← Back to the lesson Tip: print to PDF, then tape it above the engineering workstation.
🛡️ CODESYS Academy · Security Track

OT Security Field Kit

A practical, IEC 62443-aligned hardening checklist, the 10 commandments, and a one-page breach runbook. Walk the checklist for any control network — every unchecked box is a door an attacker would happily use.

🧱 1 · Network & segmentation 62443 · ZONES & CONDUITS

🔐 2 · Remote access & identity 62443 · IAC

👁️ 3 · Monitoring & detection 62443 · TRE

💾 4 · Endpoints & removable media 62443 · SI

🛟 5 · Safety & resilience 62443 · RA

🧑‍🏭 6 · People & process 62443 · MATURITY

📜 The 10 OT-security commandments

  1. Thou shalt not expose an HMI, PLC or SCADA box to the public internet.
  2. Thou shalt change the default password. 1111 is an invitation.
  3. Thou shalt segment IT from OT with a real DMZ — no flat networks.
  4. Thou shalt put MFA on every remote-access path; kill shared logins.
  5. Thou shalt patch the edge even when thou canst not patch the PLC.
  6. Thou shalt keep the Safety System on its own isolated island.
  7. Thou shalt monitor OT traffic; a new Modbus command is a scream.
  8. Thou shalt control USB drives. The air gap is a vibe, not a control.
  9. Thou shalt keep offline, tested backups and an OT incident plan.
  10. Thou shalt assume breach — minimise what an intruder can do once in.

🚨 "We think we're breached" — first 6 moves

⚠️ This kit is an awareness and hygiene aid, not a substitute for a formal IEC 62443 risk assessment, your site's safety case, or qualified incident-response support. Adapt every item to your plant's risk and regulatory context.
CODESYS Academy · Security Track · OT Security Field Kit · checklist mapped loosely to IEC 62443 foundational requirements (FR1–FR7) for orientation only.