Yesway Communications
IEC 62443 Industrial Radio Security Assessment
IEC 62443 Industrial Radio
Security Assessment
Every industrial site running two-way radio, SCADA wireless, or DMR/TETRA infrastructure has a security gap that no IEC 62443 certification body is qualified to assess — because they don’t understand radio. We do.
Your IEC 62443 audit almost certainly missed your radio network.
The major IEC 62443 certification bodies bring deep IT and OT cybersecurity expertise. What they cannot bring is RF engineering knowledge — because industrial radio assessment requires a combination of skills that sits outside the background of most cybersecurity professionals: RF propagation, radio zone architecture, DMR and TETRA encryption, repeater topology, and an understanding of how wireless conduits cross security zone boundaries in ways that wired networks don’t. That is not a criticism. It is a structural gap that exists because this specialism sits at an unusual intersection — and it means radio networks are the missing piece in most industrial cybersecurity assessments currently being conducted in the UK and worldwide.
On this page
The radio security problem industrial sites don’t know they have
Picture a manufacturing plant. It has a comprehensive IEC 62443 assessment. Zone-and-conduit diagrams are documented. Firewall rules are reviewed. SCADA network access is controlled. The IT security team is satisfied.
Now picture the site radio system. Twelve Hytera DMR handsets. An analogue repeater on the roof. A SCADA telemetry link running on unlicensed 433MHz. An unencrypted radio channel covering the entire plant — production, maintenance, security, and management all on the same talkgroup, all audible to anyone within range with a £30 scanner from Amazon.
That radio network crosses every security zone on site. It transmits operational data — process alarms, maintenance instructions, personnel locations, shift handover information — in the clear, outside every firewall and access control the IEC 62443 assessment reviewed. It is a conduit with no security controls, connecting every zone on the site to the physical RF environment outside the perimeter fence.
This is not a hypothetical. It is the default state of most industrial radio networks in the UK and worldwide. And it is not being assessed, because the people conducting IEC 62443 audits don’t know enough about radio to see it.
The UK Cyber Security and Resilience Bill, announced November 2025, will extend mandatory cybersecurity requirements to a significantly wider range of critical national infrastructure operators. IEC 62443 is the referenced framework. Radio networks are in scope. Non-compliance will carry liability. The window to address this proactively — before enforcement — is now.
How IEC 62443 applies to industrial radio networks
IEC 62443 uses a zone-and-conduit model as its core architectural framework. Zones group assets with the same security requirements. Conduits are the communication paths between zones — and they must be assessed and controlled to prevent unauthorised data flow between zones with different security levels.
A radio network is a conduit. In fact, it is a particularly challenging conduit to manage, because RF signals do not respect physical boundaries. A repeater covering an industrial site creates a wireless conduit that potentially connects every zone on the site — process control, operations, maintenance, safety, and management — to each other and to the RF environment beyond the site perimeter.
IEC 62443-3-2 requires that all conduits be identified, assessed for risk, and assigned an appropriate Security Level target. IEC 62443-3-3 defines the technical controls required to meet each Security Level. For a radio conduit, the relevant controls include encryption of radio transmissions, authentication of radio users, restricted access to radio talkgroups, and monitoring of radio traffic for anomalies.
None of this appears in standard IEC 62443 assessments — because the assessors don’t have the RF engineering background to identify radio conduits, assess their risk, or specify appropriate controls.
| IEC 62443 requirement | Standard IT/OT assessment | Radio network reality |
|---|---|---|
| Conduit identification | Wired network conduits documented | Radio conduits rarely identified or mapped |
| Zone boundary control | Firewall rules reviewed | RF signals cross zone boundaries invisibly — no firewall equivalent assessed |
| Data confidentiality (FR4) | Network encryption verified | Analogue radio and unencrypted DMR transmit operational data in clear |
| Access control (FR1/FR2) | Network authentication reviewed | Radio talkgroup access rarely controlled or authenticated |
| Restricted data flow (FR5) | VLAN segmentation reviewed | Radio coverage maps not assessed against zone boundaries |
| SCADA wireless telemetry | Sometimes reviewed if IP-based | RF-based SCADA telemetry links almost never assessed |
What the certification bodies miss
This is not a criticism of Bureau Veritas, TÜV SÜD or the other IEC 62443 bodies. They are excellent at what they do. The gap exists because IEC 62443 radio assessment requires a specific combination of skills that no single certification body currently has: deep RF engineering knowledge, practical industrial radio system experience, and IEC 62443 standards fluency.
