Lincoln 01522 740818 Hull 01482 520818
Shop certified radios

Yesway Communications

IEC 62443 Industrial Radio Security Assessment

OT Security

IEC 62443 Industrial Radio
Security Assessment

Every industrial site running two-way radio, SCADA wireless, or DMR/TETRA infrastructure has a security gap that no IEC 62443 certification body is qualified to assess — because they don’t understand radio. We do.

The gap nobody is talking about

Your IEC 62443 audit almost certainly missed your radio network.

The major IEC 62443 certification bodies bring deep IT and OT cybersecurity expertise. What they cannot bring is RF engineering knowledge — because industrial radio assessment requires a combination of skills that sits outside the background of most cybersecurity professionals: RF propagation, radio zone architecture, DMR and TETRA encryption, repeater topology, and an understanding of how wireless conduits cross security zone boundaries in ways that wired networks don’t. That is not a criticism. It is a structural gap that exists because this specialism sits at an unusual intersection — and it means radio networks are the missing piece in most industrial cybersecurity assessments currently being conducted in the UK and worldwide.

The radio security problem industrial sites don’t know they have

Picture a manufacturing plant. It has a comprehensive IEC 62443 assessment. Zone-and-conduit diagrams are documented. Firewall rules are reviewed. SCADA network access is controlled. The IT security team is satisfied.

Now picture the site radio system. Twelve Hytera DMR handsets. An analogue repeater on the roof. A SCADA telemetry link running on unlicensed 433MHz. An unencrypted radio channel covering the entire plant — production, maintenance, security, and management all on the same talkgroup, all audible to anyone within range with a £30 scanner from Amazon.

That radio network crosses every security zone on site. It transmits operational data — process alarms, maintenance instructions, personnel locations, shift handover information — in the clear, outside every firewall and access control the IEC 62443 assessment reviewed. It is a conduit with no security controls, connecting every zone on the site to the physical RF environment outside the perimeter fence.

This is not a hypothetical. It is the default state of most industrial radio networks in the UK and worldwide. And it is not being assessed, because the people conducting IEC 62443 audits don’t know enough about radio to see it.

Regulatory context

The UK Cyber Security and Resilience Bill, announced November 2025, will extend mandatory cybersecurity requirements to a significantly wider range of critical national infrastructure operators. IEC 62443 is the referenced framework. Radio networks are in scope. Non-compliance will carry liability. The window to address this proactively — before enforcement — is now.

How IEC 62443 applies to industrial radio networks

IEC 62443 uses a zone-and-conduit model as its core architectural framework. Zones group assets with the same security requirements. Conduits are the communication paths between zones — and they must be assessed and controlled to prevent unauthorised data flow between zones with different security levels.

A radio network is a conduit. In fact, it is a particularly challenging conduit to manage, because RF signals do not respect physical boundaries. A repeater covering an industrial site creates a wireless conduit that potentially connects every zone on the site — process control, operations, maintenance, safety, and management — to each other and to the RF environment beyond the site perimeter.

IEC 62443-3-2 requires that all conduits be identified, assessed for risk, and assigned an appropriate Security Level target. IEC 62443-3-3 defines the technical controls required to meet each Security Level. For a radio conduit, the relevant controls include encryption of radio transmissions, authentication of radio users, restricted access to radio talkgroups, and monitoring of radio traffic for anomalies.

None of this appears in standard IEC 62443 assessments — because the assessors don’t have the RF engineering background to identify radio conduits, assess their risk, or specify appropriate controls.

