Lincoln 01522 740818 Hull 01482 520818
Shop certified radios

Wireless Communications Blog

Why your IEC 62443 assessment almost certainly missed your radio network

The IEC 62443 assessment report is sitting on the desk. Zone diagrams. Conduit maps. Security Level targets assigned for every SCADA workstation, every PLC, every firewall and managed switch on site. The certification body is satisfied. The compliance team is satisfied. The insurance underwriter is satisfied.

And somewhere on the roof of the building, a repeater is broadcasting every operational conversation on site — unencrypted, unlicensed, audible to anyone within two kilometres with a scanner that costs less than a round of drinks.

That repeater did not appear in the assessment. Neither did the twelve handsets signed out to shift supervisors every morning. Neither did the SCADA telemetry link running on 433MHz between the pump house and the control room. Neither did the DMR talkgroup that operations, maintenance, security, and senior management all share — crossing every security zone on the site with every transmission.

This is not an edge case. It is the default outcome of most IEC 62443 assessments conducted in the UK and worldwide right now. And it happens for one reason: the people conducting the assessments do not understand radio.

What IEC 62443 actually requires for wireless systems

IEC 62443 uses a zone-and-conduit model as its core architectural framework. Zones group assets with the same security requirements. Conduits are the communication paths between zones — and under IEC 62443-3-2, every conduit must be identified, assessed for risk, and assigned a Security Level target.

A radio network is a conduit. Not metaphorically — literally. A repeater covering an industrial site creates a wireless communication channel that connects every zone on the site to every other zone, and to the RF environment beyond the perimeter fence. Under IEC 62443-3-2, that conduit must be in the zone diagram. The risk of unauthorised access, eavesdropping, and signal injection must be assessed. A Security Level target must be assigned. Controls must be specified and verified.

IEC 62443-3-3 then defines the technical controls required to meet each Security Level. For a radio conduit operating at Security Level 2 — protection against intentional misuse by simple means, which is the typical baseline target for most industrial sites — the relevant controls include encryption of all transmissions, authentication of radio users, restricted access to operational talkgroups, and monitoring for anomalous radio activity.

None of this is hidden in the standard. It is explicit. The reason it is not appearing in most IEC 62443 assessments is not a gap in the standard — it is a gap in the assessors.

Why assessors miss it

IEC 62443 assessment is dominated by professionals from IT and OT cybersecurity backgrounds. They understand network architecture, firewall rules, SCADA software security, PLC access control, and vulnerability management. These are genuine and important skills.

What they do not have is RF engineering knowledge. And without that, radio conduit assessment is impossible — not difficult, impossible. You cannot identify radio conduits without understanding RF propagation. You cannot map a repeater’s coverage against zone boundaries without conducting an RF survey. You cannot assess DMR encryption status without knowing how DMR encryption works at the air interface level. You cannot verify Ofcom licence compliance without knowing what the licence requires and how to check the radio equipment against it.

The result is a predictable and entirely understandable blind spot. The assessor documents what they can see and understand — the wired network, the software systems, the IT infrastructure. The radio network, which they cannot assess, does not appear. The zone diagram has no wireless conduits. The gap analysis has no radio findings. The report is signed off.

The repeater keeps transmitting.

What an unassessed radio conduit actually means

Let us be specific about the risk, because it is not abstract.

An unencrypted analogue radio system — still common across UK manufacturing, utilities, and logistics — broadcasts every transmission in the clear. Anyone with a basic scanner, available for under £30 online, can receive every word spoken on that system. Maintenance schedules. Shift handover information. Security patrol timings. Process alarm acknowledgements. Personnel locations. In a worst case, system passwords or access codes spoken over radio by staff who should know better but do not have a secure alternative.

An unencrypted DMR system is marginally better — the digital encoding provides some practical obscurity — but DMR without encryption enabled is not a secure conduit. The transmission can be decoded with freely available software defined radio tools and open-source DMR decoder software. The barrier to interception is low.

An unlicensed SCADA telemetry link — and there are more of these than the industry admits — creates regulatory exposure under the Wireless Telegraphy Act 2006 alongside the security vulnerability. Operating without the correct Ofcom licence is a criminal offence. It also signals that the radio system has not been professionally managed, which is itself a risk indicator under IEC 62443’s security management requirements.

