← Resources

May 31, 2026 · KOPENS

OT Cybersecurity — How IEC 62443 and NIS2 Are Reshaping Manufacturing

Manufacturing accounted for more than two-thirds of industrial ransomware victims in 2025. This article maps the OT cybersecurity landscape being reshaped by IEC 62443 and NIS2.

"Manufacturing accounted for more than two-thirds of industrial ransomware victims in 2025. OT security is no longer an appendage of the IT department." — Dragos, 2026 OT Year in Review

In 2025, industrial cyber threats went a level deeper. The ransomware groups Dragos tracked in its 2026 Year in Review numbered 119, up 49% from 80 the year before, and the industrial organizations they targeted reached 3,300. Manufacturing accounted for more than two-thirds of them. Over the same period, the SANS State of ICS/OT Security 2025 survey reported that 55% of respondents said their OT security budgets had grown over the past two years — yet the share of organizations reporting insufficient OT network visibility still stood at 45%. Investment is up, but the fundamentals are not yet in place.

Against this backdrop, two frameworks are establishing themselves as the de facto standard on the manufacturing floor. One is ISA/IEC 62443 — the international standard for industrial automation and control system (IACS) security; the other is the European Union's NIS2 Directive — a legal mandate that enforces cyber resilience across 18 critical sectors, including manufacturing. This article looks at how the two standards interlock to change OT operations in Korean manufacturing, and what plants should tackle first.

Industrial control system security

▲ Industrial control system (ICS) security is no longer an appendage of IT security.


1. Why IEC 62443, and Why Now

IEC 62443 is not a single specification but a series of 14 standards. It spans every layer, from policy (Part 2-1) to system design (Part 3-3), component requirements (Part 4-2), and the secure development lifecycle (Part 4-1). At its core is the Zone and Conduit model — a way of thinking that divides the plant into physical and logical zones and identifies and controls the communication channels between them, so that the compromise of a single sensor cannot propagate across an entire line.

Each zone is assigned a Security Level, from SL-1 to SL-4, according to its threat level. If the goal is preventing simple mishaps, SL-2 is the benchmark; blocking deliberate attackers calls for SL-3; and defending against nation-state-grade adversaries calls for SL-4. By abandoning the unrealistic approach of "protecting every asset to the same level," this method enables risk-based investment — which makes it a particularly good fit for Korean manufacturing sites operating with limited OT security budgets.

  • Part 2-1 — Cybersecurity management system (CSMS): policy, roles, training, audit
  • Part 3-2 — Risk assessment and system design methodology
  • Part 3-3 — System requirements (FR 1-7) and SL mapping
  • Part 4-1 — Secure-by-Design development lifecycle (supplier side)
  • Part 4-2 — Technical requirements for PLC/HMI/network components

2. What NIS2 Means for Manufacturing Leaders

NIS2 (Directive (EU) 2022/2555) began transposition into member-state law in October 2024 and enters full enforcement in 2026. The biggest change is the expansion of scope from 7 to 18 sectors, bringing parts of manufacturing (machinery, automotive, electrical/electronics, medical devices) into scope as "Important entities." Nor is this irrelevant to Korean companies — manufacturers with subsidiaries, joint ventures, or major customers in the EU are effectively subject to indirect application through supply chain security obligations.

NIS2's core obligations come down to four things. First, initial incident reporting within 24 hours and a detailed report within 72 hours. Second, supply chain security — which naturally translates into a requirement that suppliers deliver IEC 62443-4-1/4-2 certified components. Third, direct executive accountability — board members can face personal sanctions when a cyber incident occurs. Fourth, regular risk assessments and business continuity planning. This is why EU consulting firms such as ST2 advise in their 2026 NIS2 guidance: "Don't try to do everything at once — first define the System under Consideration (SuC) using IEC 62443-2-1."

Factory OT network

▲ NIS2 has elevated visibility, segmentation, and incident reporting in manufacturing OT networks into legal obligations.

3. What Industrial Threats Actually Looked Like in 2025

Cross-referencing the Dragos 2026 Year in Review with the SANS State of ICS/OT Security 2025 brings the threat picture into focus. In ransomware incidents, the average dwell time in OT environments was 42 days — but organizations with strong OT visibility contained incidents in an average of just 5 days. A single visibility gap is the difference between an incident measured in single-digit days and one that drags on for a month and a half.