IEC 62443 requirement Standard IT/OT assessment Radio network reality
Conduit identification Wired network conduits documented Radio conduits rarely identified or mapped
Zone boundary control Firewall rules reviewed RF signals cross zone boundaries invisibly — no firewall equivalent assessed
Data confidentiality (FR4) Network encryption verified Analogue radio and unencrypted DMR transmit operational data in clear
Access control (FR1/FR2) Network authentication reviewed Radio talkgroup access rarely controlled or authenticated
Restricted data flow (FR5) VLAN segmentation reviewed Radio coverage maps not assessed against zone boundaries
SCADA wireless telemetry Sometimes reviewed if IP-based RF-based SCADA telemetry links almost never assessed

What the certification bodies miss

This is not a criticism of Bureau Veritas, TÜV SÜD or the other IEC 62443 bodies. They are excellent at what they do. The gap exists because IEC 62443 radio assessment requires a specific combination of skills that no single certification body currently has: deep RF engineering knowledge, practical industrial radio system experience, and IEC 62443 standards fluency.

Specifically, a complete radio conduit assessment requires the ability to:

1

Map radio coverage against security zone boundaries

Conduct an RF survey to establish actual radio coverage — where repeaters reach, where handhelds operate, where SCADA telemetry links run. Overlay this against the IEC 62443 zone diagram to identify every point where a wireless conduit crosses a zone boundary.

2

Assess encryption and access control status

Determine whether each radio link is analogue (unencrypted by definition) or digital, and if digital, whether encryption is enabled and correctly keyed. Assess talkgroup access controls — whether unauthorised users can monitor or transmit on operational channels.

3

Assess licence compliance and spectrum exposure

Verify that all radio equipment is operating on correctly licensed frequencies. Unlicensed operation creates regulatory exposure and indicates a radio system that has not been professionally managed — itself a security risk indicator under IEC 62443.

4

Assign Security Level targets and gap analysis

For each identified radio conduit, assign an appropriate IEC 62443 Security Level target based on what data the conduit carries, which zones it connects, and what the consequence of compromise would be. Produce a gap analysis against current state and a prioritised remediation roadmap.

5

Produce the written assessment report

Deliver a written IEC 62443 wireless conduit gap analysis report, structured to integrate with your existing IEC 62443 documentation and suitable for submission to your certification body, insurance underwriter, or regulatory authority.

How an assessment works

A Yesway IEC 62443 industrial radio assessment is a structured, five-stage process — conducted by a wireless communications engineer, not a cybersecurity generalist. It can be completed as a standalone engagement or integrated into an existing IEC 62443 programme.

1

Pre-assessment scoping call

A 30-minute call to understand your site, your current radio infrastructure, and whether you have an existing IEC 62443 programme. We confirm scope, agree access requirements, and issue a fixed-price proposal within two working days.

2

Site RF survey and radio inventory

Onsite visit to conduct a professional RF coverage survey — mapping where every radio, repeater, and SCADA wireless telemetry link actually reaches. We document all radio equipment, frequencies, talkgroups, encryption status, and licence details. This is the foundational step that no IT-background assessor can perform.

3

Zone boundary mapping and conduit identification

We overlay the RF coverage map against your IEC 62443 zone diagram — or create one if it doesn’t exist — to identify every point where a wireless conduit crosses a security zone boundary. This produces a complete picture of your radio conduit architecture for the first time.

4

Security Level gap analysis

For each identified radio conduit, we assign an appropriate IEC 62443 Security Level target based on what data the conduit carries, which zones it connects, and what the consequence of compromise would be. We then compare that target against current controls — encryption, access control, monitoring — and identify the gaps.

5

Written report and remediation roadmap

We deliver a written IEC 62443 wireless conduit gap analysis report — structured to integrate with your existing IEC 62443 documentation and suitable for submission to your certification body, insurance underwriter, or regulatory authority. The report includes a prioritised remediation roadmap with indicative costs and timescales.

Timescales and logistics

A single-site assessment typically takes one day onsite and two to three days of analysis and report writing. The written report is delivered within five working days of the site visit. For multi-site programmes, we agree a phased schedule. All site visits are conducted by Craig Miles personally — not subcontracted to a junior assessor.

Yesway OT wireless security services

GAP

IEC 62443 Wireless Conduit Gap Analysis

For: Asset owners, system integrators, compliance teams

A full assessment of your industrial radio network against IEC 62443 zone-and-conduit requirements. Includes site RF survey, zone boundary mapping, encryption and access control assessment, licence compliance review, Security Level gap analysis, and written report.

