"In 2025, 60% of organizations experienced an OT security incident. Yet no more than 52% have dedicated monitoring in place." — Dragos & SANS 2025 reports
2025 was a turning point for industrial cybersecurity. In February, Gartner published its first CPS Protection Platforms Magic Quadrant, naming Claroty, Dragos, Microsoft, Armis, and Nozomi Networks as Leaders; the EU's NIS2 Directive came fully into force; and in November, the US Department of Defense officially released its "Zero Trust for Operational Technology" guide.
Cybersecurity on the industrial floor is no longer at the level of "someone occasionally goes to take a look when something seems off." It has become a structural issue where international standards (ISA/IEC 62443), regulation (NIS2), and design principles (Zero Trust, the Purdue Model) are converging all at once.
OT security is no longer a copy of IT security.
1. ISA/IEC 62443 — The International Standard for Industrial Cybersecurity
According to Dragos's official explainer, IEC 62443 is a global standards framework that protects the reliability, integrity, and security of IACS (Industrial Automation and Control Systems) through a risk-based methodology. IEC 62443-1 defines terminology and models, -2 covers policies and programs, -3 defines system security, and -4 defines product security requirements.
There are four core concepts. (1) Security Levels (SL 1-4) — defining the security design level for each asset. (2) Zones and Conduits — separating graded security zones and the controlled conduits between them. (3) The seven Foundational Requirements (FR) — identification and authentication, use control, system integrity, data confidentiality, restricted data flow, response to events, and availability. (4) Certified products, suppliers, and operations — using only supply chains certified under the IECEE CB scheme.
- Zones & Conduits — separate assets into graded zones; permit only the conduits between them
- Security Levels 1-4 — SL2 and above is the realistic target for most manufacturing sites
- Seven Foundational Requirements — cross-verification across distinct security domains
- Certification for both products and components — IEC 62443-4-2 (product), -3-3 (system)
- Continuous recertification — regular monitoring and audits are mandatory
2. The NIS2 Directive — The EU's Mandatory Standard for Industrial Security
NIS2 is the updated version of the EU's directive on the security of network and information systems, which entered into force in 2023 and became fully applicable in 2025. Compared with the original NIS, its industry scope has expanded substantially, covering manufacturing, energy, logistics, and food. The core requirements are board-level accountability for security, incident reporting within 24 hours, supply-chain security obligations, and fines for non-compliance.
What deserves attention is that NIS2 mandates "governance compliance," not merely "technical compliance." It aligns naturally with technical standards such as IEC 62443, and most companies adopt an "IEC 62443 compliance → NIS2 reporting framework" structure. In addition, NIS2 audit requirements and the corresponding cyber-insurance policies recommend retaining OT session records for at least 12 months.
IEC 62443 answers "how"; NIS2 answers "what you must prove."
3. The Purdue Model and Zero Trust — Synthesis, Not Opposition
The Purdue Reference Model, an industrial network layering model that emerged in the late 1990s, defines data flows and security boundaries across five levels (L0-L5). Claims that "Purdue will be different" have multiplied recently, but the SANS Institute, the IEC 62443 working groups, and the US Department of Defense's November 2025 Zero Trust for OT guide have all stated officially that "the Purdue Model's principle of functional separation remains valid."
- Companies that experienced an OT security incident in 2025: 60% (Dragos)
- Adoption rate of dedicated OT security monitoring: 52% (SANS)
- Gartner CPS MQ 2025 Leaders: Claroty, Dragos, Microsoft, Armis, Nozomi
- NIS2 incident reporting obligation: 24 hours
- NIS2 fines for board-level non-compliance: up to 2% of annual revenue
4. Case Study — A Redesign After a Ransomware Incident
A European beverage manufacturer suffered a five-day production shutdown in 2024 following a ransomware attack. In the course of settling its insurance claim, it redesigned its OT environment under a policy of "IEC 62443 compliance plus demonstrable NIS2 readiness," and 12 months later had deployed Claroty CTD-based asset discovery alongside Dragos Platform-based threat monitoring. The results: 42% of assets discovered that previously had no visibility, every connection reclassified on a zone basis, and zero recurring incidents over the following 18 months.
Cybelesoft's 2025 guide ("Securing Third-Party Vendor Access to OT Networks: Zero Trust Guide") points out that third-party vendor access to OT accounts for 46% of cyber incidents. A "ZT + Purdue" design that layers Zero Trust principles on top of the Purdue Model is establishing itself as the practical answer.
How PlantPulse Answers
KOPENS PlantPulse adopts IEC 62443-3-3 (system security requirements) plus 62443-4-2 (component level) design as its baseline architecture. Data collection agents are deployed in line with Zone/Conduit separation, and every access is recorded on the basis of authentication, authorization, and audit logs. The 12-month session-record retention called for by NIS2 audits is a default setting.
PlantPulse's data governance in particular is designed to satisfy IEC 62443's FR2 (use control), FR3 (system integrity), and FR4 (data confidentiality) simultaneously. It also supports API integration with Claroty and Dragos asset-inventory data, reducing friction when connecting to a security operations center (SOC).
Closing
The essentials for industrial cybersecurity in 2026 are clear: design for IEC 62443 compliance, a governance framework that answers NIS2 and comparable domestic regulations, Zero Trust principles layered on top of Purdue, and a continuously monitoring OT security operations center (OT SOC).
Security is not something you get just because a vendor sells it. It is decided by "how you designed it" and "who can prove what." That is the real message of IEC 62443 and NIS2. (Related sources: Dragos "ISA/IEC 62443 Concepts" white paper, EU NIS2 Directive 2022/2555, US DoD "Zero Trust for OT" Nov 2025, Gartner CPS Protection MQ 2025, Cybelesoft "Zero Trust Vendor Access" 2025, SANS 2025 OT Survey)
© KOPENS — Industrial DataOps & PlantPulse Platform