site-logo
site-logo
site-logo
The CEA Cyber Security in Power Sector Regulations-2026

Regulatory Playbook

IEC 61511 & OT Cybersecurity Checklist

Where Functional Safety Meets Cybersecurity

Functional safety and cybersecurity are no longer separable disciplines in the process industries. IEC 61511 says so explicitly. IEC 61511-1:2016 (Edition 2), the international functional safety standard for Safety Instrumented Systems in the process industry sector, introduced a binding requirement, widely cited as Clause 8.2.4, that a security risk assessment be carried out to identify the security vulnerabilities of the SIS, alongside a related requirement, Clause 11.2.12, that SIS design provide resilience against the risks that assessment identifies. This closed a gap that had existed since the first edition in 2003, which addressed security only implicitly.

What this means in practice is the argument this checklist is built around: a cybersecurity weakness in the Basic Process Control System, the engineering workstation, the SIS communication path, or the vendor remote-access channel is not purely an IT or network problem. It is a potential contributor to a hazardous event, because it can degrade, defeat, or falsely trigger a Safety Instrumented Function in ways the original hazard and risk assessment did not, and since 2016, was not permitted to, ignore.

Five things this checklist argues every OT CISO should already know:

SIS cybersecurity risk assessment is a documented compliance gap at many sites: many facilities still run a PHA/HAZOP and LOPA without an accompanying, documented cyber-related risk assessment covering the SIS and its interfaces, the single most common IEC 61511:2016 gap encountered in practice.

The SIS is not an isolated island by default: engineering workstations, historian links, asset management systems, and vendor remote-access paths routinely create connectivity between the SIS and less-trusted networks, even where the process design assumes independence.

Security controls can themselves create safety risk if untested against the SIS: an antivirus scan or an aggressive intrusion prevention system tuned for IT can degrade SIS availability or introduce nuisance trips if deployed without functional safety review.

Management of Change is the practical control point: because both functional safety and OT cybersecurity rely on formal change control, MOC is the fastest process to extend to capture cybersecurity-relevant SIS changes.

IEC 62443 and ISA-TR84.00.09 do the detailed work IEC 61511 asks for: IEC 61511 requires a security risk assessment; IEC 62443 and ISA-TR84.00.09 tell you how to structure and execute it, as one workflow, not two competing compliance tracks.

Shieldworkz built this checklist as a practitioner's bridge between the two disciplines, and it is explicit about its own boundary: IEC 61511 is a functional safety standard, not a cybersecurity standard. It does not define network segmentation, patch cadences, or monitoring requirements, that detail lives in IEC 62443. This checklist treats that boundary as non-negotiable throughout.

Why This Checklist Matters

Most OT cybersecurity guidance is written from the network-security side inward, and most functional safety guidance treats cybersecurity as someone else's problem. This checklist is built from the intersection outward, using four realistic, documented failure patterns to show exactly where that gap bites.

A shared engineering workstation quietly defeats layer independence: malware reaching a combined BPCS/SIS engineering laptop through a routine software update can invalidate the LOPA's independence assumption without touching the physical plant or SIF logic at all.

Unmanaged vendor remote access outlives its purpose: a standing, shared-credential remote-support path granted for a turnaround and never disabled becomes an external actor's route into the SIS-adjacent network months later, when the vendor's own infrastructure is compromised.

A falsified proof-test result masks a failed safety function: a maintenance-tooling integrity gap, not a sophisticated attack, can cause a SIF to show as compliant in every record while it has actually failed, with the gap invisible until a real hazardous demand occurs.

An aggressive IT security control causes a spurious trip: a corporate antivirus rollout deployed to a BPCS operator station without functional safety review can delay a time-critical response and trigger an entirely preventable shutdown, illustrating that the risk runs in both directions.

Each scenario in this checklist carries a specific, named set of controls that would have prevented it, cross-referenced to the relevant section of the practical concern areas this guide walks through: SIS communications, remote access, segmentation, patching, backup, malware, incident response, monitoring, supply chain, and proof-testing.

Why Downloading This Checklist Is Critical for Your Organization

If your site operates a Safety Instrumented System under IEC 61511, whether in oil and gas, chemicals, power generation, or any other process industry, you are already subject to the Clause 8.2.4 security risk assessment obligation, regardless of whether it has been formally scoped yet. Auditors and functional safety assessors are increasingly asking for it directly, and a PHA/HAZOP and LOPA without an accompanying documented cyber-related risk assessment is a compliance gap, not a stylistic choice.

