17 Aug 2026 · 6 min read

A conduit is not a cable

security · scada

Somebody has handed you IEC 62443 and asked whether the plant complies. You have done the sensible thing: printed the network diagram, and started drawing boxes around parts of it.

That is the first wrong turn, and it is not your fault. It comes from one word.

The word

In everyday use a conduit is a physical thing — a duct, a trunking run, the tube the cable goes through. Every instinct an engineer has says a conduit is where the wires live.

In this standard it is not that at all. A conduit is a logical grouping of the communications between two zones that share the same security requirements.

Which means one conduit can be three cables, a VLAN, and a radio link all at once, if those carry the same traffic between the same two areas and need protecting the same way. And a single fibre can carry several different conduits, because what is travelling through it belongs to different conversations with different needs.

ONE CONDUIT
everything travelling between these two areas that needs protecting the same way
fibre to the pump housecopper to the panela VLAN on the switcha radio link to the tanks
swap any item inside, and the conduit is still the same conduit
The outer boundary is the thing the standard names. What is inside it is whatever happens to carry that traffic today, and it can change without the boundary changing.

Once you accept that, the network diagram stops being the right piece of paper. The network diagram shows you cables and switches. The standard is asking about conversations and consequences, and those two pictures do not line up.

The other word

The same problem happens with "zone", and it matters more.

A zone is a grouping of assets by risk — by what happens if that group is compromised. Not by which switch they plug into, not by which building they are in, not by which VLAN somebody assigned in 2018.

That has a consequence people find genuinely uncomfortable: two devices sitting on the same switch, in the same panel, can belong in two different zones. And a single zone can span three buildings. If your zones happen to line up neatly with your network segments, that is worth a second look — it may mean you drew the segments and called them zones.

SORTED BY WHAT IT PLUGS INTO
switch A
safety shutdown
pump drive
canteen display
switch B
tank level
SORTED BY WHAT HAPPENS IF YOU LOSE IT
stop the process
safety shutdown
run the process
pump drive
tank level
nobody gets hurt
canteen display
The same four items, sorted twice. Grouping by what a thing plugs into and grouping by what happens if you lose it produce different piles — which is why the network diagram is the wrong sheet of paper.

The order almost everyone reverses

The standard lays the work out as a sequence. Simplified, it runs: identify what system you are actually talking about, do an initial risk assessment, and then partition that system into zones and conduits.

Zones come third. They are an output of the risk assessment, not an input to it.

1
decide what system you mean
2
assess the risk
3
draw the zones and conduits
where most people startskip the middle and there is nothing the drawing can be justified against
The grouping is an output of the assessment. Beginning at the third step is what produces zone drawings nobody can justify when questioned.

Nearly every plant I have seen does it the other way round — draws zones first, usually copied from a reference diagram, then works backwards to justify them. That is why so many zone drawings feel arbitrary when you interrogate them: they were not derived from anything. Nobody can tell you what would happen if a particular zone were compromised, because that question was never asked. It was supposed to be asked first.

If you want a fast test of whether your zone drawing is real, pick any zone and ask what the consequence of losing it would be. If the room goes quiet, the drawing is decoration.

The four zones you probably do not have

This is the part worth walking your own plant with, because the standard is specific and most sites fail all four.

Safety gets its own zone. Safety-related equipment is supposed to be grouped separately from everything that is not safety-related. And there is a sting in the tail: if you cannot separate them, then the entire zone is treated as safety-related — with everything that implies for how it must be protected. That rule quietly converts "we never got round to splitting it" into a much larger obligation.

Wireless gets its own zone. Anything wireless is expected to sit in one or more zones separate from the wired equipment. Not because radio is inherently untrustworthy, but because its exposure is different and grouping by risk means grouping things whose exposure matches.

Temporarily connected equipment gets its own zone. The maintenance laptop. The contractor's portable analyser. The USB stick that carries the firmware update. The standard expects devices that connect temporarily to be treated as their own grouping, because a device that comes and goes has a different risk profile from one that is bolted to the wall.

Almost nobody does this. The maintenance laptop plugs into whatever socket is closest, and it has been doing so for years.

Anything connected from outside gets its own zone. Equipment permitted to reach into the plant from external networks is supposed to be its own zone with its own requirements — vendor remote support most obviously.

safety equipment
fail to separate it and the whole zone becomes safety-related
◻ does this exist here?
anything wireless
different exposure, so it groups separately from wired kit
◻ does this exist here?
things that plug in temporarily
the maintenance laptop, the portable analyser, the USB stick
◻ does this exist here?
anything reaching in from outside
vendor remote support, and whoever else has a way in
◻ does this exist here?
Four groupings the standard expects to exist. Walk the plant and mark which are genuinely separated today — four honest blanks is a more useful finding than a tidy drawing.

Four questions, then. Do you have a safety zone? A wireless zone? A zone for things that plug in temporarily? A zone for whoever dials in from outside? Most plants answer no four times, and that is a more useful compliance finding than any amount of drawing.

One number for the plant is the wrong shape

The last common mistake is to treat security level as a single grade for the site — "we're aiming for level 2".

The standard sets a target level per zone and per conduit. That is the whole point of splitting things up: the zone containing your safety system and the zone containing the canteen printer should not be held to the same target, and a single plant-wide number means either overspending everywhere or underspending where it matters.

target 4safety shutdowntarget 3process controltarget 2site monitoringtarget 1canteen displayone grade for the whole siteeverything under the dashed line is overspend; everything above it is a gap
A single site-wide grade forces the same spend on the shutdown system and the canteen screen. Setting it per group is what makes splitting things up worth doing at all.

There is a related trap that catches people at procurement. The level a product is capable of and the level you have actually achieved in your installation are different numbers. Where the capability is lower than the target, that gap is your work list. Where the capability is high but the feature was never switched on, the target is not met either, and the certificate on the datasheet will not say so. That is a whole argument of its own, and I have written it here.

4
what the box could do
the protections it ships with · printed on the datasheet
2
what it is doing
the protections somebody switched on · only your plant knows
Two different questions that get written down as one number. The certificate answers the left dial; only your own installation answers the right one, and the gap between them is the work list.

What to do on Monday

None of this requires buying anything.

Put the network diagram away and get a different sheet. You are drawing groups of consequence, not groups of cable.

Ask the consequence question for each group. If nobody can answer it, you have found the real gap, and it is upstream of any firewall.

Walk the four groupings. Safety, wireless, temporarily connected, externally connected. Write down which ones exist as real, separated groupings today. The honest answer is the deliverable.

Set a target per group, not per plant, and note where what you have falls short of what you want.

And if you want to know what your plant is actually doing rather than what the drawing says, the only reliable way is to watch the traffic for a day and write it down — which is a different piece of work, and one I measured on my own estate with results that disagreed with the textbook in twenty-two places.

The word "conduit" has probably cost this industry more wasted drawing hours than any other term in the standard. It does not mean the tube. It means the conversation.

What a packet capture can and cannot prove about these requirements — four of the seven, as it turns out — is measured in the protocol scorecard.

A zone you can actually enforce, rather than draw: overlay networks label the machine instead of the cable, and refuse a policy change that would let the wrong label through — the tunnel was never the hard part.

What belongs inside each zone once it is drawn, and how the work differs for an isolated plant and a connected one: one firewall is not segmentation.

A conduit that has to cross a wide-area network to reach a remote site, held as a designed path at every site rather than whatever the routing table allowed: when did your backup link last carry the plant?

Keep reading

Newsletter

New essays, by email.

SCADA, cloud, AI, and the plant floor — a short email when something new is published. No noise, unsubscribe anytime.