Cybersecurity for Steel Plants: IEC 62443

By James Smith on July 20, 2026

cybersecurity-steel-plants-iec-62443-ai

Every AI model that touches a steel plant's control systems widens the plant's attack surface by definition — it needs a data connection somewhere it didn't have one before. That isn't a reason to avoid AI, but it is a reason cybersecurity leads need to be in the room before the first sensor gets wired up, not after. IEC 62443 already gives steel plants a mature framework for zone-based segmentation; the work now is extending that same framework to cover AI data pipelines without opening a path back into the control loop. Book a demo to see how AI connectivity is designed to fit inside your existing IEC 62443 zone model.

CYBERSECURITY LEAD GUIDE · STEEL PLANTS · IEC 62443

AI Expands Your Attack Surface by Design — IEC 62443 Tells You Exactly Where to Contain It

Zero-trust and zone segmentation aren't new concepts to steel plant cybersecurity teams. What's new is applying that same discipline to the data pipelines feeding AI models on the plant floor.

5
IEC 62443 Security Levels From SL-0 to SL-4
70%+
Of OT Incidents Traced to Poor Segmentation
Zero
Write-Back Paths Required Into Control Zones
THE EXPANDED ATTACK SURFACE

What Actually Changes When AI Joins the Control Loop

Adding AI to a steel plant doesn't just mean adding a new server — it means adding new data flows, new third-party model dependencies, and often new edge devices near sensitive equipment. Each of the categories below represents a place where a cybersecurity team needs a documented answer before rollout, not a discovery made after an incident.

01
New Edge Devices on the Floor
Cameras, vibration sensors, and edge gateways introduce new physical and network endpoints near production equipment.
02
Third-Party Model Dependencies
Cloud-hosted or vendor-managed AI models introduce a dependency on external infrastructure and its own security posture.
03
New Data Egress Paths
Historian data leaving the OT network for analytics creates a new egress point that must be explicitly monitored.
04
Expanded Credential Surface
More systems accessing OT data means more credentials and service accounts that need lifecycle management.
IEC 62443 ZONE MODEL

Mapping AI Connectivity to Existing Security Zones

IEC 62443 organizes a plant into zones and conduits, each carrying an assigned security level target. The clearest way to bring AI into this framework is to treat it as its own zone, connected to the rest of the plant only through explicitly defined, monitored conduits — never as an extension of an existing control zone.

ZoneTypical ContentsTarget SLAI Connectivity Rule
Safety ZoneSafety instrumented systemsSL-3 / SL-4No AI connectivity permitted
Control ZonePLCs, DCS, HMISL-2 / SL-3Read-only historian export only
Operations ZoneMES, SCADA historianSL-2Primary source for AI data intake
AI / Analytics ZoneAI models, dashboardsSL-1 / SL-2Isolated zone, one-way inbound data only

Every iFactory Deployment Starts With a Zone Mapping Exercise

Before any sensor or data pipeline goes live, we work with your cybersecurity team to map exactly where the AI zone sits relative to your existing IEC 62443 conduits.

ZERO-TRUST PATTERNS

Four Zero-Trust Principles That Apply Directly to AI Connectivity

Zero-trust isn't a single product — it's a set of principles that apply cleanly to how AI systems should be allowed to touch a steel plant's data. The four patterns below form the baseline most cybersecurity leads require before approving any AI integration.

Explicit Conduit Definition
Every data path between the AI zone and operations zone is documented, justified, and reviewed — nothing connects implicitly.
Least-Privilege Data Access
AI models and the people who manage them get access to only the specific data streams required for their function.
Continuous Conduit Monitoring
Traffic across every AI-related conduit is logged and monitored the same way any inter-zone traffic is under IEC 62443.
Assume Breach Design
The AI zone is architected so that a compromise there cannot propagate a path back into control or safety zones.
ASSESSMENT SEQUENCE

How a Cybersecurity-Led AI Rollout Typically Proceeds

Cybersecurity leads who bring AI projects in successfully tend to run a consistent assessment sequence before any deployment, rather than reviewing the architecture after vendors have already been selected.


Phase 1 — Zone & Conduit Mapping
Existing IEC 62443 zones are reviewed and a new AI zone is defined with explicit conduit boundaries.

Phase 2 — Risk Assessment
A formal risk assessment scores the proposed AI conduits against target security levels for each zone involved.

Phase 3 — Controlled Pilot Deployment
A limited pilot validates that data flows behave exactly as designed, with monitoring active from day one.

Phase 4 — Fleet-Wide Rollout
The validated architecture is replicated across additional lines or sites under the same conduit rules.
FREQUENTLY ASKED QUESTIONS

Questions Cybersecurity Leads Ask Before Approving AI Connectivity

Does connecting AI monitoring require opening new inbound paths into the control zone?
No. A properly architected AI integration only requires a one-way, outbound data export from the operations zone historian, with no inbound path created into the control zone. The AI zone itself is treated as a separate, isolated zone under the IEC 62443 model. Book a demo to review this conduit design against your specific zone architecture.
What security level should the AI/analytics zone target under IEC 62443?
Most AI and analytics zones are appropriately targeted at SL-1 or SL-2, reflecting their isolation from safety and control functions, though the exact target depends on what data the zone processes and how sensitive that data is considered. A formal risk assessment specific to your plant determines the right target. Contact our support team to work through this assessment for your facility.
How is third-party AI model risk handled if the vendor manages infrastructure outside our network?
Third-party model risk is managed by keeping the vendor's infrastructure entirely outside any control or safety zone, limiting the data it receives to what's strictly needed, and requiring documented security practices from the vendor that meet your plant's baseline standards. On-premises deployment options exist for plants that prefer to keep all AI processing inside their own network boundary. Book a demo to compare on-premises and cloud-connected deployment models.
Who signs off on the AI zone's security architecture before it goes live?
Sign-off typically follows the same process your plant already uses for any new zone or conduit under IEC 62443 — a joint review between the cybersecurity lead, OT engineering, and often a third-party security assessor for higher-risk facilities. Adding an AI zone doesn't require a new approval process, just an extension of the existing one. Contact our support team to align the AI zone review with your existing sign-off process.
What happens during a security incident if it originates in the AI/analytics zone?
Because the AI zone is architected with no inbound path into control or safety zones, an incident originating there is designed to be containable without threatening production or safety systems. Incident response plans should still explicitly cover this zone, including how monitoring alerts are routed and who is accountable for containment. Book a demo to see how incident response scenarios are tested for the AI zone specifically.

Get a Zone Mapping Review Before Any Sensor Goes Live

Bring your cybersecurity team into the design conversation from the start — we'll walk through the IEC 62443 zone and conduit model for your specific plant.


Share This Story, Choose Your Platform!