Here's what this checklist puts in your hands:

A full IEC 61511 to OT cybersecurity crosswalk: mapping every safety lifecycle phase, from hazard and risk assessment through modification and Management of Change, to the specific cybersecurity activity and the IEC 62443 or ISA-TR84.00.09 guidance that provides the detailed method.

A practical, 12-area CISO checklist: covering governance, SIS design, network architecture, remote access, change management, patching, backup, malware, incident response, monitoring, supply chain, and proof-testing, rated by priority from real engagement experience.

An evidence and documentation checklist: so your team knows exactly what an auditor or functional safety assessor will expect to see, not just what control should conceptually exist.

Role-specific key questions: for process/instrumentation engineering, operations, maintenance/proof-test personnel, IT/OT network and security teams, and leadership, so every stakeholder in the safety-and-security conversation has their own entry point.

A three-phase roadmap: from 0-90 day visibility and governance actions through a 3-12 month integrated program build to an ongoing sustain-and-mature phase.

Key Takeaways From the Checklist

Clause 8.2.4 and 11.2.12 are the two clauses that matter most. A documented security risk assessment identifying SIS vulnerabilities, and a SIS design providing resilience against the risks that assessment identifies, are the checklist's central, binding obligations.

The risk runs in both directions. Cybersecurity weaknesses can degrade or defeat a safety function, but security controls deployed without functional safety review can just as easily cause a spurious trip or degrade SIS availability themselves.

IEC 61511 will not tell you how; IEC 62443 and ISA-TR84.00.09 will. Zone and conduit segmentation, security levels, and system requirements are IEC 62443's job; IEC 61511's job is only to require that the assessment happen and the design respond to it.

Management of Change is the fastest integration point available. Adding cybersecurity-trigger questions to an existing MOC workflow is a low-cost, immediate-effect action that most organisations can implement without building a parallel process.

Proof-test tooling is frequently out of scope, and shouldn't be. Test tools and their data paths to historians and maintenance systems are often added post-commissioning as productivity improvements and left outside the original segmentation design, exactly where a falsified or corrupted result can hide a failed safety function.

Shared engineering assets are the most common invisible failure point. A single combined BPCS/SIS engineering workstation can quietly invalidate a LOPA's independence assumption, a gap only a cybersecurity-aware risk assessment, not a purely process-focused HAZOP, will surface.

How Shieldworkz Supports Your IEC 61511 and OT Security Journey

Reading the crosswalk tells you what belongs where. Executing the joint safety-and-security program, especially closing the Clause 8.2.4 assessment gap most sites carry, is where Shieldworkz comes in.

OThello Assess: builds the SIS and OT asset inventory, hardware, firmware, network location, that underpins the security risk assessment and nearly every other control in this checklist.

OT network detection and response: delivers the passive monitoring across SIS zones and conduits this checklist's Phase 2 roadmap calls for, with escalation paths reaching both the SOC and process-safety on-call functions.

Joint tabletop exercises: scoped across cybersecurity, functional safety, and operations, exercising the OT/SIS-specific incident response annex this checklist recommends rather than a generic IT playbook.

Security risk assessment and crosswalk execution: structuring your Clause 8.2.4 assessment against an IEC 62443-3-2-style methodology, with a documented zone/conduit and conduit register your functional safety assessors and auditors will recognise.

Sites that engage us early aren't just closing a documentation gap. They're building the joint safety-and-security workflow this checklist argues should have existed since 2016, before an auditor, or a real hazardous demand, finds the gap first.

Download the Checklist

A cybersecurity weakness in your SIS is not a network problem waiting to be triaged. It's a hazardous-event contributor the standard has required you to assess since 2016.

Fill in the form to receive your free copy of the IEC 61511 and OT Cybersecurity checklist. You'll also have the option to book a no-obligation consultation with a Shieldworkz OT security expert, who can help you scope your Clause 8.2.4 security risk assessment and identify your highest-priority gaps across the safety-and-security lifecycle.


Schedule a Demo With Shieldworkz OT Security Experts

Download your copy today!

Strengthen SIS Cybersecurity Readiness.

Download the IEC 61511 SIS Cybersecurity Checklist to identify vulnerabilities and build audit-ready evidence.