• ISA provides technical resources and standards to help industrial automation professionals advance their careers and the field. We enable automation professionals worldwide to solve problems and enhance their skills by bringing people together to create new technologies and share best practices with future automation professionals.
    • Industry Insights

  • We attract over 140,000 unique automation professionals monthly, making us the premier online content provider and the only dedicated electronic magazine in the automation industry.

    Monthly Magazine

    • More things to read

    Back
    Back
  • M logo for Automation.com Monthly. Link to current issue.

Unraveling Cybersecurity Myths in Chemical Manufacturing: A Path to Safer, More Resilient Operations

By: Marco (Marc) Ayala
12 August, 2026
11 min read
Feature Image for Unraveling Cybersecurity Myths in Chemical Manufacturing: A Path to Safer, More Resilient Operations
Here are some common ISA/IEC 62443 myths that still trip up chemical manufacturers.

When digital intruders target the physical world  

Picture a petrochemical plant running steady in the dead of night — pipes humming, reactors holding pressure, safety systems standing watch over exothermic reactions that could release toxic clouds or trigger runaway events if anything goes wrong. Then a digital intruder slips in, not through the fence but through a vendor’s or integrator’s remote access to the engineering workstation or application server that someone thought was “just for diagnostics.” 

Safety systems start to blink. Pressures climb. Critical alarms that should be screaming are suddenly suppressed or inhibited, then buried in an overwhelming alarm flood. What should have been another routine shift suddenly edges toward potential disaster. 

This isn’t a movie script. In 2017, the TRITON (or TRISIS) malware hit a Saudi petrochemical facility and went straight for the Schneider Electric Triconex safety instrumented system (SIS). The attackers — later tied by the US Treasury to a Russian government research institute — reverse-engineered the proprietary TriStation protocol, exploited a zero-day and tried to reprogram the very controllers that keep explosions and toxic releases from happening. Only a coding slip that tripped the SIS into safe shutdown saved the day. 

Years earlier, Stuxnet — now known as part of Operation Olympic Games — had already shown the world that cyber payloads could physically destroy industrial equipment. In chemical manufacturing — where the materials are hazardous, the processes are continuous and the consequences are measured in lives, environmental impact and multi-million-dollar restarts — cybersecurity stopped being an “IT thing” a long time ago. It is process safety, plain and simple. Yet myths about how to protect these environments refuse to die. They slow down real progress and keep creating dangerous gaps between the cybersecurity team and the folks who actually run the units day after day. ISA/IEC 62443 was written precisely for this world. Developed by the International Society of Automation’s (ISA) ISA99 committee as an American National Standard (ANSI) and later adopted by the International Electrotechnical Commission (IEC), it gives us a risk-based, practical framework that respects 20- and 30+ year equipment life cycles, real-time demands and the fact that a cyber incident here can cause physical harm on a scale most IT professionals never have to consider.

I’ve been applying these standards — or their early drafts — since the ISA technical report that came out in 2004, well before the first published version of ISA/IEC 62443 in October 2007. That means two decades of working them out in the field at plant sites, mentoring teams through the real developments we’ve faced as industry and technology have shifted. And for the past decade, I’ve been teaching the standards in classrooms around the world, tailoring the material to the specific challenges each group of students brings from their own facilities. The myths below are the ones I still hear on almost every assessment I perform. Let’s clear them up once and for all.

Figure 1: © ISA Cybersecurity course IC32, International Society of Automation. Used with permission of ISA.

The digital shift: Opportunities and hidden perils

Digital tools have sharpened what we already do — real-time optimization of distillation columns, predictive maintenance on rotating equipment, tighter supply-chain visibility for raw materials and finished products. But every new connection widens the attack surface. Ransomware has already frozen chemical production lines for days. Espionage crews chase proprietary formulations that represent years of R&D investment. Manufacturing, especially chemicals, sits near the top of every threat list year after year. 

Advertisement

The old idea that our plants are somehow isolated is gone. Historians talk to corporate networks. Vendors dial in remotely. Wireless instruments and portable media move data in and out. A breach here doesn’t just steal files — it can tamper with a controller and turn a stable reaction into something far worse, perhaps even forcing an emergency shutdown that takes a week to safely restart. 

