Insights & Thought Leadership
Practical articles on industrial cybersecurity, functional safety, and the standards that govern them. Written by practitioners for practitioners.
Concept and Design Phase: Security Artifacts and Handovers That Survive an Audit
Scope, assumptions, protection goals, threat model: which artifacts must be created in the early phase so that anything can be evidenced later on.
CRA Deadlines 11 September 2026 and 11 December 2027: What Must Be Provable by When
Two dates structure the Cyber Resilience Act. Which obligation applies when, what applies to products already shipped, and what backward planning depends on.
IEC 62443-4-1 in Practice: From a Documented Process to Verifiable Evidence
Eight practices, four maturity levels: what IEC 62443-4-1 requires of device manufacturers, and why a documented process is not yet evidence in an audit.
The Maturity Gap: What IEC 62443-4-1 Requires and What IEC 62443-4-2 Proves in the Device
Process maturity and technical implementation are assessed separately. The difference between the two is the most telling metric of a product's state.
SBOM Without a Parallel Process: Generating the Bill of Materials from the Build
A manually maintained SBOM spreadsheet is outdated by the second release. How the software bill of materials is generated from the build — and what the CRA actually requires.
Attack Feasibility According to ISO/IEC 18045: The Five Factors in Practice
How ISO/IEC 18045 breaks down the feasibility of an attack into five ratable factors — and what that means for product risk assessment.
Attacker Profiles Instead of Parameter Guesswork: Risk Rating That Scales Across a Team
Why fixed attacker profiles make risk ratings more consistent than repeatedly estimating individual parameters — and how to define them properly.
CVSS 3.1 vs. 4.0 — and Why a CVSS Score Is Not a Risk Assessment
What changed in CVSS 4.0, what matters for device manufacturers — and why a CVSS score does not replace a system risk assessment under IEC 62443.
Evaluating Attack Paths: Weakest Link, Sum, or Weighted Hybrid
How to combine a decomposed attack path into a single rating — and why the choice of aggregation determines your entire prioritization.
Accepting Risk Under the Cyber Resilience Act: What Still Holds and What Doesn't
The CRA does not prohibit risk acceptance — but it does require every treatment decision to be traceable to the risk assessment. What that means in practice.
STRIDE and Attack Trees on a PROFINET Field Device: A Detailed Walkthrough
What a threat analysis looks like in concrete terms: STRIDE and an attack tree applied to a PROFINET circuit breaker platform with a safety-related switching function.
Threat and Risk Assessment under IEC 62443: Method, Evidence, Common Gaps
How a threat and risk assessment under IEC 62443 is structured methodically, what the Cyber Resilience Act requires on top — and where it fails in an audit.
Zones and Conduits in IEC 62443-3-2 — and Why Device Manufacturers Should Know Them
The seven-step ZCR process of IEC 62443-3-2, the principle behind zone partitioning — and why device manufacturers should understand it.
IEC 62443-4 and the Cyber Resilience Act: What's the Gap?
Implementing IEC 62443-4-1 and 62443-4-2? Here's exactly what's still missing for CRA compliance and CE marking – a gap analysis.
IEC 62443 Security Levels Explained: SL-C, SL-T, and SL-A
The three types of Security Level in IEC 62443 — Capability, Target, and Achieved — are often confused. Here's how they differ and why the distinction matters for your IACS risk assessment.
A Practical Guide to Zone and Conduit Modeling in OT Networks
Zone and conduit modeling is the core structural concept in IEC 62443-3-2. This guide walks through how to define meaningful zones, assign SL-T values, and design conduits that enforce security boundaries without breaking operations.
IEC 61508 vs IEC 61511: Which Standard Applies to You?
The relationship between the umbrella IEC 61508 standard and the process-industry-specific IEC 61511 confuses many practitioners. Here's a clear breakdown of scope, applicability, and how to navigate both.
Why OT Asset Inventory is Step Zero for Any Security Program
You can't protect what you can't see. Building a reliable OT asset inventory is harder than in IT — passive discovery, engineering workstations, legacy PLCs — but it's non-negotiable. Here's how we approach it.
Stationary Robots and the SRCI Technology
With SRCI and PROFINET®, integrating stationary robots into production lines is simpler than ever — increasing flexibility, reducing engineering effort, and shaping the future of automation.