site-logo
site-logo
site-logo

How AI Is Changing IEC 62443 Assessments

How AI Is Changing IEC 62443 Assessments

How AI Is Changing IEC 62443 Assessments

How AI Is Changing IEC 62443 Assessments
Shieldworkz logo

Team Shieldworkz

Every plant has a version of the same story. A security assessment gets approved, a team is assigned, and the first three weeks disappear into folders. Network diagrams in three different formats. Asset lists that do not match each other. Policies written years ago. Vendor manuals, change records, and emails that were never filed anywhere sensible. By the time someone starts judging actual risk, half the project budget has gone to collecting and reading paper.

That is the quiet problem with IEC 62443 assessments. The standard itself is sound. It is the most widely used framework for securing industrial automation and control systems, and it gives asset owners, system integrators, and product suppliers a shared language for security. But applying it well takes a great deal of evidence review, and that review has historically been manual, slow, and hard to repeat.

Artificial intelligence is now changing that part of the job. Not the judgment part. The reading, sorting, matching, and drafting part. This article explains what is actually shifting, where AI helps, where it should not be trusted on its own, and how industrial leaders can use it to assess more often without lowering the bar. It also explains how OThello Assess, the AI-assisted assessment approach from Shieldworkz, is designed around that principle: machines handle the paperwork, experts keep the decisions.

Why IEC 62443 Matters More Than Ever

IEC 62443 is a series of international standards for the security of industrial automation and control systems. It was developed jointly by the ISA99 committee and the International Electrotechnical Commission, and it is used across manufacturing, energy, water, oil and gas, transportation, and other critical infrastructure sectors.

Its strength is that it speaks to everyone in the industrial supply chain at once. Asset owners use it to run security programs. Integrators use it to design and deliver secure systems. Suppliers use it to build security into products. Regulators and insurers increasingly point to it as a reasonable benchmark for what “good” looks like.

The parts of the standard most assessments touch

Part

What it covers

Who it matters to most

IEC 62443-2-1

Security program requirements for asset owners

Plant owners, CISOs, OT security leaders

IEC 62443-2-4

Security capabilities of service providers

Integrators and maintenance providers

IEC 62443-3-2

Security risk assessment and system design, including zones and conduits

Engineering and security architects

IEC 62443-3-3

System security requirements and security levels

System owners and integrators

IEC 62443-4-1

Secure product development lifecycle

Product suppliers

IEC 62443-4-2

Technical security requirements for components such as PLCs and network devices

Suppliers and procurement teams

The standard organizes technical requirements under seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events, and resource availability. Systems are then assessed against four security levels, from protection against casual or accidental misuse (Security Level 1) up to protection against sophisticated attackers with extended resources (Security Level 4).

That structure is what makes the standard powerful, and it is also what makes assessments heavy. One facility can easily involve hundreds of individual requirements, multiple zones, dozens of asset types, and evidence scattered across engineering, IT, operations, procurement, and third-party vendors.

The Real Reason Industrial Security Is Under Pressure

Operational technology environments are not hypothetical targets. The incidents that shaped the industry’s thinking are well documented, and each one points to a different weakness that a good assessment is meant to catch.

Incident

What happened

What it exposed

Ukraine power grid, December 2015

Attackers took control of operator workstations and opened breakers at regional distribution companies, cutting power to roughly 225,000 customers

Weak separation between business networks and control networks, and remote access without strong controls

Safety system attack at a petrochemical facility, 2017

Malware was built to tamper with a plant’s safety instrumented system, and a fault caused an unplanned shutdown

Safety systems reachable from the wider network, and limited monitoring of engineering workstations

Norsk Hydro ransomware, March 2019

A ransomware attack hit operations across dozens of countries, forcing the company to switch many plants to manual operation, with costs estimated in the tens of millions of dollars

Flat networks, slow recovery planning, and dependence on IT systems that production relied on

Oldsmar water treatment plant, February 2021

An intruder using remote access software briefly changed a sodium hydroxide setting to a dangerous level; an operator noticed and reversed it

Shared credentials, always-on remote access, and no second layer of approval for critical changes

Colonial Pipeline, May 2021

A ransomware attack on business systems led the company to halt pipeline operations for several days, disrupting fuel supply across the U.S. East Coast

The operational impact of IT compromise, and the difficulty of proving that control systems were isolated

Notice the pattern. None of these were failures of one clever gadget. They were failures of architecture, access, segmentation, monitoring, and response, which is precisely the territory that IEC 62443 addresses. An organization that had honestly mapped its zones and conduits, checked its remote access paths, and tested its response plans would have found many of these weaknesses long before an attacker did.