From £2,500 — single site
AUD

Radio Security Audit — Standalone

For: Sites without an existing IEC 62443 programme

A practical assessment of your industrial radio infrastructure security — encryption status, talkgroup access controls, licence compliance, SCADA wireless telemetry links, and coverage mapping. Written report with prioritised remediation recommendations.

From £1,500 — single site
TRN

IEC 62443 Wireless Security Awareness Training

For: OT security teams, site engineers, compliance managers

Half-day or full-day workshop covering how IEC 62443 applies to industrial radio networks, how to identify radio conduit risks, what good wireless security looks like in practice, and how to integrate radio assessment into your existing IEC 62443 programme.

From £950 — remote or on-site
SUB

Subcontract Radio Assessment for Certification Bodies

For: IEC 62443 certification bodies and consultancies

If your IEC 62443 practice needs a wireless communications specialist to complete radio conduit assessments for your clients, Yesway provides subcontract radio assessment services — delivering the RF expertise your team doesn’t have, under your engagement.

Day rate available on request

Sectors most at risk

Any industrial site running radio communications alongside SCADA or control systems has a wireless conduit gap. These are the sectors where the risk is highest and the regulatory pressure most acute.

Oil, gas and petrochemical
Extensive radio networks across ATEX zones. SCADA telemetry links. Safety-critical comms. High consequence of compromise. High IEC 62443 compliance exposure under NIS2 and UK CNI legislation.
Water and wastewater utilities
Wide-area SCADA wireless linking remote pump stations and treatment works. Often legacy analogue radio. Critical national infrastructure designation under the Cyber Security and Resilience Bill.
Power generation and grid
TETRA and DMR radio networks integrated with SCADA and energy management systems. High-value attack target. Regulatory compliance requirements increasing significantly in 2026.
Manufacturing and automotive
Factory radio crossing production zone boundaries constantly. Industry 4.0 wireless integration adding new conduits faster than security teams can assess them. IEC 62443 increasingly required by Tier 1 customers.
Ports and maritime
VHF, UHF and TETRA radio across port operations, cargo handling and vessel-to-shore communications. Multiple zone boundaries. Increasing cyber insurance and port authority compliance requirements.
Rail and transport infrastructure
GSM-R, TETRA and radio-based control systems. Safety-critical communications with significant cybersecurity regulatory development underway including IEC 63452 (railway adaptation of IEC 62443).

Why Yesway — and why RF expertise matters

RF
30 years of industrial radio
Yesway has designed, installed and maintained radio systems across manufacturing, utilities, maritime and public safety for over 15 years. Craig Miles has 30 years of RF and wireless systems experience including aerospace satellite programmes at Airbus.
SRV
RF survey capability
We conduct professional RF coverage surveys — the foundational step that no IT-background cybersecurity assessor can perform. You cannot map radio conduits against zone boundaries without knowing where the radio actually reaches.
DMR
DMR, TETRA and analogue expertise
We understand the encryption architecture of DMR and TETRA, the security implications of analogue radio, and how talkgroup access control works in practice — not in theory from a standards document.
LIC
Ofcom licensing expertise
Licence compliance is a foundational IEC 62443 radio security control. We verify your radio equipment is correctly licensed — something no cybersecurity firm can assess because they don’t work with Ofcom spectrum frameworks.
RPT
Report structured for certification bodies
Our gap analysis reports are structured to integrate with your existing IEC 62443 documentation — zone diagrams, Security Level assignments, conduit specifications — in the format your certification body expects.
UNQ
The only dedicated service of its kind
We have searched the global market. No other organisation offers IEC 62443 radio conduit assessment as a dedicated, standalone service. The major certification bodies bring cybersecurity expertise — Yesway brings the RF engineering expertise they don’t have. We are filling a genuine gap.

Request an IEC 62443 wireless assessment

If your site runs industrial radio and you have an IEC 62443 programme — or are about to start one — contact us to discuss a wireless conduit gap analysis. We respond within two working days.