Threat actors have evolved as well. Dragos currently tracks 26 OT-focused threat groups, with three — AZURITE, SYLVANITE, and PYROXENE — newly identified in 2025 alone. Of particular concern is "control loop mapping" — attempts to map the control loops themselves in order to bypass safety interlocks. This goes beyond mere data theft and aims at physical damage, which puts it in a different dimension. According to European industrial analyses, 60% of OT vulnerabilities cannot be fixed with a simple software patch — they are inherent in the aging hardware architecture itself.

  • 119 — ransomware groups targeting industrial organizations in 2025 (vs. 80 the year before)
  • 3,300 — industrial organizations hit over the same period
  • More than two-thirds — manufacturing's share of the victims
  • 45% — respondents reporting insufficient OT visibility (SANS 2025)
  • Roughly $329.5 billion — potential global losses from OT cyber incidents (Dragos 2025 Financial Risk Report)

4. The Starting Point for Korean Manufacturing — Visibility and Segmentation

In the SANS 2025 survey, the top investment priority respondents named for 2025 was asset inventory and visibility (50%), and it held the top spot in the 2026-2027 outlook as well, at 54%. Korean manufacturing sites need to start from the same place. Few plants can immediately answer exactly which PLC, HMI, DCS, and SCADA assets — accumulated over decades — are running, where, and on which firmware version. Without visibility, you cannot draw IEC 62443 zones, and the NIS2 24-hour incident reporting clock never even starts.

Second comes segmentation. Layered separation along the Purdue model (Levels 0-5), unidirectional gateways (data diodes) at the OT-IT boundary, and Just-In-Time privilege management for remote access form the basic skeleton. The NIS2 remote access guide HMS Networks published in May 2025 recommends that "the fastest way to bring third-party maintenance access in line with NIS2 is per-session approval and full-session recording." In other words, it is time to retire the practice of contractor engineers plugging laptops straight into PLCs.

5. Case Study — How European Automotive Suppliers Sequence NIS2 Preparation

According to a NIS2 industrial white paper published by Cisco, Tier-1 automotive suppliers have effectively standardized the following sequence since 2025: (1) establish a site-level CSMS based on IEC 62443-2-1 → (2) map zones/conduits and assign SLs → (3) deploy an industrial visibility platform such as Cisco Cyber Vision, Claroty, or Nozomi → (4) implement microsegmentation based on Identity Services Engine → (5) validate incident response playbooks (tabletop exercises). The biggest bottleneck reported in this process was not technology but reaching agreement on roles and responsibilities among OT operations, IT security, and quality departments. Meeting NIS2's 24-hour reporting clock requires a governance line in which the site manager holds incident-declaration authority while the corporate CISO is notified immediately.

How PlantPulse Answers

KOPENS PlantPulse is an Industrial DataOps platform, but it builds in the security foundations of IEC 62443/NIS2 from day one. Its 200+ industrial protocol connectors all default to read-only passive collection, and Zone and Conduit metadata can be attached directly on top of the ISA-95 asset model. Because asset inventory, communication topology, and access logs converge in one place, the primary data needed for IEC 62443 Part 3-2 risk assessments and NIS2 incident reporting can be extracted without building anything separate.

The edge-cloud hybrid architecture is also a deliberate choice from a security standpoint. Sensitive control data stays at the edge, while only statistics, time series, and events flow upward according to policy. AI/ML model inference also runs at the edge, minimizing the externally exposed surface. PlantPulse's governance layer keeps tamper-proof logs of who viewed or changed which tags on which assets, and when — naturally satisfying the auditability NIS2 demands.

Closing

IEC 62443 and NIS2 are not separate tracks. The former answers the "How" — how to design and operate OT securely — while the latter asks the "Must" — what you are required to prove. The most realistic starting point for satisfying both standards converges on a single question: "Do we truly know our plant's OT assets?" If you cannot answer it, every other control ultimately remains policy on paper.

2026 is the year NIS2 enforcement gets fully under way and KISA accelerates its overhaul of OT security policy (KISA Insight 2025 Vol.05). If Korean manufacturing executives are redrawing this quarter's priorities, the first item should be OT asset inventory and network segmentation. The standards merely provide the language for the step after that. (References: Dragos 2026 OT Year in Review / 2025 Financial Risk Report; SANS State of ICS/OT Security 2025; ISA IEC 62443 series; EU NIS2 Directive 2022/2555; Cisco NIS2 Industrial White Paper; HMS Networks NIS2 Remote Access Guide 2025-05; KISA Insight 2025 Vol.05.)

© KOPENS — Industrial DataOps & PlantPulse Platform