That’s why ISA/IEC 62443 matters. It’s modular and risk-based, built to be adopted in phases the same way we built our process safety programs over the years. ISA/IEC 62443-1-1 lays out the core concepts and models that hold the whole series together, 62443-2-1 spells out the asset-owner security program (especially useful now with the 2024 maturity model), 62443-3-2 gives you the practical steps for security risk assessment and designing the zones and conduits you actually need on the plant floor, 62443-3-3 defines the system security requirements and the four security levels you scale to real threats and 62443-2-4 makes sure your service providers and integrators are held to the same standard so the whole supply chain pulls its weight. The recent updates make it even more usable: 

  • ANSI/ISA-62443-2-1-2024 (January 2025) refreshed the asset-owner security program requirements for the first time since 2009. It added a maturity model for incremental progress, cleaned out overlap with IT-centric standards and reorganized everything into clear security program elements.
  • ISA-TR62443-2-2-2025 (December 2025) delivers practical day-to-day guidance on security operations and maintenance. 

Far from being academic, this is a roadmap written for the plant floor by people who understand that a controller reboot isn’t just an IT ticket — it can affect product quality, environmental compliance and the safety of everyone on shift.

Dispelling the myths: What really stands in the way  

These aren’t harmless old stories. They create complacency in an industry where one missed layer can cascade into a very bad day or near-miss or worse.

Myth 1: “Our control networks are air-gapped — we’re safe.”

I wish this were still true. Modern plants have dozens of connections — historian replication, vendor diagnostics, wireless instruments, USB/portable media transfers. TRITON didn’t “jump” the gap; it pivoted laterally from an engineering workstation that sat on both sides. In my assessments I routinely find hidden pathways that even the most experienced automation teams had forgotten about. 

ISA/IEC 62443’s zones-and-conduits model (Part 3-2) assumes those connections exist. It forces you to map every asset and every pathway, then put safety systems, business IT, wireless devices and temporary laptops in separate zones with controlled boundaries. Believing you’re air-gapped just means you’re flying blind.

Myth 2: “Proprietary protocols and firewalls make us bulletproof.”

Obscurity is not security. TRITON’s authors reverse-engineered the undocumented TriStation protocol. Stuxnet did the same with Siemens S7. Firewalls are useful, but they stop at the perimeter. Phishing, insiders, compromised vendor laptops and supply-chain attacks walk right past them. I’ve seen a single undocumented cellular modem located in the field bypass what everyone thought was an impenetrable perimeter, and a single infected vendor portable drive infect the control system. 

The standard answers with defense-in-depth — seven foundational requirements across four security levels (Part 3-3). No single technology carries the whole load.

Myth 3: “Our safety instrumented systems handle cyber threats, too.”

Safety instrumented systems (SIS), governed by ISA/IEC 61511 — the functional safety standard that grew out of the ISA84 working group and is further supported by technical report ISA-TR84.00.09 on cybersecurity related to the safety lifecycle — are built for equipment failures and operator errors, not for intelligent adversaries who study your exact configuration. TRITON went straight for the SIS because that’s the last line of defense. I’ve sat in PHA reviews where teams realized too late that their safety layer was sharing the same network as the basic process control system (BPCS, or DCS). 

Advertisement

ISA/IEC 62443 treats cyber and process safety as complementary but distinct. It puts safety systems in their own dedicated zones and gives additional rigor beyond ISA/IEC 61511 requirements. Conflating the two creates a single point of failure.

Myth 4: “Cybersecurity is IT’s problem.”

This one grinds my gears, and I hear this one constantly. But the people who truly own the risk are the automation engineers, instrument techs, process engineers, operators and plant leaders. Patching a controller means understanding what a reboot does to the reaction. Segmenting networks requires knowing which control loops talk to each other.  

The 2024 update to Part 2-1 makes it clear: this is the asset owner’s responsibility, and the risk assessment (Part 3-2) demands cross-functional input. Insider threats — 20–40 % of manufacturing breaches — can’t be fixed with firewalls alone.

Myth 5: “The standards are too complex and burdensome.”