The issue is that honest, detailed assessments are expensive and slow. So they happen once every few years, if at all. And in between, the environment keeps changing.

Where Traditional IEC 62443 Assessments Break Down

If you have run or sponsored one of these projects, the following will sound familiar.

1. Evidence collection eats the schedule

Assessors often spend the largest share of their time simply finding and reading documents. Policies, procedures, network drawings, configuration exports, access lists, patch records, vendor contracts, and incident logs all need to be reviewed and linked to specific requirements. A single document may support a dozen requirements, and a single requirement may depend on a dozen documents.

2. Results depend heavily on who does the work

Two capable assessors can read the same evidence and reach slightly different conclusions, especially on partially met requirements. Without a consistent method for how evidence is weighed, results are hard to compare across sites or across years.

3. Traceability is thin

A finding that says “requirement not met” is only useful if everyone can see why. Which document was reviewed? Which paragraph? Which asset? In manual projects, that trail often lives in spreadsheets and personal notes, and it fades quickly once the report is delivered.

4. The assessment is out of date almost immediately

Plants add equipment, replace controllers, onboard new vendors, and change network paths. A report that was accurate in March may be misleading by October. Because each reassessment is so labor intensive, organizations tend to delay them.

5. Skilled people are spending time on low-value work

OT security specialists are scarce. When experienced engineers spend most of their hours cross-referencing documents and formatting tables, there is less time left for the work only they can do: walking the plant floor, challenging assumptions, and judging what a gap actually means for safety and production.

How AI Is Changing IEC 62443 Assessments

AI does not change what the standard requires. It changes how quickly and consistently evidence can be turned into something an expert can evaluate. Four shifts stand out.

Shift 1: From manual reading to automated evidence analysis

Modern language-based AI can read large volumes of unstructured material, such as policies, procedures, diagram descriptions, asset inventories, and technical documents, and pull out the statements that matter. Instead of a person opening two hundred files, the system reads them first, organizes what it finds, and shows the reviewer where relevant evidence sits.

Shift 2: From scattered notes to mapped requirements

The harder task is not reading, it is matching. Which sentence in a remote access procedure speaks to a specific access control requirement? Which part of a backup policy relates to resource availability? AI can propose those links across hundreds of requirements and thousands of pages, and it can keep them organized so the reviewer sees each requirement alongside the supporting material.

Shift 3: From generic findings to asset and context awareness

A requirement does not apply the same way to every part of a plant. A safety controller, a historian server, and a remote engineering laptop each carry different risk. AI can help identify which assets and which zones are relevant to a given requirement, and what security context surrounds them, so findings are tied to real equipment instead of broad statements.

Shift 4: From one-time projects to continuous reassessment

When the administrative workload shrinks, assessments stop being rare, painful events. Teams can refresh evidence when a major change happens, rerun the analysis, and see what moved. That is a very different posture from waiting for the next audit cycle.

Assessment activity

Traditional approach

AI-assisted approach

Reading and sorting documents

Manual, assessor by assessor

Automated first pass with reviewer oversight

Linking evidence to requirements

Spreadsheet cross-referencing

Proposed mappings with visible source references

Identifying relevant assets and context

Interviews and manual lookup

Suggested associations for expert confirmation

Spotting potential gaps

Late in the project

Surfaced early for expert review

Consistency between reviewers

Varies by individual

Same method applied every time, then validated by experts

Reassessment frequency

Every few years

As often as the environment changes

Final risk decisions

Expert judgment

Expert judgment (unchanged)

The last row is the most important one, and it is where thoughtful assessment design separates itself from hype.

What OThello Assess Does, and What It Deliberately Does Not Do

OThello Assess is the AI-assisted approach Shieldworkz uses to support IEC 62443 assessments. It is built on a simple belief: AI should do the repetitive work, and people should own the conclusions.

