Lincoln 01522 740818 Hull 01482 520818
Shop certified radios

Wireless Communications Blog

What IEC 62443 Says About Wireless Radio Networks — And What Most Auditors Miss

There is a pattern that repeats itself across industrial sites throughout the UK. A manufacturing plant, a water treatment facility, a port, a power station. They commission an IEC 62443 assessment. The consultants spend days reviewing SCADA network architecture, firewall configurations, remote access controls, patch management processes.

Then they leave. The assessment report is comprehensive, well-structured, and almost certainly missing something significant: the radio network.

This is not an edge case. It is the default state of IEC 62443 compliance work in the UK right now.

What the standard actually requires

IEC 62443 is built on a zone-and-conduit model. Group assets into zones based on their security requirements, identify every conduit that connects or crosses those zones, assess the risk each conduit represents, and apply appropriate security controls.

IEC 62443-3-2 is unambiguous on scope. It requires that all conduits be identified and assessed — which means every communication path that carries operational data across a zone boundary, regardless of whether that path uses a cable or a radio signal.

IEC 62443-3-3 then defines the security controls that conduits must implement to meet a given Security Level. For a wireless conduit, the relevant controls include: confidentiality of transmitted data, authentication of users, restriction of data flow to authorised devices, and monitoring of the conduit for anomalous activity.

Why radio falls through the gap

IEC 62443 certification has developed as a cybersecurity discipline. The major bodies bring expertise in IT and OT network security, SCADA system architecture, and industrial control system risk management. What it doesn’t include is RF engineering — and assessing an industrial radio network correctly requires RF engineering knowledge that most cybersecurity professionals simply don’t have.

Coverage mapping. Before you can assess whether a radio conduit crosses a security zone boundary, you need to know where the radio actually reaches. This requires a professional RF survey — a physical survey that maps signal propagation across the site, not a desk review of a network diagram.

Encryption assessment. Analogue radio is unencrypted by definition. Digital radio (DMR, TETRA) can be encrypted, but encryption must be correctly configured and keyed — and in practice, many digital radio deployments operate with encryption disabled or incorrectly implemented.

Talkgroup access control. In most industrial radio deployments, anyone with a compatible radio programmed with the correct frequency and tone squelch settings can listen. This is an access control failure by any IEC 62443 definition — but invisible to an auditor who has never worked with radio systems.

SCADA wireless telemetry links. Many industrial sites use radio-based telemetry links to connect remote assets — pump stations, substations — back to the central SCADA system. These often operate on proprietary radio protocols and are entirely absent from the IT/OT asset inventory.

What the consequence actually looks like

The scenario is simpler than most cybersecurity threats. It doesn’t require sophisticated malware or a nation-state actor. It requires a £30 scanner purchased from an online retailer.

A site radio system running on analogue, or on digital radio without encryption, transmits operational data — process alarms, maintenance instructions, personnel locations, production status — in clear audio, across the site and beyond the perimeter. Anyone within range can receive every transmission.

For sites with SCADA telemetry running over radio links, the risk profile is more significant: unauthenticated radio links can be subject to replay attacks, jamming, or injection of false data. A poorly secured radio telemetry link to a remote pump station is, in IEC 62443 terms, an uncontrolled conduit connecting a high-consequence asset directly to the RF environment beyond the site perimeter.

The regulatory context in 2026

The UK Cyber Security and Resilience Bill will extend mandatory cybersecurity requirements to a significantly wider range of critical national infrastructure operators. IEC 62443 is the referenced framework for OT security. The NIS2 Directive similarly drives IEC 62443 compliance at industrial operators across EU member states.

In both cases, wireless communications are in scope. The window to address radio security proactively — before enforcement begins — is now.

What a proper wireless conduit assessment looks like

  1. A professional RF survey — mapping actual radio coverage across the site and beyond the perimeter
  2. Zone boundary mapping — overlaying the coverage map against the IEC 62443 zone diagram
  3. Encryption and access control assessment — determining the encryption status of every radio link
  4. SCADA wireless telemetry review — identifying RF-based telemetry links absent from the IT/OT asset inventory
  5. A written gap analysis report structured to integrate with existing IEC 62443 documentation

This is the assessment that standard IEC 62443 programmes are currently not performing. It requires someone who is both a wireless communications engineer and conversant with the IEC 62443 standards — a combination that sits at a very narrow intersection of expertise.

A practical step if you’re going through IEC 62443 compliance

Ask your current IEC 62443 consultant a direct question: has the radio network been assessed as a conduit? Has the RF coverage been surveyed? Has the encryption status of all radio links been verified? Have the SCADA wireless telemetry links been identified and assessed?

If the answer is uncertainty, the wireless conduit gap is still open.

We offer a standalone IEC 62443 wireless conduit gap analysis that can be conducted as a complement to any existing compliance programme, with a written report structured to integrate with your existing IEC 62443 documentation. Contact us to discuss your site.

Craig Miles is a wireless communications engineer and IEC 62443 practitioner with 30 years of RF and industrial radio experience, including aerospace satellite systems at Airbus Defence & Space. He is a 2023 TEDx speaker and PGCE Level 7 qualified engineer.


Need a standalone IEC 62443 wireless conduit assessment? Yesway is the only organisation offering a dedicated wireless conduit audit in the UK — covering SCADA telemetry, DMR, TETRA and unlicensed bands as a standalone service. Find out how the assessment works →

Author

  • craig miles

    TEDx Conversation

    Wireless communications engineer, technical educator and founder with 30 years of experience spanning aerospace, LEO satellite systems and RF engineering.

    Former ILS engineer at Airbus Defence and Space on NATO satellite and classified UK defence radio programmes.

    Founder of Yesway Communications — a Lincoln-based wireless communications specialist established in 2010, and ReachED, a new charitable initiative using LEO direct-to-device satellite connectivity to deliver education to the 273 million children globally without school access.

    TEDx Brayford Pool 2023 speaker. BSc · PGCE · QTS · Level 4 DSA Specialist Mentor · Ofcom Licensed · DBS Checked.