Specifically, a complete radio conduit assessment requires the ability to:
Map radio coverage against security zone boundaries
Conduct an RF survey to establish actual radio coverage — where repeaters reach, where handhelds operate, where SCADA telemetry links run. Overlay this against the IEC 62443 zone diagram to identify every point where a wireless conduit crosses a zone boundary.
Assess encryption and access control status
Determine whether each radio link is analogue (unencrypted by definition) or digital, and if digital, whether encryption is enabled and correctly keyed. Assess talkgroup access controls — whether unauthorised users can monitor or transmit on operational channels.
Assess licence compliance and spectrum exposure
Verify that all radio equipment is operating on correctly licensed frequencies. Unlicensed operation creates regulatory exposure and indicates a radio system that has not been professionally managed — itself a security risk indicator under IEC 62443.
Assign Security Level targets and gap analysis
For each identified radio conduit, assign an appropriate IEC 62443 Security Level target based on what data the conduit carries, which zones it connects, and what the consequence of compromise would be. Produce a gap analysis against current state and a prioritised remediation roadmap.
Produce the written assessment report
Deliver a written IEC 62443 wireless conduit gap analysis report, structured to integrate with your existing IEC 62443 documentation and suitable for submission to your certification body, insurance underwriter, or regulatory authority.
How an assessment works
A Yesway IEC 62443 industrial radio assessment is a structured, five-stage process — conducted by a wireless communications engineer, not a cybersecurity generalist. It can be completed as a standalone engagement or integrated into an existing IEC 62443 programme.
Pre-assessment scoping call
A 30-minute call to understand your site, your current radio infrastructure, and whether you have an existing IEC 62443 programme. We confirm scope, agree access requirements, and issue a fixed-price proposal within two working days.
Site RF survey and radio inventory
Onsite visit to conduct a professional RF coverage survey — mapping where every radio, repeater, and SCADA wireless telemetry link actually reaches. We document all radio equipment, frequencies, talkgroups, encryption status, and licence details. This is the foundational step that no IT-background assessor can perform.
Zone boundary mapping and conduit identification
We overlay the RF coverage map against your IEC 62443 zone diagram — or create one if it doesn’t exist — to identify every point where a wireless conduit crosses a security zone boundary. This produces a complete picture of your radio conduit architecture for the first time.
Security Level gap analysis
For each identified radio conduit, we assign an appropriate IEC 62443 Security Level target based on what data the conduit carries, which zones it connects, and what the consequence of compromise would be. We then compare that target against current controls — encryption, access control, monitoring — and identify the gaps.
Written report and remediation roadmap
We deliver a written IEC 62443 wireless conduit gap analysis report — structured to integrate with your existing IEC 62443 documentation and suitable for submission to your certification body, insurance underwriter, or regulatory authority. The report includes a prioritised remediation roadmap with indicative costs and timescales.
A single-site assessment typically takes one day onsite and two to three days of analysis and report writing. The written report is delivered within five working days of the site visit. For multi-site programmes, we agree a phased schedule. All site visits are conducted by Craig Miles personally — not subcontracted to a junior assessor.
Yesway OT wireless security services
IEC 62443 Wireless Conduit Gap Analysis
A full assessment of your industrial radio network against IEC 62443 zone-and-conduit requirements. Includes site RF survey, zone boundary mapping, encryption and access control assessment, licence compliance review, Security Level gap analysis, and written report.
Radio Security Audit — Standalone
A practical assessment of your industrial radio infrastructure security — encryption status, talkgroup access controls, licence compliance, SCADA wireless telemetry links, and coverage mapping. Written report with prioritised remediation recommendations.
IEC 62443 Wireless Security Awareness Training
Half-day or full-day workshop covering how IEC 62443 applies to industrial radio networks, how to identify radio conduit risks, what good wireless security looks like in practice, and how to integrate radio assessment into your existing IEC 62443 programme.
Subcontract Radio Assessment for Certification Bodies
If your IEC 62443 practice needs a wireless communications specialist to complete radio conduit assessments for your clients, Yesway provides subcontract radio assessment services — delivering the RF expertise your team doesn’t have, under your engagement.
Sectors most at risk
Any industrial site running radio communications alongside SCADA or control systems has a wireless conduit gap. These are the sectors where the risk is highest and the regulatory pressure most acute.
Why Yesway — and why RF expertise matters
Related services and resources
Request an IEC 62443 wireless assessment
If your site runs industrial radio and you have an IEC 62443 programme — or are about to start one — contact us to discuss a wireless conduit gap analysis. We respond within two working days.
