old Assumption
Air-gapped networks kept OT safe from IT-side threats
→
The 2026 Reality
IIoT, remote access, and cloud analytics dissolve the gap on every connected line
Zones, Conduits, and Security Levels: The Core Model
IEC 62443 does not ask you to secure every device to the same standard. It asks you to group assets by how much protection they actually need, then control what is allowed to pass between those groups. A zone is a collection of assets that share the same protection requirements — your safety systems form one zone, your supervisory historian forms another. A conduit is the defined, monitored channel that connects two zones, and nothing is supposed to cross a zone boundary outside of one. That structure — zones, conduits, and security levels ranging from SL 1 for casual, accidental exposure up to SL 4 for a sophisticated, well-resourced attacker — is what makes it possible to connect an AI platform to a plant without exposing the safety systems sitting right next to it.
SL 3–4
Safety Instrumented Systems
Highest protection. No AI platform should ever connect directly here.
conduit
SL 2–3
Control Zone — PLCs, DCS, HMIs
Read-only data taps only. Never a write path for an AI platform.
SL 2
Supervisory Zone — Historian, SCADA
The standard, sanctioned integration point for most AI data ingestion.
conduit
SL 1–2
AI and Analytics Zone
Where iFactory's platform lives — isolated from the control zones it monitors.
Legacy OT Security vs. AI-Ready Zoned Architecture
The difference between a flat network and a zoned one rarely shows up until something goes wrong — and by then, the difference determines whether an incident stays contained to one system or spreads across the plant. The comparison below maps that gap across the questions a security lead actually gets asked during an audit or after an incident.
| Security Dimension |
Flat, Unsegmented Network |
IEC 62443 Zoned Architecture |
| AI Data Access |
Direct connection into the control network, often through a single shared VLAN |
Reads only from the supervisory zone via a defined, monitored conduit |
| Breach Containment |
A single compromised device can reach the entire plant network |
Compromise is contained to one zone; conduits enforce the boundary |
| Vendor Remote Access |
Persistent VPN access directly into control-level equipment |
Time-boxed access to a designated zone, logged and reviewed |
| Compliance Readiness |
No documented security level targets; audits start from zero |
Documented SL-T per zone maps directly to CRA and IEC 62443 audits |
| Incident Response |
Unclear which systems were exposed; response starts with discovery |
Zone boundaries define blast radius before the incident even happens |
See how iFactory's AI and Analytics zone connects without ever touching your control-level network
Four Principles for Deploying AI Inside a Zoned Network
1
Never let AI write to control-level equipment
Predictive and monitoring platforms should read from the supervisory zone. A model that can send commands into a control zone turns a data project into a safety risk the moment its logic, its credentials, or its host is compromised.
2
Treat every conduit as a documented, monitored path
A conduit is not just a firewall rule — it is a defined, inspected channel with a stated purpose. Undocumented conduits are the single most common finding in IEC 62443 gap assessments across manufacturing plants.
3
Assign a security level target to the AI zone itself
The analytics platform is a zone in its own right, with its own SL-T based on what it can see and what it could theoretically be used to reach. Treating it as an afterthought outside the security model is the gap attackers look for.
4
Apply zero-trust to every remote and vendor connection
Persistent, always-on remote access for any vendor — including your AI provider — is a standing risk. Time-boxed, logged, and scoped access closes the door that most real-world OT breaches actually walked through.
What a Gap Assessment Should Cover Before You Connect AI
A short, focused assessment before connecting any AI platform to your network catches the majority of avoidable exposure. It does not need to be a multi-month engagement to be effective, and it does not need to cover the entire facility on day one — most manufacturers get the most value by scoping the assessment tightly around the specific lines, historians, and conduits the AI platform will actually touch, then expanding coverage from there once the pattern is proven.
01
Every zone in scope has a documented Security Level Target, not an assumed one
02
Every conduit connecting to the AI zone has a written, single stated purpose
03
No AI platform holds write access to any PLC, DCS, or safety instrumented system
04
Vendor remote access is time-boxed, logged, and reviewed on a defined cadence
05
Incident response plans define expected blast radius per zone, not just per device
06
The AI vendor can produce, in writing, exactly which zone their platform integrates with
Frequently Asked Questions
Does connecting an AI platform automatically increase our OT risk?
It increases your attack surface, which is not the same as increasing your risk, provided the connection is designed correctly. A platform that reads from the supervisory zone through a documented conduit, with no write access to control-level equipment, adds a bounded and monitored path rather than an open one. The risk comes from unplanned, undocumented connections — not from AI itself. For a review of how a specific deployment maps to your zones,
book a security architecture session.
Is IEC 62443 certification mandatory for manufacturers?
IEC 62443 itself is a voluntary standard in most jurisdictions, but it has become the de facto reference framework regulators point to when enforcing newer mandatory requirements, including the EU Cyber Resilience Act's vulnerability reporting rules that took effect in 2026. Even where certification is not legally required, demonstrating alignment with IEC 62443 zones and security levels is increasingly expected in customer audits, insurance underwriting, and supply chain security reviews.
Can we still use wireless IIoT sensors in a zoned architecture?
Yes. Wireless sensors are placed in an appropriately rated zone — typically the same supervisory or field zone as their wired equivalents — and their data flows through a defined conduit rather than a direct, unmonitored path. The zone model is designed to accommodate exactly this kind of modern instrumentation without forcing a choice between connectivity and security.
How long does a basic zone and conduit assessment take?
For a single production line or a focused system under consideration, a practical gap assessment covering zone definition, conduit mapping, and security level targets typically takes two to four weeks. Full-facility assessments across multiple production areas take longer, but most manufacturers start with the zones an AI platform will actually touch rather than the entire plant at once.
What is the difference between a Security Level and a Maturity Level?
A Security Level rates the technical capability of a product, system, or zone to resist a defined category of attacker — from casual, unintentional violations at SL 1 up to sophisticated, resourced attacks at SL 4. A Maturity Level, by contrast, certifies the discipline of a vendor's development process. Both fall under IEC 62443, but a vendor can hold a strong Maturity Level certification while the specific zone their product sits in still needs its own Security Level Target defined for your environment.
Connect AI Without Opening the Door
Deploy Manufacturing AI Inside a Security Architecture Built for It
iFactory's platform integrates at the supervisory zone by design — read-only, conduit-defined, and mapped to your IEC 62443 security level targets from day one. No write access to control systems. No undocumented paths in.