Every AI model that touches a steel plant's control systems widens the plant's attack surface by definition — it needs a data connection somewhere it didn't have one before. That isn't a reason to avoid AI, but it is a reason cybersecurity leads need to be in the room before the first sensor gets wired up, not after. IEC 62443 already gives steel plants a mature framework for zone-based segmentation; the work now is extending that same framework to cover AI data pipelines without opening a path back into the control loop. Book a demo to see how AI connectivity is designed to fit inside your existing IEC 62443 zone model.
CYBERSECURITY LEAD GUIDE · STEEL PLANTS · IEC 62443
AI Expands Your Attack Surface by Design — IEC 62443 Tells You Exactly Where to Contain It
Zero-trust and zone segmentation aren't new concepts to steel plant cybersecurity teams. What's new is applying that same discipline to the data pipelines feeding AI models on the plant floor.
5
IEC 62443 Security Levels From SL-0 to SL-4
70%+
Of OT Incidents Traced to Poor Segmentation
Zero
Write-Back Paths Required Into Control Zones
THE EXPANDED ATTACK SURFACE
What Actually Changes When AI Joins the Control Loop
Adding AI to a steel plant doesn't just mean adding a new server — it means adding new data flows, new third-party model dependencies, and often new edge devices near sensitive equipment. Each of the categories below represents a place where a cybersecurity team needs a documented answer before rollout, not a discovery made after an incident.
01
New Edge Devices on the Floor
Cameras, vibration sensors, and edge gateways introduce new physical and network endpoints near production equipment.
02
Third-Party Model Dependencies
Cloud-hosted or vendor-managed AI models introduce a dependency on external infrastructure and its own security posture.
03
New Data Egress Paths
Historian data leaving the OT network for analytics creates a new egress point that must be explicitly monitored.
04
Expanded Credential Surface
More systems accessing OT data means more credentials and service accounts that need lifecycle management.
IEC 62443 ZONE MODEL
Mapping AI Connectivity to Existing Security Zones
IEC 62443 organizes a plant into zones and conduits, each carrying an assigned security level target. The clearest way to bring AI into this framework is to treat it as its own zone, connected to the rest of the plant only through explicitly defined, monitored conduits — never as an extension of an existing control zone.
| Zone | Typical Contents | Target SL | AI Connectivity Rule |
| Safety Zone | Safety instrumented systems | SL-3 / SL-4 | No AI connectivity permitted |
| Control Zone | PLCs, DCS, HMI | SL-2 / SL-3 | Read-only historian export only |
| Operations Zone | MES, SCADA historian | SL-2 | Primary source for AI data intake |
| AI / Analytics Zone | AI models, dashboards | SL-1 / SL-2 | Isolated zone, one-way inbound data only |
Every iFactory Deployment Starts With a Zone Mapping Exercise
Before any sensor or data pipeline goes live, we work with your cybersecurity team to map exactly where the AI zone sits relative to your existing IEC 62443 conduits.
ZERO-TRUST PATTERNS
Four Zero-Trust Principles That Apply Directly to AI Connectivity
Zero-trust isn't a single product — it's a set of principles that apply cleanly to how AI systems should be allowed to touch a steel plant's data. The four patterns below form the baseline most cybersecurity leads require before approving any AI integration.
Explicit Conduit Definition
Every data path between the AI zone and operations zone is documented, justified, and reviewed — nothing connects implicitly.
Least-Privilege Data Access
AI models and the people who manage them get access to only the specific data streams required for their function.
Continuous Conduit Monitoring
Traffic across every AI-related conduit is logged and monitored the same way any inter-zone traffic is under IEC 62443.
Assume Breach Design
The AI zone is architected so that a compromise there cannot propagate a path back into control or safety zones.
ASSESSMENT SEQUENCE
How a Cybersecurity-Led AI Rollout Typically Proceeds
Cybersecurity leads who bring AI projects in successfully tend to run a consistent assessment sequence before any deployment, rather than reviewing the architecture after vendors have already been selected.
Phase 1 — Zone & Conduit Mapping
Existing IEC 62443 zones are reviewed and a new AI zone is defined with explicit conduit boundaries.
Phase 2 — Risk Assessment
A formal risk assessment scores the proposed AI conduits against target security levels for each zone involved.
Phase 3 — Controlled Pilot Deployment
A limited pilot validates that data flows behave exactly as designed, with monitoring active from day one.
Phase 4 — Fleet-Wide Rollout
The validated architecture is replicated across additional lines or sites under the same conduit rules.
FREQUENTLY ASKED QUESTIONS
Questions Cybersecurity Leads Ask Before Approving AI Connectivity
Does connecting AI monitoring require opening new inbound paths into the control zone?
No. A properly architected AI integration only requires a one-way, outbound data export from the operations zone historian, with no inbound path created into the control zone. The AI zone itself is treated as a separate, isolated zone under the IEC 62443 model.
Book a demo to review this conduit design against your specific zone architecture.
What security level should the AI/analytics zone target under IEC 62443?
Most AI and analytics zones are appropriately targeted at SL-1 or SL-2, reflecting their isolation from safety and control functions, though the exact target depends on what data the zone processes and how sensitive that data is considered. A formal risk assessment specific to your plant determines the right target.
Contact our support team to work through this assessment for your facility.
How is third-party AI model risk handled if the vendor manages infrastructure outside our network?
Third-party model risk is managed by keeping the vendor's infrastructure entirely outside any control or safety zone, limiting the data it receives to what's strictly needed, and requiring documented security practices from the vendor that meet your plant's baseline standards. On-premises deployment options exist for plants that prefer to keep all AI processing inside their own network boundary.
Book a demo to compare on-premises and cloud-connected deployment models.
Who signs off on the AI zone's security architecture before it goes live?
Sign-off typically follows the same process your plant already uses for any new zone or conduit under IEC 62443 — a joint review between the cybersecurity lead, OT engineering, and often a third-party security assessor for higher-risk facilities. Adding an AI zone doesn't require a new approval process, just an extension of the existing one.
Contact our support team to align the AI zone review with your existing sign-off process.
What happens during a security incident if it originates in the AI/analytics zone?
Because the AI zone is architected with no inbound path into control or safety zones, an incident originating there is designed to be containable without threatening production or safety systems. Incident response plans should still explicitly cover this zone, including how monitoring alerts are routed and who is accountable for containment.
Book a demo to see how incident response scenarios are tested for the AI zone specifically.
Get a Zone Mapping Review Before Any Sensor Goes Live
Bring your cybersecurity team into the design conversation from the start — we'll walk through the IEC 62443 zone and conduit model for your specific plant.