In practice, that means OThello Assess uses AI-powered evidence analysis to:

  • Process documentation such as policies, procedures, technical records, and supporting files

  • Map requirements from the standard to the evidence that may support or contradict them

  • Identify relevant assets and security context so that findings connect to real systems and zones

  • Surface potential gaps for review by qualified OT security experts

What it does not do is just as important. It does not decide that your plant is compliant. It does not declare a risk acceptable. It does not replace site walkthroughs, interviews, or operational validation. A potential gap flagged by AI is a starting point for a conversation, not a verdict.

Why the human-in-the-loop design is not optional

Industrial environments carry consequences that office networks do not. A wrong conclusion in an industrial setting is not a lost spreadsheet. It could be an unsafe process condition, a stopped production line, or a service interruption for a community.

Three reasons keep experts in charge:

  1. Context lives outside documents. A procedure might say patches are applied monthly, while the plant floor knows that one legacy controller has not been touched in years because the vendor no longer supports it. Only people who have seen the system can reconcile the two.

  2. Risk is a business and safety decision. Whether a gap is tolerable depends on process hazards, redundancy, compensating controls, regulatory exposure, and cost. AI can inform that decision. It cannot own it.

  3. Documents can be wrong or incomplete. AI works with what it is given. If a diagram is outdated, the analysis reflects an outdated plant. Operational validation closes that distance.

The Benefits of AI-Assisted IEC 62443 Assessment

Used well, this approach delivers practical advantages that decision-makers can measure.

Faster evidence processing

The first pass through documentation, which used to take weeks of analyst time, can be compressed substantially. That frees the schedule for the parts of the project where expertise matters most. Exact savings depend on the volume and quality of evidence, but the shift in where time is spent is consistent: less on collecting and cross-referencing, more on analysis and validation.

Greater consistency

The same method is applied to every requirement, every site, and every reassessment. That makes it easier to compare plants, track improvement, and explain results to boards, auditors, and customers. Experts still validate the output, but they start from a consistent baseline instead of a blank page.

Improved traceability

Every proposed mapping and potential gap can point back to the source material behind it. When a leadership team asks “why did we score this requirement the way we did,” the answer is visible, not buried in someone’s inbox.

More frequent reassessment

Because the administrative burden is lower, organizations can reassess after meaningful changes: a new production line, a network redesign, a vendor change, or an acquisition. Security posture becomes something you track through the year, not something you discover at the end of a project.

Better use of scarce experts

Senior OT security professionals are hard to hire and expensive to retain. Letting them focus on validation, prioritization, and remediation planning gets more value from every hour they spend.

Benefit

Why it matters to leadership

Faster evidence processing

Shorter projects and earlier insight into real risk

Greater consistency

Comparable results across sites and years

Improved traceability

Defensible findings for auditors, insurers, and boards

Frequent reassessment

Security posture that keeps pace with plant changes

Expert focus on judgment

Higher-quality recommendations and remediation plans

The Limits and Risks You Should Understand

A credible discussion of AI in security has to include its weaknesses. Leaders who understand them will get better results than those who treat the technology as a shortcut.

Limit 1: AI is only as good as the evidence

If documentation is missing, outdated, or contradicts reality, the analysis will inherit those flaws. In many plants, the gap between “what is written” and “what is real” is exactly where the biggest risks sit. This is why operational validation remains part of the process.

Limit 2: AI can misread nuance

A statement such as “critical systems are segmented” sounds reassuring, but what counts as critical, and what segmented means in practice, requires technical interpretation. Expert review catches these cases.

Limit 3: Mapping is not the same as compliance

Finding a document that relates to a requirement does not prove the requirement is met. A policy may exist while the practice does not. Assessments must test whether controls operate as described.

Limit 4: Sensitive information needs careful handling

Industrial documentation often includes network layouts, configurations, and vendor details that an adversary would value. Any AI-assisted process must handle that data with strict access control, clear data governance, and a defined approach to confidentiality. Ask about this before you share anything.

Limit 5: Over-reliance creates false comfort

The most dangerous outcome is a polished report that nobody challenged. Automation should make review sharper, not optional.

