top of page
  • Youtube
  • Facebook

Valve and Actuator Cybersecurity (IEC 62443)

Jun 18
5 min read

Updated: Aug 24

Introduction

Connected valve actuators, positioners, gateways, engineering tools and remote-maintenance paths can expand an industrial automation and control system (IACS) attack surface. Cybersecurity must therefore be engineered together with process safety, availability and deterministic control. This guide explains how IEC 62443 concepts apply to smart valve and actuator procurement and integration without treating a component certificate as proof that an entire plant is secure.

Why Valve and Actuator Cybersecurity Matters

Smart actuators may use Ethernet, fieldbus, HART, wireless or vendor-specific service interfaces. Their exposure differs by architecture: a field protocol is not automatically internet-accessible, but gateways, maintenance laptops, engineering software, portable media, remote access and supply-chain updates can create paths into the control environment.

A compromise elsewhere in the control system can affect valve commands, position feedback or actuator availability even when the actuator itself was not the initial entry point. Risk assessment should therefore cover the complete command and feedback path, including controllers, safety systems, networks, gateways, credentials, update mechanisms and maintenance procedures.

How the IEC 62443 Series Applies

IEC 62443 is a series for securing industrial automation and control systems. Important parts include IEC 62443-2-1 for the asset owner's security program, IEC 62443-3-2 for system risk assessment and the definition of zones and conduits, IEC 62443-3-3 for system security requirements, IEC 62443-4-1 for a secure product development lifecycle, and IEC 62443-4-2 for technical security requirements for IACS components.

IEC 62443-4-2 maps component requirements to seven foundational requirements: identification and authentication control, use control, system integrity, data confidentiality, restricted data flow, timely response to events and resource availability. A valve actuator, positioner or gateway should be assessed for the applicable component type, intended use, interfaces and claimed component capability level—not only for passwords or encryption.

Security Levels: SL-T, SL-C and SL-A

IEC 62443 security levels describe resistance to classes of threat capability and motivation. In practical specifications, distinguish the target level selected by risk assessment (SL-T), the capability a system or component is designed to provide (SL-C), and the achieved level after integration and verification (SL-A). These are related but not interchangeable.

Do not assign a universal security level to every actuator or assume that an ESD duty automatically requires a particular component level. IEC 62443-3-2 risk assessment determines targets for each zone and conduit. The final design must also preserve safety-system independence, fail-safe behavior, response time and availability; a security control must not undermine the safety function.

Threat Paths and Consequences

Relevant paths include exposed remote-access services, shared or default credentials, insecure engineering workstations, unauthorized portable media, weakly protected gateways, tampered configuration or firmware, vulnerable dependencies and poorly controlled vendor support connections. The actual exposure depends on the installed architecture and operating procedures.

Potential consequences include unauthorized valve movement, loss or falsification of position feedback, denial of service, delayed maintenance, process interruption and degraded safety or environmental protection. These are hazard scenarios to evaluate—not proof that any one product or protocol is vulnerable.

Risk-Based Security Controls

Remove or change default credentials, use unique named accounts and least privilege, disable unused services, restrict configuration access and log security-relevant events where the component supports them. Multi-factor authentication is usually enforced at remote-access or management layers; it may not be implemented inside a field actuator.

Use approved cryptographic mechanisms where required and supported, but avoid prescribing a protocol version without considering product capability and lifecycle. Firmware and configuration updates should be authenticated, tested, scheduled with operations, recoverable or reversible where possible, and governed by vulnerability disclosure, patch evaluation and end-of-support processes.

Zones, Conduits and Network Segmentation

Use IEC 62443-3-2 risk assessment to group assets into zones and control communications through defined conduits. Segmentation may use industrial firewalls, access-control rules, monitored remote-access gateways and a DMZ for controlled data exchange between enterprise and operational networks.

Allow only required communication between authorized controllers, engineering stations and field devices. Do not expose actuators directly to the internet. A VLAN can support segmentation, but it is not a complete security boundary by itself; enforce routes, rules, authentication, monitoring and physical controls appropriate to the risk.

