Lincoln 01522 740818 Hull 01482 520818
Shop certified radios

Wireless Communications Blog

SCADA Wireless Telemetry and IEC 62443 – The Conduit Nobody Is Assessing | Yesway

Of all the wireless conduits that appear — or more accurately, fail to appear — in IEC 62443 assessments, SCADA wireless telemetry links are the most consistently overlooked. Not the voice radio network, which at least has a visible presence in the form of handsets and repeaters. The telemetry links: the low-power radio connections carrying process data between remote assets and control rooms, often running on unlicensed frequencies, often installed years ago by a controls engineer rather than a radio specialist, and almost never documented in any security assessment. These links carry some of the most operationally sensitive data on an industrial site. They connect directly to control systems. They often run without encryption. And they are essentially invisible to the IT and OT cybersecurity professionals conducting most IEC 62443 assessments — because finding them requires RF engineering knowledge, not cybersecurity knowledge. This post explains what SCADA wireless telemetry links are, why they are a specific IEC 62443 compliance gap, and what a correct assessment looks like. What SCADA wireless telemetry links are SCADA — Supervisory Control and Data Acquisition — systems monitor and control industrial processes. They collect data from sensors, actuators, and PLCs distributed across a site or across a wide geographic area, and they transmit control commands back to those field devices from a central control room. Many SCADA systems use wireless radio links to carry this data — either because the distances involved make wired connections impractical, because the terrain makes cable laying prohibitively expensive, or simply because wireless was the most pragmatic solution when the system was installed. These wireless telemetry links are common in water and wastewater utilities (connecting remote pump stations and reservoirs), energy (connecting substations, wind turbines, and solar arrays), oil and gas (connecting wellheads and pipeline monitoring points), and agriculture (connecting irrigation and environmental monitoring systems). The frequencies used vary widely. Licensed links typically use VHF (136–174MHz) or UHF (403–470MHz) bands under Ofcom SCADA or fixed link licences. Unlicensed links — and there are more of these than the industry acknowledges — frequently use the 433MHz ISM band, the 868MHz SRD band, or proprietary systems operating on frequencies that may or may not be correctly licensed. The data carried is not peripheral. A SCADA telemetry link connecting a remote pump station to a water utility control room carries pump status, flow rates, pressure readings, alarm states, and in many cases the control commands that start and stop pumps. Compromising that link — through interception, replay attack, or signal injection — has direct operational consequences. Why they are almost never in the IEC 62443 zone diagram Three factors combine to make SCADA wireless telemetry links systematically invisible in IEC 62443 assessments. They were not installed by the IT or OT team. Most SCADA wireless telemetry links were installed by the controls engineer or the SCADA system integrator who specified the overall system, often years or decades ago. They are not in the IT asset register. They may not be in any asset register. The OT security team conducting the IEC 62443 assessment may not know they exist. They are not visible on the network diagram. A wireless telemetry link does not appear as a connection on a network switch or firewall. It exists in the RF domain — which means it is only visible to someone who knows to look for it, and who has the RF engineering background to identify it. The assessors do not conduct RF surveys. Finding wireless telemetry links requires an RF survey — physically walking the site with appropriate test equipment, scanning for transmissions, and identifying links that may not appear in any documentation. IT and OT cybersecurity assessors do not typically conduct RF surveys. It is not part of their methodology. So the links go undetected. The result is a zone-and-conduit diagram that shows the SCADA system connected to field devices — but shows that connection as if it were wired, with no representation of the wireless conduit that actually carries the data. The conduit is unassessed. The security controls on it are unreviewed. The risk it represents is unquantified. What IEC 62443 requires for a SCADA telemetry conduit The IEC 62443 requirements for a SCADA wireless telemetry conduit follow the same zone-and-conduit framework as any other conduit — but the specific controls required are particularly challenging for wireless links, because wireless adds attack vectors that wired connections do not have. Under IEC 62443-3-2, the conduit must be identified and documented. A Security Level target must be assigned based on the consequence of compromise. For a conduit carrying SCADA control data — data that directly affects physical process operation — the consequence of compromise is typically significant, and SL2 is frequently the minimum appropriate target. In high-consequence environments such as water supply or power generation, SL3 may be warranted. Under IEC 62443-3-3, the technical controls for SL2 applied to a SCADA wireless telemetry conduit include: Data confidentiality (FR4): Transmissions must be encrypted. Many SCADA wireless telemetry systems — particularly older systems using proprietary protocols — transmit data in clear text. This is a direct SL2 failure for FR4. Data integrity (FR3): The conduit must protect against unauthorised modification of transmitted data. This requires both encryption and message authentication — ensuring that a transmitted control command cannot be intercepted and