A rolling mill's PLC doesn't get patched on Patch Tuesday, and a blast furnace control loop can't just reboot mid-shift. OT cybersecurity has to protect uptime and safety first, data second, which is exactly the opposite priority order of a typical IT security program. Sign up to see how Oxmaint keeps OT asset inventory, firmware versions, and vendor access records on one system your reliability and security teams both use.
6
Core functions in NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover
SL1-SL4
Security Levels in IEC 62443, defining the threat actor capability each zone must withstand
4-8 wks
Time for a baseline gap assessment against IEC 62443-3-3 at a medium-complexity plant
12-24 mo
Typical time to full compliance from a low-maturity security baseline
Two Frameworks, Not One Choice
NIST CSF tells an organization what security outcomes to achieve; IEC 62443 tells the plant floor how to achieve them through zones, conduits, and Security Levels. Most mature OT security programs run both together, using CSF for governance and 62443 for the technical architecture underneath it.
The Six Functions of NIST CSF 2.0 on the Plant Floor
| Function |
What It Looks Like in a Steel Plant |
| Govern |
Executive ownership of OT risk, not just an IT security policy applied by default |
| Identify |
A complete inventory of PLCs, HMIs, drives, and sensors across the caster and mill lines |
| Protect |
Zone and conduit segmentation, access control, and firmware version management |
| Detect |
Monitoring conduits like vendor remote access and historian data flows for anomalies |
| Respond |
An incident plan that isolates a zone without tripping a safety shutdown unnecessarily |
| Recover |
Restoring control systems to a known-good state without re-introducing the same gap |
Your Asset Register Is Half Your Identify Function
Oxmaint already tracks every controller, drive, and sensor as a maintained asset, which means the OT inventory NIST CSF's Identify function demands is largely built the day you start using it. Sign up for a free trial to see your asset register from a security lens, or book a demo and we'll map it against your zones.
IEC 62443: Zones, Conduits, and Security Levels
| Concept |
Steel Plant Application |
| Zone |
A group of assets sharing security needs, such as all rolling mill PLCs on one segment |
| Conduit |
A documented, monitored path between zones, like a vendor connection or historian feed |
| Security Level (SL1-SL4) |
The threat capability a zone must resist, with SL2 as a common floor for operational zones |
IT Security Habits vs OT Security Reality
IT Security Habits
Patches applied on a routine cycle, rebooting systems as needed
Confidentiality treated as the top priority in most risk models
Undocumented laptops and vendor logins tolerated as a convenience
OT Security Reality
Patches tested and scheduled around planned production downtime
Availability and safety take priority, confidentiality comes third
Every conduit, including engineering laptops, documented and monitored explicitly
How Oxmaint Supports OT Security Readiness
Oxmaint keeps a living record of every controller, drive, and instrument, including firmware version and last-touched date, which is exactly the asset visibility both NIST CSF's Identify function and IEC 62443's zone model require. Vendor access events logged as work orders create the audit trail a conduit review needs. Book a demo to see it mapped against your own control system inventory.
Frequently Asked Questions
Q
Should a steel plant pick NIST CSF or IEC 62443?
Most mature programs use both rather than choosing one. NIST CSF works well as the governance layer that gives leadership a structured view of maturity, while IEC 62443 supplies the technical zone, conduit, and Security Level architecture on the plant floor.
Q
What's the most commonly overlooked conduit in a steel plant?
Vendor remote access connections, historian data flows, and engineering laptops are frequently left undocumented, and these are exactly the paths attacks tend to propagate through once inside a segmented network.
Q
Can a mid-size steel plant realistically implement IEC 62443?
Yes, the standard is designed to scale. A facility with an existing NIST-aligned or similar governance program typically moves faster, since the foundational risk assessment and documentation work is already in place.
Build Your OT Asset Inventory Before You Build Your Zones
Oxmaint gives steel plant teams a living OT asset register, firmware and vendor access tracking, and work order history that supports both NIST CSF and IEC 62443 readiness. Sign up for a free trial to see your own control system inventory, or book a demo and we'll walk through it against your plant's zones.