Most chemical engineers already live inside the Occupational Safety and Health Administration’s (OSHA) Process Safety Management (PSM) requirements, the Environmental Protection Agency’s (EPA) Risk Management Program (RMP), ISA/IEC 61511 and layer of protection analysis (LOPA). ISA/IEC 62443 is an extension of that same mindset — consequence-based, layered, continuous improvement. 

Finally, the common gripe about complexity — “It’s too much — hundreds of pages, endless rules.” This usually stems from partial reads or outdated views. A bit of hands-on ISA cyber training often changes that perspective quickly. You don’t swallow the whole series on day one. Start with risk assessment and zone mapping, then scale controls to actual threats using the four security levels. The new maturity model lets you begin where you are and climb. Legacy systems? Compensating measures (data diodes, application control, allow-listing/whitelisting, enhanced monitoring) are explicitly allowed. The 2024 update even removed redundant ISO 27001 overlap. It’s leaner than it used to be, and I’ve helped plants implement it without adding a single new capital project.

Table 1: Five myths vs. ISA/IEC 62443 reality

Myth Reality in Chemical Contexts How ISA/IEC 62443 Addresses It
Air-gapped networks guarantee safety Modern integrations create hidden connectivity; attackers pivot through them to reach controls and safety systems Mandatory safety zone separation; ISA/IEC 62443 provides the cybersecurity rigor that 61511 was not designed to deliver
Proprietary tech and firewalls are bulletproof Protocols are routinely reverse-engineered; firewalls fail against phishing, insiders and supply-chain attacks Asset-owner accountability model; cross-functional risk assessment process (Parts 2-1, 3-2)
Safety systems handle cyber threats SIS are designed for equipment failure, not intelligent adversaries — TRITON proved they're high-value targets Maturity model and security program elements in 2024 update (Part 2-1); security levels allow right-sized controls (Part 3-3)
Cybersecurity is IT's job OT cyber requires engineering, operations, safety and leadership involvement; insider threats demand operational awareness  
The ISA/IEC 62443 framework is too complex Modular, risk-based, phased; maturity model enables incremental adoption; compensating countermeasures address legacy  

The real toll: Safety, downtime and compliance at risk

When these myths linger, the damage shows up in three places: process safety, reliability and regulatory readiness.   An attacker who manipulates BPCS readings while the SIS sits in the same unsegmented network can collapse every protection layer at once. TRITON showed exactly that path.

The human and financial cost of even a near-miss in our industry can be staggering. 

Ransomware on I/O tag servers, an HMI or historian doesn’t just slow production — it can stop it, and in continuous chemical processes the restart can take days. Legacy systems (15–30+ year life cycles) are the norm; ISA/IEC 62443 gives practical ways to manage them without a full rip-and-replace. One prolonged outage can easily run into the millions in lost production, plus the ripple effects through customers who depend on our intermediates. 

Advertisement

The Chemical Facility Anti-Terrorism Standards (CFATS) expired in July 2023, but the pressure hasn’t gone away. NIS2, reinterpretations of OSHA PSM and EPA RMP and global regulators increasingly point to ISA/IEC 62443 as the consensus standard. Building your program on it keeps you ready no matter which rule lands next — and it demonstrates to auditors and leadership that you take process safety and cybersecurity as two sides of the same coin.

Table 2: Operational impact of cybersecurity myths

Impact Area Key Effects Chemical-Specific Examples
Process Safety Undetected cyber vulnerabilities create exploitable gaps in safety layers Tampered SIS readings masking runaway reactions; compromised BPCS outputs causing unsafe actuator positions
Reliability Unplanned downtime from ransomware, unpatched systems or supply-chain compromise Legacy DCS failures halting ethylene cracking; historian ransomware stopping batch records and quality release
Regulatory Readiness Non-compliance risks fines, shutdowns or liability exposure Failed audits from unsegmented SIS networks; NIS2 gaps for EU-market chemical suppliers

Charting a practical course: Building defenses that fit real operations

Cybersecurity here is a process safety enabler, not a tax. Here’s a four-step path I’ve used successfully with chemical sites around the world.

Step 1: Map your environment and assess risk.

Define the full system under consideration — every asset, every overlooked connection. Pull in automation engineers, instrument techs, process engineers, safety pros, IT and operations. Use your existing PHA and LOPA data; don’t reinvent the wheel. Consequence categories should be safety, environmental, operational and regulatory — just like you already do. In practice, I always ask teams to walk the unit and physically verify what’s connected; paper diagrams rarely tell the whole story.