What a Strong AI-Assisted Assessment Looks Like in Practice

To make this concrete, consider a typical scenario. A mid-sized manufacturer operates four plants and wants to understand how well each aligns with IEC 62443 before a major customer audit. Previously, a project like this meant separate teams, separate spreadsheets, and a report months later.

With an AI-assisted approach, the process looks different:

  1. Scope and context are agreed first. Experts define which systems, zones, and requirements are in scope, and which security levels are the target.

  2. Evidence is gathered once. Documentation from each plant is collected into a single, organized set.

  3. AI performs the first pass. It reads the material, proposes requirement mappings, links evidence to assets and zones, and highlights potential gaps.

  4. Experts review everything that matters. They confirm, correct, or reject each proposed link, ask for missing evidence, and note where documents and reality disagree.

  5. Operational validation follows. Interviews, site walkthroughs, and technical checks confirm whether controls work as written.

  6. Findings are prioritized by real risk. Safety, production impact, and exposure drive the order of remediation, not just the number of gaps.

  7. The baseline is kept alive. When a plant changes, the team updates the evidence and re-runs the analysis instead of starting over.

The outcome is not just a report. It is a living picture of where the organization stands and where to invest next.

Practical Recommendations for OT Security Leaders

Whether you work with Shieldworkz or run assessments internally, these practices will help you get real value from AI-assisted IEC 62443 work.

Start with a clear scope and target

Decide which plants, systems, and security levels matter most. Trying to assess everything at once is how projects stall. Begin with the processes where a failure would hurt people, production, or the public.

Clean up your evidence before you start

  • A surprising amount of assessment pain comes from poor document hygiene. Before the project begins:

  • Confirm that network diagrams reflect the current plant

  • Reconcile asset inventories across engineering, IT, and operations

  • Collect the latest versions of security policies and procedures

  • Gather vendor access arrangements and maintenance agreements

  • Locate recent patch, backup, and incident response records

Treat every AI finding as a hypothesis

Require a named expert to confirm or reject every finding before it enters a report. Build that expectation into your process and your contracts.

Insist on traceability

Every finding should link back to its source evidence and the requirement it relates to. If you cannot see the reasoning, you cannot defend the result.

Pair documents with the plant floor

Plan time for interviews with operators, maintenance staff, and engineers. They know which procedures are followed and which are quietly ignored.

Prioritize by consequence, not by count

A single gap in remote access to a safety-related system may deserve more urgency than twenty minor documentation gaps. Rank remediation by process impact, safety, and likelihood.

Reassess after meaningful change

Define triggers for reassessment: a new vendor, a network redesign, a controller upgrade, an acquisition, or a significant incident. Make it routine rather than exceptional.

Protect the assessment data itself

Treat your assessment evidence as sensitive. Limit access, define retention rules, and make sure any partner handling it can explain how it is protected.

Recommendation

Common mistake it prevents

Clear scope and target security level

Projects that sprawl and never finish

Clean evidence before starting

Findings based on outdated drawings

Expert review of every finding

Confident-looking reports nobody challenged

Traceability to sources

Results that cannot be defended to auditors

Site validation

Gaps between written policy and daily practice

Consequence-based prioritization

Fixing easy items while serious risks remain

Triggered reassessment

Reports that go stale within months

Questions Decision-Makers Should Ask Any Assessment Provider

Before you commit to an AI-assisted assessment, use these questions to test depth and honesty:

  • Who reviews and signs off on every finding, and what is their OT experience?

  • Can we see the source evidence behind each result?

  • How is our documentation stored, protected, and deleted after the project?

  • How do you handle evidence that is missing or contradictory?

  • What operational validation happens beyond document review?

  • How easily can we reassess after a major plant change?

  • How are findings prioritized against safety and production impact?

A provider that answers these clearly and without hedging is likely to deliver something you can rely on.

Why This Matters for Different Roles

For CISOs and OT security leaders: you gain a defensible, repeatable view of posture that supports board reporting, insurance conversations, and customer assurance.

For plant managers and operations leaders: you get findings expressed in terms of process impact, with less disruption to production teams during the assessment itself.

For ICS engineers: you spend less time answering the same documentation questions and more time on technical validation and remediation design.