replayed, or that a fabricated command cannot be injected into the link. Many proprietary SCADA wireless protocols have no message authentication. Identification and authentication (FR1): Devices communicating over the conduit must be authenticated. A wireless telemetry link where any device transmitting on the correct frequency can inject data into the SCADA system does not meet FR1 at SL2. Availability (FR7): The conduit must maintain availability against denial of service. A wireless link is inherently more vulnerable to jamming and interference than a wired connection — and the availability controls for a wireless SCADA conduit must address this specifically. Frequency agility, signal strength monitoring, and fallback communication paths are relevant controls. The unlicensed frequency problem A significant proportion of SCADA wireless telemetry links in UK industrial environments are operating on unlicensed or incorrectly licensed frequencies. The 433MHz ISM band — widely used for short-range telemetry — is a shared, unlicensed band. Any device can transmit on it. There is no protection from interference. There is no regulatory mechanism to identify or exclude rogue transmitters. For a SCADA telemetry link carrying operational or control data, operating on an unlicensed shared frequency is a significant security and availability risk. It also indicates that the radio link was not professionally specified — which is itself a finding under IEC 62443’s security management requirements. Links that should be on licensed frequencies — VHF or UHF SCADA licences from Ofcom — are sometimes found operating without the correct licence. This creates both regulatory exposure under the Wireless Telegraphy Act 2006 and a security gap: a licensed link has a degree of frequency exclusivity and regulatory protection that an unlicensed link does not. Licence compliance verification — checking that every wireless telemetry link is operating on a correctly licensed frequency with the correct equipment type — is a foundational step in any SCADA wireless conduit assessment, and one that requires RF engineering knowledge rather than cybersecurity knowledge to execute. What a correct SCADA wireless telemetry assessment looks like A complete assessment of SCADA wireless telemetry links within an IEC 62443 programme has four components. Link discovery: An RF survey to identify all wireless telemetry links operating on the site — including those not in any documentation. This requires scanning across relevant frequency bands, correlating detected signals with known SCADA system architectures, and identifying any links that cannot be attributed to known licensed equipment. Protocol and encryption assessment: For each identified link, determination of the protocol in use (proprietary, DNP3 over radio, Modbus over radio, or other), whether encryption is implemented, and whether message authentication is in use. For proprietary protocols, this may require traffic capture and analysis. Licence compliance verification: Confirmation that each link is operating on a correctly licensed frequency under the appropriate Ofcom licence category, with equipment that matches the licence conditions and type approval requirements. Zone boundary mapping and Security Level gap analysis: Identification of which IEC 62443 zones the link connects, assignment of a Security Level target based on the data carried and the consequence of compromise, and gap analysis of current controls against that target. The output is a documented wireless telemetry conduit assessment that integrates with the site’s existing IEC 62443 zone-and-conduit model — filling the gap that the cybersecurity assessment left. The practical starting point For most industrial sites, the starting point is simple: ask whether your existing IEC 62443 zone diagram includes your SCADA wireless telemetry links. If it does not — and for most sites, it will not — you have an unassessed conduit carrying operationally significant data, potentially without encryption, potentially on an unlicensed frequency, and sitting outside your current compliance posture. Yesway Communications provides IEC 62443 industrial radio and wireless conduit assessments covering SCADA wireless telemetry links, voice radio networks, and all other wireless conduits on an industrial site. Assessments include RF survey, protocol and encryption analysis, licence compliance verification, and a written gap analysis report structured for integration with your IEC 62443 programme. Contact us to arrange a free 30-minute scoping call. Craig Miles is the founder of Yesway Communications and a wireless communications engineer with 30 years of experience across RF, industrial radio and satellite systems — including ILS engineering at Airbus Defence and Space on NATO satellite programmes. BSc · PGCE · QTS · Ofcom Licensed. IEC 62443 industrial radio security services.

Need a standalone IEC 62443 wireless conduit assessment? Yesway is the only organisation offering a dedicated wireless conduit audit in the UK — covering SCADA telemetry, DMR, TETRA and unlicensed bands as a standalone service. Find out how the assessment works →

Author

  • craig miles

    TEDx Conversation

    Wireless communications engineer, technical educator and founder with 30 years of experience spanning aerospace, LEO satellite systems and RF engineering.

    Former ILS engineer at Airbus Defence and Space on NATO satellite and classified UK defence radio programmes.

    Founder of Yesway Communications — a Lincoln-based wireless communications specialist established in 2010, and ReachED, a new charitable initiative using LEO direct-to-device satellite connectivity to deliver education to the 273 million children globally without school access.

    TEDx Brayford Pool 2023 speaker. BSc · PGCE · QTS · Level 4 DSA Specialist Mentor · Ofcom Licensed · DBS Checked.