Chemical-specific tip: Your existing PHAs and LOPA studies already contain the exact consequence data you need for ISA/IEC 62443 cybersecurity risk assessments. The standard’s consequence-based approach fits seamlessly with the hazard analysis work chemical engineers already perform every day. Don’t start from scratch — build on what you have.

Step 2: Segment wisely — zones, conduits and security levels.  

Put safety systems in their own zone, separate from BPCS. Keep enterprise IT out with a proper DMZ. Treat vendor remote access and wireless devices as controlled conduits. Assign target security levels based on real risk — SIS usually needs the highest; a historian may not. The Purdue model (ISA-95) is a great starting scaffold; ISA/IEC 62443 simply adds the security lens. I’ve found that starting zone mapping with the most hazardous reaction or storage areas yields the biggest risk reduction quickly.

Advertisement

Step 3: Layer controls and build the culture

Implement the seven foundational requirements scaled to each zone’s target level. Eliminate shared passwords, enforce least privilege and MFA, deploy application whitelisting, use deny-all/permit-by-exception rules and monitor with OT-aware tools. For legacy gear, compensating measures work. 

Bake cybersecurity into the processes you already own: add a security impact check to management of change (MOC), include cyber scenarios in operator drills, require Software Bills of Materials (SBOMs) from suppliers. On one recent project we added a simple “cyber what-if” question to every MOC form and it caught several risky vendor changes before they reached the plant floor.

Step 4: Monitor, measure and adapt  

Track meaningful KPIs — mean time to detect/respond, zone coverage, patch/compensation status, MOC review completion. Reassess when the plant changes or threats shift. Align audits with your PSM/RMP cadence. Use the 2024 maturity model honestly; it’s a ladder, not a club. The plants that treat this as a living program, reviewed quarterly with the same discipline as their safety metrics, are the ones that stay ahead.

Table 3: Implementation roadmap

Phase Key Actions Chemical-Specific Tips
Scope & Assess Map all IACS assets and connections; conduct consequence-focused risk assessment with cross-functional team Leverage existing PHA/LOPA data; prioritize high-hazard reaction and storage areas
Zone & Secure Partition into zones/conduits; assign target security levels; mandate safety system separation Isolate SIS from BPCS; put vendor remote access in a DMZ; separate wireless devices
Build & Train Implement layered controls per zone; deploy compensating measures for legacy; embed cyber in MOC and training Use the maturity model for phased rollout; start where consequences are highest
Monitor & Adapt Track KPIs; reassess periodically; audit against target security levels; adjust as threats evolve Align audit cadence with PSM/RMP cycles; use gap analysis to drive investment priorities

Stewards of an indispensable industry

The chemicals we make feed the world, protect our water, build our devices and keep patients alive. Most people never think about that supply chain until it breaks. Fertilizers that grow the food on our tables, polymers in the medical devices that save lives, specialty gases that keep semiconductor fabs running, water-treatment chemicals that keep communities healthy — all of it flows from the plants we operate. 

That makes every one of us a steward of something irreplaceable. In an era of escalating threats, stewardship means facing the truth: air gaps are illusions, firewalls are not fortresses, safety systems are not cyber shields and this responsibility belongs to all of us.

ISA/IEC 62443 gives us the shared language and the practical tools we already understand — consequence analysis, layers of protection, continuous improvement. The 2024–2025 updates have made it even more accessible for the real-world plants we operate every day. 

The future doesn’t require perfection on day one. It asks for steady, honest progress — starting where the risk is highest, building defenses that fit our operations and sustaining the program with the same discipline we bring to process safety. We owe it to the communities around our facilities, to our colleagues on shift and to the global supply chain that depends on us. 

Let’s get to work. The process safety and industrial cybersecurity lifecycles are very well aligned:  “Analysis | Assess,” “Realization | Design & Implement,” “Operation & Maintain.”

This article is reprinted with the author's permission. © Chemical Engineering June 2026

Advertisement

Trending Articles

Advertisement

Related Articles

View all Articles and News
Advertisement
Advertisement