For compliance and risk teams: you get traceable, consistent records that make audits less stressful.

For energy, utility, and critical infrastructure operators: you can keep pace with evolving regulation and customer expectations without building a large internal assessment team.

How Shieldworkz Supports Organizations

Shieldworkz focuses exclusively on the security of industrial and critical infrastructure environments. Our teams combine OT engineering experience with cybersecurity expertise, so recommendations make sense on the plant floor as well as in the boardroom. Through OThello Assess and our wider advisory services, we help organizations:

  • Scope IEC 62443 assessments around the systems, zones, and security levels that matter most to safety, production, and compliance

  • Analyze evidence efficiently with AI-powered document processing that reduces repetitive administrative work

  • Map requirements to evidence with clear references so every finding can be traced and explained

  • Identify relevant assets and security context so gaps connect to real equipment, networks, and processes

  • Surface potential gaps for expert review, with experienced OT security professionals validating every conclusion

  • Validate operational reality through interviews, walkthroughs, and technical checks that go beyond documentation

  • Prioritize remediation based on safety, operational impact, and exposure rather than raw gap counts

  • Support zone and conduit design and segmentation improvements aligned with IEC 62443-3-2 and 62443-3-3

  • Strengthen security programs across policy, supplier management, remote access, monitoring, and incident response

  • Enable regular reassessment so your security baseline stays current as your plants evolve

  • Prepare for audits and customer reviews with consistent, well-documented evidence and findings

Our approach is consultative. We start by understanding your operations, your risk tolerance, and your obligations, and we shape the work around them. We do not believe in handing over a thick report and walking away. We believe in leaving your team with a clearer picture, a prioritized plan, and the confidence to act on it.

Looking Ahead: The Future of IEC 62443 Assessment

AI will keep getting better at reading, matching, and summarizing. Over time, expect assessments to become more continuous, with evidence refreshed as systems change and gaps flagged closer to the moment they appear. Expect customers, regulators, and insurers to ask for more frequent proof of security posture rather than a single certificate on the wall.

What will not change is the need for people who understand industrial processes. The plants that benefit most will be those that treat AI as a capable assistant and keep their experts firmly in charge of risk.

Conclusion

IEC 62443 gives industrial organizations a proven way to structure security. The difficulty has never been the standard, it has been the effort required to apply it often enough and consistently enough to matter. Real incidents, from power grid attacks to pipeline shutdowns to water treatment tampering, keep demonstrating what is at stake when segmentation, access control, monitoring, and response are not examined honestly.

AI-assisted assessment changes the economics of that examination. By handling evidence analysis, requirement mapping, asset and context identification, and early gap detection, it clears away the repetitive work that slows projects down. The benefits are practical: faster evidence processing, more consistent results, better traceability, and the freedom to reassess as your environment changes. The limits are just as real, which is why human control over risk decisions and operational validation must stay at the center.

If your organization is planning an IEC 62443 assessment, preparing for an audit, or simply wants to know where your biggest industrial security gaps sit today, the best next step is a conversation with people who have done this in real plants.

Book a Free Consultation with Our Experts

Whether you are starting your first IEC 62443 assessment or looking to make your current process faster and more reliable, the Shieldworkz team is ready to talk. In a no-obligation consultation, our OT security specialists will listen to your goals, review where you are today, and outline practical next steps, including how OThello Assess could fit your environment.

Book a Free Consultation with Our Experts

Share a few details about your facilities and priorities, and we will connect you with an expert who understands your industry.

Additional resources  

A downloadable report on the Stryker cyber incident here  
Removable media scan solution vendor evaluation and selection checklist here  
IEC 62443-based OT/ICS risk assessment checklist for the food and beverage manufacturing sector here 
IEC 62443-based remediation guides here

احصل على تحديثات أسبوعية

الموارد والأخبار

تعرف على كيفية معالجة حلولنا الرائدة في مجال أمن تكنولوجيا التشغيل (OT) للتحديات الأمنية الحيوية

قد تود أيضًا

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.

BG image

ابدأ الآن

عزز موقفك الأمني لنظام CPS

تواصل مع خبرائنا في أمن CPS للحصول على استشارة مجانية.