Procurement Requirements for Smart Actuators

State the intended architecture, interfaces, zone/conduit context and risk-derived security requirements in the request for quotation. If IEC 62443 evidence is required, specify the exact applicable part, component type, claimed capability level, certificate scope, product and firmware versions, issuing assessment body, assumptions and exclusions.

Request a security manual, hardening guide, software bill of materials when appropriate, secure configuration and backup procedures, authenticated update method, vulnerability reporting contact, patch and support policy, incident-notification process and lifecycle dates. Verify that integration requirements can be met without weakening functional safety or availability.

Legacy Actuators and Compensating Controls

Legacy devices may lack native authentication, logging or cryptography. Reduce exposure with tightly controlled gateways, protocol breaks where appropriate, network segmentation, allowlisting, monitored maintenance access and procedural controls. Test any gateway for latency, failure modes and its effect on diagnostics and safety.

An 'air gap' is not absolute protection when portable media, temporary engineering connections or maintenance laptops cross the boundary. Replacement may be justified when residual risk remains unacceptable, but the decision should follow asset criticality, lifecycle support, safety impact and a documented risk assessment.

Operations, Maintenance and Training

Train operators, maintenance technicians, control engineers and vendors on credential handling, approved remote access, portable-media controls, configuration change management, phishing awareness, vulnerability reporting and incident escalation.

Maintain an asset inventory with hardware, software and firmware versions; review vendor advisories; back up known-good configurations; test recovery; and exercise cyber incident scenarios alongside process-safety response. Cybersecurity is a lifecycle activity, not a one-time product feature.

Conclusion

Secure valve automation depends on the whole IACS architecture. Use IEC 62443-3-2 to set risk-based targets for zones and conduits, evaluate component capabilities under IEC 62443-4-2, require a secure development lifecycle under IEC 62443-4-1, and verify the achieved protection after integration. Coordinate security, safety and operations throughout procurement, commissioning, maintenance and decommissioning.

Frequently Asked Questions

Do all valve actuators need cybersecurity protection?

Any device or maintenance path that can influence control, feedback or availability should be included in the system risk assessment. Required controls depend on connectivity, consequence, architecture and threat exposure; an ESD duty alone does not establish a universal component security level.

What is the difference between IEC 62443 and the NIST Cybersecurity Framework?

IEC 62443 provides IACS-specific lifecycle, system and component requirements. NIST CSF 2.0 is an organization-level framework for managing cybersecurity risk, while NIST SP 800-82 Rev. 3 gives detailed operational technology guidance. Organizations can use them together.

Can cybersecurity be added to existing actuators?

Often only partly. Segmentation, monitored gateways, restricted engineering access and procedural controls can reduce exposure, but they do not add every missing security capability to the legacy component. Document the residual risk and replace unsupported equipment when compensating controls are insufficient.

How should IEC 62443 claims be verified?

Ask for evidence naming the exact IEC 62443 part, certificate or assessment body, product and firmware scope, component type, claimed capability level, assumptions and exclusions. A vague statement such as 'IEC 62443 compliant' is not enough, and a component certificate does not establish the achieved security level of the integrated system.

Primary References

IEC 62443-4-2:2019, Technical security requirements for IACS components — https://webstore.iec.ch/en/publication/34421

IEC 62443-3-2:2020, Security risk assessment for system design — https://webstore.iec.ch/en/publication/30727

NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security — https://csrc.nist.gov/pubs/sp/800/82/r3/final

Contact Us

For valve and actuator selection, integration requirements or technical support, contact our team. For connected actuator projects, include the communication architecture, cybersecurity specification, applicable IEC 62443 evidence and site acceptance requirements in the inquiry.

Ted Wang

Wechat/Whatsapp: +86 18267833722

Email: sales@wofervalve.com

Web: www.wofervalve.com

Wenzhou Wofer Valve Co., Ltd.

Recent Posts

See All

Comments


bottom of page