Skip to main content Skip to search Skip to main navigation

1. Initial Situation of Cybersecurity in Operational Technology (OT) (Industrial Cybersecurity, OT Risks)


Cybersecurity is a critical issue - not only for corporate IT, but also increasingly for operational technology (OT). OT was originally a rather isolated environment in which PLCs, networks and control components were interconnected for a specific task. The term “security” primarily referred to secure operation, rather than cyber threats.

However, this has changed fundamentally since the discovery of the “Stuxnet” worm in 2010. The attack on PLC controllers impressively demonstrated that OT environments can also be the target of cyber attacks. Traditionally, these areas were “air-gapped” and not connected to external networks. Today, however, OT networks are often connected to IT systems or the cloud via Ethernet or WiFi.

With the convergence of IT and OT, factory automation and industrial applications must be prepared for current and future cyber security threats. Although IT incidents occur more frequently, OT incidents are usually much more destructive and can endanger life and limb as well as entire companies. The technical gap between IT and OT systems makes it difficult to simply adopt established IT security mechanisms.

2. Governmental and Normative Requirements
(Cyber Resilience Act, NIS-2, Machinery Regulation)


National, European and international institutions have now recognized the relevance of OT security. In addition to protecting society and the economy, state actors who use cyber attacks strategically are also involved.

cyber-resilience-actA key result at EU level is the Cyber Resilience Act (CRA). This applies to all products with digital elements that are sold in the European Union - including OT components. After a transitional period until November 2027, the CRA will apply throughout Europe without national legislation.

While the CRA focuses on products, the NIS-2 directive primarily addresses processes and IT in companies, especially in critical infrastructures (KRITIS) and KRITIS-related companies.

Cybersecurity requirements can also be found in other standards and regulations such as the Machinery Regulation 2023/1230, the Radio Equipment Directive (RED, Article 3.3), UNR 155/156 (automotive communication) and IEC 61508 (functional safety).

3. Solution Approach IEC 62443 for Safe OT Environments
(Industrial Automation & Control Systems, IACS)


The IEC 62443 series of standards is specifically geared towards industrial communication systems (Industrial Automation & Control Systems, IACS) and provides a framework for taking a comprehensive look at cybersecurity and implementing it in practice.

IEC 62443 consists of four parts. While the first part (62443-1) clarifies definitions, the other parts deal with the entire value chain of a system - from the component supplier to the machine manufacturer to the system operator.

Each player must make their contribution to safety:

Component Supplier


Secure development, provision of security updates over the life cycle

Mechanical Engineer


Security in design, equipment with safe components, safe configuration

Plant Operator


Secure operation, installation of updates, staff training

All parties involved must also provide comprehensive documentation, hardening guides and training and monitor and publicize potential security risks throughout the entire product lifecycle.

4. Concepts of IEC 62443
(Defense in Depth, Security by Design, Security by Default, DevSecOps)


IEC 62443 follows practice-oriented concepts to cover technical and organizational requirements.


  • Defense in Depth

    Multi-layered security concepts, similar to a castle with a moat, walls and towers. Systems and machines are divided into different layers, from physical access protection to secure system and network design.

  • Security by Design

    Safety requirements must be incorporated into product and machine development right from the start, on an equal footing with functional requirements.

  • Security by Default

    Products should be delivered as securely as possible in their basic configuration. Potentially risky functions are only activated when required.

  • Secure Development Process & DevSecOps

    A secure development process must take security into account throughout. Similarly, NIS-2 and GDPR require secure development and operating environments.

5. Simple Machine Security Through Zones and Conduits
(OT Network Segmentation, Industrial Security Architecture)


In the context of security by design, the network structure in a production plant is crucial. Similar to castle tactics, networks should be divided into different trust zones whose transitions are protected by so-called “conduits”. These conduits only allow the absolutely necessary communication and thus increase security without impairing the functionality of the system. This network segmentation can often be implemented retrospectively in existing systems without having to redo the basic planning of the machine.


6. Technical Solutions as Conduit:
Firewall, Coupler, MQTT Broker, Remote Maintenance Router


Machine Firewall as Conduit (OT Firewall)

A firewall (e.g. Helmholz WALL IE) separates the machine's communication from the factory network. Only configured and permitted connections are possible. IP addresses in the machine network are translated via NAT, addresses that are not required remain invisible. This also makes commissioning easier, as the machine always remains the same internally.

Gateways and Couplers as Conduit
(Machine-to-Machine Communication)

If only the pure user data of two machines is to be exchanged, fieldbus couplers are used. These only copy user data, but prevent any other data traffic between the machines. For example, a PROFINET CPU can be securely coupled with an EtherNet/IP CPU.

MQTT Broker as Conduit
(Machine-to-Cloud, Industrial IoT)

An MQTT broker with two separate LAN interfaces (e.g. from Helmholz) can serve as a secure intermediary. It receives the machine data on one side and forwards it to the cloud on the other, without the machine being directly accessible from the internet.

Remote Maintenance Router as Conduit
(Remote Maintenance, VPN Security)

Remote maintenance is security-critical. A router with an integrated firewall (e.g. Helmholz REX series) enables role-based remote access via VPN. This makes it possible to define exactly which devices the service technician is allowed to access in order to prevent unintentional or unauthorized access.

A Comparison of the Advantages of Conduit Solutions and Areas of Application

Conduit Solution Application Advantages
Machine Firewall Machine <--> Factory Network
  • Individual Approvals
  • NAT Address Conversion
  • Clear Separation
Fieldbus Coupler Machine <--> Machine
  • Exchange of pure user data
  • No undesired traffic
MQTT-Broker (2 LANs) Machine <--> Cloud (IoT)
  • Secure disconnection from the Internet
  • Only defined data flows
Remote Maintenance Router Remote Access
(Service <--> Machine)
  • Role-based access via VPN
  • Limited Accessibility of Certain Devices

7. Organizational Measures and Information Management PSIRT, CERT@VDE, Firmware Updates


In addition to technical measures such as conduits, professional information management is crucial. Regular information about security vulnerabilities, firmware updates and secure configurations is essential.

Important Questions for System Operators:

  • Which networked components (Ethernet, WiFi, Bluetooth, LTE/5G) are installed in my system?
  • Where can I get information on security incidents and new firmware versions?
  • How do I configure the devices securely?
  • Who can I contact if I have security problems?

PSIRT - Product Security Incident Response Team

The PSIRT team is your direct contact for Helmholz components.
E-mail: psirt@helmholz.de
Phone: +49 (9135) 7380-0

Contact us now

You can find further information on our page on PSIRT.

CERT@VDE is a partner for the publication of security incidents in Helmholz products. Here you will find published advisories, and via RSS feeds you can integrate messages directly into Outlook to stay up-to-date.

8. Conclusion of IEC 62443: Strategies for a Secure and
and Future-Proof OT Infrastructure


IEC 62443 offers a sound approach to making OT environments and machines secure, taking into account the Cyber Resilience Act, the NIS-2 directive and other standards.

A high level of security can be achieved by applying defense-in-depth concepts, security by design and security by default as well as through the targeted use of conduits in the form of firewalls, couplers, MQTT brokers and remote maintenance routers. Supplemented by active information and security management, PSIRT support and CERT@VDE connection, plant operators, machine builders and component manufacturers are prepared for current and future cyber threats in the long term.

Our Partners on the Subject of Security

How Helmholz protects industrial communication.

Guide for machine manufacturers and operators on
current EU legislation.

Download Whitepaper

Subscribe to our newsletter now!

Receive regular news on products, promotions and solutions from the world of Helmholz.