A talkgroup with no access control — where any radio programmed to the correct channel can transmit — is an open conduit between every zone the coverage reaches. In IEC 62443 terms, this is a conduit with no security controls connecting zones with potentially very different Security Level requirements. It fails the foundational requirements for identification and authentication control (FR1), use control (FR2), and restricted data flow (FR5).

The regulatory timing makes this urgent

The UK Cyber Security and Resilience Bill, announced in November 2025, will extend mandatory cybersecurity requirements to a significantly wider range of critical national infrastructure operators. IEC 62443 is the referenced framework. The legislation is expected to reach enforcement through 2026 and 2027.

Simultaneously, NIS2 — the EU Network and Information Security Directive, which came into force in October 2024 — has extended OT cybersecurity obligations across a much broader range of sectors including manufacturing, utilities, transport, and digital infrastructure. For UK organisations operating in EU markets or with EU supply chains, NIS2 compliance obligations apply regardless of Brexit.

Both frameworks reference IEC 62443. Both will require demonstrable compliance. A compliance posture that has an unassessed radio network sitting outside the zone-and-conduit model is not a complete IEC 62443 compliance posture — and regulators, insurers, and Tier 1 customers conducting supply chain audits are becoming sophisticated enough to notice.

The window to address this proactively — before enforcement arrives and before a supply chain audit finds it — is now.

How to find out if your radio network was assessed

If you have an existing IEC 62443 assessment, three questions will tell you immediately whether your radio network was included:

Does the zone-and-conduit diagram include any wireless conduits? If the diagram shows only wired network connections — switches, firewalls, SCADA connections — and no radio or wireless links, the radio network was not assessed.

Does the assessment reference your radio frequencies, equipment models, or Ofcom licence numbers? A radio assessment requires knowledge of the specific equipment in use. If the report contains no radio equipment details, it does not contain a radio assessment.

Was an RF survey conducted as part of the assessment? Mapping radio coverage against zone boundaries requires an onsite RF survey. If no RF survey took place, zone boundary mapping for wireless conduits did not happen.

If the answer to all three questions is no, your radio network was not assessed. That is not a reflection on the quality of your existing assessor — it is a reflection of the skills gap described above. The assessment covered what could be assessed with IT and OT cybersecurity expertise. Radio assessment requires a different specialism.

What a radio conduit assessment looks like in practice

A Yesway IEC 62443 radio conduit assessment follows a structured five-stage process: a pre-assessment scoping call to understand the site and radio infrastructure, a site RF survey to map actual coverage, zone boundary mapping to identify conduit crossings, a Security Level gap analysis for each identified conduit, and a written report structured to integrate with your existing IEC 62443 documentation.

The written report is suitable for submission to your certification body, insurance underwriter, or regulatory authority. It can be delivered as a standalone engagement or as a supplement to an existing IEC 62443 programme — filling the radio gap in an assessment that was otherwise thorough.

For a single site, the assessment typically takes one day onsite and delivers a written report within five working days. All site visits are conducted by Craig Miles personally — not subcontracted to a junior assessor.

If you have an IEC 62443 programme and want to know whether your radio network was included — or if you are starting an IEC 62443 programme and want to ensure radio is addressed from the outset — the full service description is here, or contact us directly to arrange a free 30-minute scoping call.


Craig Miles is the founder of Yesway Communications and a wireless communications engineer with 30 years of experience across RF, industrial radio, and satellite systems — including aerospace ILS engineering at Airbus Defence and Space on NATO satellite programmes. BSc · PGCE · QTS · Ofcom Licensed · DBS Checked. IEC 62443 industrial radio security assessment services ?

Author

  • craig miles

    TEDx Conversation

    Wireless communications engineer, technical educator and founder with 30 years of experience spanning aerospace, LEO satellite systems and RF engineering.

    Former ILS engineer at Airbus Defence and Space on NATO satellite and classified UK defence radio programmes.

    Founder of Yesway Communications — a Lincoln-based wireless communications specialist established in 2010, and ReachED, a new charitable initiative using LEO direct-to-device satellite connectivity to deliver education to the 273 million children globally without school access.

    TEDx Brayford Pool 2023 speaker. BSc · PGCE · QTS · Level 4 DSA Specialist Mentor · Ofcom Licensed · DBS Checked.