Lincoln 01522 740818 Hull 01482 520818
Shop certified radios

Wireless Communications Blog

IEC 62443 Wireless Audit: What a Real Industrial Radio Assessment Finds

The following is an anonymised account of an IEC 62443 wireless security assessment carried out by Yesway Communications for a UK manufacturing client. Identifying details have been changed. The technical findings are representative of what is commonly discovered in industrial radio environments that have not previously received a formal security assessment.

Client background

The client operates a multi-site manufacturing facility in the UK Midlands. The site has approximately 200 staff across production, logistics, and maintenance. Radio communications are used across all three functions: production supervisors carry DMR handsets, the logistics team use a separate talkgroup for vehicle movements, and maintenance engineers have their own channel for breakdowns and planned work.

The radio system had been in place for around eight years, installed by a regional dealer and expanded incrementally as the facility grew. No security assessment had ever been carried out. The trigger for the engagement was an upcoming NIS2 compliance review — the client’s parent company has EU operations and needed to demonstrate supply chain compliance.

Scope of the assessment

The assessment was scoped to cover the entire radio network as a communications conduit, applying the zone and conduit methodology from IEC 62443-3-2. This included:

  • Three DMR talkgroups (production, logistics, maintenance)
  • Two repeater sites covering the main building and the external logistics yard
  • A legacy UHF radio link used for SCADA telemetry between the main plant and a remote pumping station
  • A PoC handset trial that had been running for six months in the logistics team

What we found

Finding 1: Encryption disabled across all DMR talkgroups

None of the three DMR talkgroups had encryption enabled. The handsets supported AES 256-bit encryption, but it had never been configured. During the assessment, we demonstrated that all three talkgroups were receivable on a consumer-grade SDR receiver within 200 metres of the facility perimeter — including the maintenance channel, which routinely carries information about equipment faults, production line status, and planned shutdowns.

Risk rating: High. Operational information transmitted unencrypted on licensed spectrum is accessible to anyone within radio range with basic equipment. For a manufacturing operation, this includes potential disclosure of production schedules, equipment vulnerabilities, and operational patterns to competitors or other third parties.

Finding 2: SCADA telemetry link operating on an unmanaged frequency

The legacy UHF link between the main plant and the remote pumping station was operating on a frequency that was not listed on the site’s current Ofcom licence schedule. The link had been installed under a previous licence that had since been amended, and the frequency had not been updated. The link was transmitting SCADA telemetry continuously — pump status, flow rates, and alarm states — on an unlicensed frequency with no encryption and no authentication.

Risk rating: Critical. An unencrypted, unauthenticated SCADA radio link operating outside the licence schedule creates two distinct problems: a regulatory compliance failure (operating unlicensed radio equipment) and a security exposure (SCADA telemetry accessible to anyone who can tune to the frequency). In an ICS environment, this type of link is a potential vector for both eavesdropping and — if the protocol supports it — command injection.

Finding 3: PoC handsets in use with no data governance

The logistics team’s PoC handset trial was operating via a commercial PoC platform. The platform routes voice communications through the vendor’s cloud infrastructure. No data processing agreement was in place between the client and the PoC vendor. Operational communications — including vehicle movements, delivery schedules, and yard access instructions — were being transmitted through a third-party cloud platform with no documented security assessment and no contractual data protection obligations.

Risk rating: Medium. Under NIS2 Article 21, supply chain security obligations require organisations to assess and manage risks from third-party service providers. A PoC platform handling operational communications is a third-party dependency that requires a documented assessment. The absence of a data processing agreement is also a separate GDPR compliance issue.

Finding 4: No process for contractor radio access

Site contractors — maintenance firms, delivery drivers, and temporary labour — were routinely issued with site radio handsets without any formal process. There was no record of which handsets had been issued, no process for return and de-programming, and no audit trail of who had been given access to which talkgroups. One handset identified during the assessment had been programmed with all three talkgroups and was associated with a contractor whose engagement had ended 18 months previously.

Risk rating: Medium. Uncontrolled contractor radio access creates an untraceable population of devices with legitimate access to site communications. For IEC 62443 zone boundary control, this represents an unmanaged conduit between the operational environment and external parties.

Remediation delivered

Following the assessment, Yesway worked with the client to address each finding:

  • Encryption: AES 256-bit encryption was configured across all three DMR talkgroups. All handsets were reprogrammed, and encryption keys were documented and secured. A key management process was established.
  • SCADA link: The unlicensed frequency was identified and an application made to Ofcom to update the licence schedule. An interim encrypted replacement link was specified and subsequently installed.
  • PoC platform: The client paused the PoC trial pending a formal vendor security assessment. A data processing agreement was subsequently put in place. The client also evaluated whether the PoC use case could be served by extending the DMR system coverage rather than using a third-party cloud platform.
  • Contractor access: A handset register was created. A process was established for contractor handset issue, talkgroup restriction (contractors now only access a dedicated visitor talkgroup), and return. Existing handsets were audited, and three unaccounted handsets were recovered and de-programmed.

Outcome

The client’s NIS2 compliance review was completed successfully. The radio network assessment, findings, and remediation documentation were included in the supply chain security evidence pack submitted to the parent company. The client now has documented baseline security for its radio network and a repeatable process for maintaining that baseline.

The total engagement — assessment, reporting, and remediation support — was completed over four weeks. The most time-consuming element was the SCADA link, which required Ofcom licence work that extended the timeline. The DMR encryption configuration and contractor access process were both resolved within the first two weeks.


If your organisation operates industrial radio and has not carried out a formal security assessment, the findings above are not unusual. Most industrial radio systems in the UK have never been assessed from a security perspective. The Yesway IEC 62443 wireless audit service provides a structured assessment using the same methodology described in this case study.


Craig Miles is a wireless communications engineer with 30 years of RF and radio systems experience, including aerospace satellite systems at Airbus Defence & Space. He is a PGCE Level 7 qualified engineer and 2023 TEDx speaker.

Author

  • craig miles

    TEDx Conversation

    Wireless communications engineer, technical educator and founder with 30 years of experience spanning aerospace, LEO satellite systems and RF engineering.

    Former ILS engineer at Airbus Defence and Space on NATO satellite and classified UK defence radio programmes.

    Founder of Yesway Communications — a Lincoln-based wireless communications specialist established in 2010, and ReachED, a new charitable initiative using LEO direct-to-device satellite connectivity to deliver education to the 273 million children globally without school access.

    TEDx Brayford Pool 2023 speaker. BSc · PGCE · QTS · Level 4 DSA Specialist Mentor · Ofcom Licensed · DBS Checked.