17 Aug 2026 · 6 min read
A conduit is not a cable
security · scada
Somebody has handed you IEC 62443 and asked whether the plant complies. You have done the sensible thing: printed the network diagram, and started drawing boxes around parts of it.
That is the first wrong turn, and it is not your fault. It comes from one word.
The word
In everyday use a conduit is a physical thing — a duct, a trunking run, the tube the cable goes through. Every instinct an engineer has says a conduit is where the wires live.
In this standard it is not that at all. A conduit is a logical grouping of the communications between two zones that share the same security requirements.
Which means one conduit can be three cables, a VLAN, and a radio link all at once, if those carry the same traffic between the same two areas and need protecting the same way. And a single fibre can carry several different conduits, because what is travelling through it belongs to different conversations with different needs.
Once you accept that, the network diagram stops being the right piece of paper. The network diagram shows you cables and switches. The standard is asking about conversations and consequences, and those two pictures do not line up.
The other word
The same problem happens with "zone", and it matters more.
A zone is a grouping of assets by risk — by what happens if that group is compromised. Not by which switch they plug into, not by which building they are in, not by which VLAN somebody assigned in 2018.
That has a consequence people find genuinely uncomfortable: two devices sitting on the same switch, in the same panel, can belong in two different zones. And a single zone can span three buildings. If your zones happen to line up neatly with your network segments, that is worth a second look — it may mean you drew the segments and called them zones.
The order almost everyone reverses
The standard lays the work out as a sequence. Simplified, it runs: identify what system you are actually talking about, do an initial risk assessment, and then partition that system into zones and conduits.
Zones come third. They are an output of the risk assessment, not an input to it.
Nearly every plant I have seen does it the other way round — draws zones first, usually copied from a reference diagram, then works backwards to justify them. That is why so many zone drawings feel arbitrary when you interrogate them: they were not derived from anything. Nobody can tell you what would happen if a particular zone were compromised, because that question was never asked. It was supposed to be asked first.
If you want a fast test of whether your zone drawing is real, pick any zone and ask what the consequence of losing it would be. If the room goes quiet, the drawing is decoration.
The four zones you probably do not have
This is the part worth walking your own plant with, because the standard is specific and most sites fail all four.
Safety gets its own zone. Safety-related equipment is supposed to be grouped separately from everything that is not safety-related. And there is a sting in the tail: if you cannot separate them, then the entire zone is treated as safety-related — with everything that implies for how it must be protected. That rule quietly converts "we never got round to splitting it" into a much larger obligation.
Wireless gets its own zone. Anything wireless is expected to sit in one or more zones separate from the wired equipment. Not because radio is inherently untrustworthy, but because its exposure is different and grouping by risk means grouping things whose exposure matches.
Temporarily connected equipment gets its own zone. The maintenance laptop. The contractor's portable analyser. The USB stick that carries the firmware update. The standard expects devices that connect temporarily to be treated as their own grouping, because a device that comes and goes has a different risk profile from one that is bolted to the wall.
Almost nobody does this. The maintenance laptop plugs into whatever socket is closest, and it has been doing so for years.
Anything connected from outside gets its own zone. Equipment permitted to reach into the plant from external networks is supposed to be its own zone with its own requirements — vendor remote support most obviously.
Four questions, then. Do you have a safety zone? A wireless zone? A zone for things that plug in temporarily? A zone for whoever dials in from outside? Most plants answer no four times, and that is a more useful compliance finding than any amount of drawing.
One number for the plant is the wrong shape
The last common mistake is to treat security level as a single grade for the site — "we're aiming for level 2".
The standard sets a target level per zone and per conduit. That is the whole point of splitting things up: the zone containing your safety system and the zone containing the canteen printer should not be held to the same target, and a single plant-wide number means either overspending everywhere or underspending where it matters.
There is a related trap that catches people at procurement. The level a product is capable of and the level you have actually achieved in your installation are different numbers. Where the capability is lower than the target, that gap is your work list. Where the capability is high but the feature was never switched on, the target is not met either, and the certificate on the datasheet will not say so. That is a whole argument of its own, and I have written it here.
What to do on Monday
None of this requires buying anything.
Put the network diagram away and get a different sheet. You are drawing groups of consequence, not groups of cable.
Ask the consequence question for each group. If nobody can answer it, you have found the real gap, and it is upstream of any firewall.
Walk the four groupings. Safety, wireless, temporarily connected, externally connected. Write down which ones exist as real, separated groupings today. The honest answer is the deliverable.
Set a target per group, not per plant, and note where what you have falls short of what you want.
And if you want to know what your plant is actually doing rather than what the drawing says, the only reliable way is to watch the traffic for a day and write it down — which is a different piece of work, and one I measured on my own estate with results that disagreed with the textbook in twenty-two places.
The word "conduit" has probably cost this industry more wasted drawing hours than any other term in the standard. It does not mean the tube. It means the conversation.
What a packet capture can and cannot prove about these requirements — four of the seven, as it turns out — is measured in the protocol scorecard.
A zone you can actually enforce, rather than draw: overlay networks label the machine instead of the cable, and refuse a policy change that would let the wrong label through — the tunnel was never the hard part.
What belongs inside each zone once it is drawn, and how the work differs for an isolated plant and a connected one: one firewall is not segmentation.
A conduit that has to cross a wide-area network to reach a remote site, held as a designed path at every site rather than whatever the routing table allowed: when did your backup link last carry the plant?
Keep reading
Newsletter
New essays, by email.
SCADA, cloud, AI, and the plant floor — a short email when something new is published. No noise, unsubscribe anytime.


