Practical Implementation of IEC 62443 in Cyber-Physical Systems: Bridging Compliance and Real-World
About This Session
This session addresses the critical challenge of translating IEC 62443 cybersecurity requirements into practical, deployable controls within real-world cyber-physical systems. It begins by examining the gap between compliance frameworks and implementation realities, particularly in OT environments where constraints such as system availability, legacy devices, and safety requirements complicate security integration. The talk then introduces an architecture-centric approach, showing how IEC 62443 concepts like zones and conduits can be mapped to actual OT system designs. Key implementation areas are explored in depth, including access control models, secure remote access through jump host architectures, network segmentation strategies, PKI-based trust establishment for OT devices, and effective logging and monitoring practices aligned with audit expectations. Drawing from field experience, the session highlights common failure points observed during system integration, FAT/SAT testing, and audits, such as misconfigured access controls, ineffective segmentation, and incomplete certificate lifecycle management. It concludes with practical guidance on developing repeatable validation procedures and generating audit-ready evidence, enabling organizations to move beyond theoretical compliance and achieve secure, resilient, and verifiable OT deployments in critical infrastructure environments.
Speaker
Shwetha GC
OT Cybersecurity Lead - Siemens Energy
Shwetha Gowdanakatte is an OT cybersecurity professional specializing in securing cyber-physical systems and critical infrastructure. She has hands-on experience implementing IEC 62443 controls in digital substations, focusing on access control, PKI, network segmentation, and remote access security, threat modeling, risk assessment including red and blue team activities . She has led lab cybersecurity certification efforts and develops audit-ready security solutions in operational environments.
She is currently a Ph.D. candidate researching AI-driven threat modeling and access control in cyber-physical systems, with publications at ACSAC, IEEE and CIGRE. Her work bridges theory and practice, enabling organizations to operationalize cybersecurity standards effectively.
She is currently a Ph.D. candidate researching AI-driven threat modeling and access control in cyber-physical systems, with publications at ACSAC, IEEE and CIGRE. Her work bridges theory and practice, enabling organizations to operationalize cybersecurity standards effectively.
