Why Zones and Conduits Make Machinery More Resilient

The Machinery Reg­u­la­tion has made Indus­trial Secu­rity a pre­req­ui­site for func­tioning Safety. Stan­dards such as IEC 62443 and the forth­coming EN 50742 rec­om­mend a clear approach: seg­ment automa­tion net­works into zones, con­trol com­mu­ni­ca­tions between them and specif­i­cally pro­tect safety-related func­tions. Andreas Willert, Head of Indus­trial Secu­rity at Pilz Aus­tria, explains how this works in prac­tice.

Dig­ital con­nec­tivity opens up new pos­si­bil­i­ties for machinery and indus­trial plants. At the same time, it increases the risk that safety-related func­tions may be affected by unin­tended changes or delib­erate manip­u­la­tion. For this reason, the Machinery Reg­u­la­tion (EU) 2023/1230 explic­itly requires safety func­tions to be pro­tected against such inter­fer­ence for the first time. As a result, Secu­rity has become a pre­req­ui­site for func­tioning Safety. To imple­ment these rather abstract pro­tec­tion objec­tives in prac­tice, machine man­u­fac­turers and oper­a­tors can rely on stan­dards such as the IEC 62443 series and the new EN 50742.

Security as a Prerequisite for Safety

Safety pro­tects people from haz­ards orig­i­nating from a machine. Secu­rity, in turn, pro­tects the safety func­tions them­selves from manip­u­la­tion and unau­tho­rised access. Only if safety-related sys­tems main­tain their integrity can they per­form reli­ably when needed.

Click here to view the con­tent from Vimeo.
Learn more in Vimeo’s pri­vacy policy (opens in a new tab).

Secu­rity for Safety explained: Why the Machinery Reg­u­la­tion makes Secu­rity a pre­req­ui­site for Safety and what this means for machine builders and oper­a­tors.

Zones Create Security

A widely recog­nised solu­tion is described in the IEC 62443 series of stan­dards through the “Zones and Con­duits” prin­ciple. Automa­tion net­works are divided into clearly defined areas, while com­mu­ni­ca­tion between these areas is per­mitted only through con­trolled con­nec­tions.

This con­cept fol­lows the defence-in-depth prin­ciple: mul­tiple pro­tec­tive layers secure the system. Even if one bar­rier is breached, addi­tional pro­tec­tive mea­sures pre­vent attacks or mis­con­fig­u­ra­tions from spreading throughout the net­work.

Click here to view the con­tent from Vimeo.
Learn more in Vimeo’s pri­vacy policy (opens in a new tab).

Zones and Con­duits in prac­tice: Our expert explains how net­work seg­men­ta­tion works and why con­trolled com­mu­ni­ca­tion paths enhance secu­rity.

Consistently Isolating Safety

Across its cur­rent port­folio, Pilz con­sis­tently applies a strict sep­a­ra­tion between Safety and stan­dard automa­tion. Safety func­tions run on ded­i­cated sys­tems that are iso­lated through log­ical, organ­i­sa­tional and tech­nical mea­sures.

Click here to view the con­tent from Vimeo.
Learn more in Vimeo’s pri­vacy policy (opens in a new tab).

Why iso­la­tion cre­ates secu­rity: Sep­a­rate sys­tems, reduced attack sur­face. Learn how the con­sis­tent iso­la­tion of safety func­tions increases pro­tec­tion while reducing effort.

The Benefits at a Glance

  • Reli­able Safety: Safety func­tions are pro­tected against unin­tended mod­i­fi­ca­tions, regard­less of what hap­pens within the stan­dard automa­tion envi­ron­ment.
  • Effi­cient Cyber­se­cu­rity: Appro­pri­ately matched secu­rity levels for each zone pro­tect net­works and data.
  • Reduced Effort: Updates, cer­ti­fi­ca­tions and mod­i­fi­ca­tions do not need to be car­ried out twice.
  • Lower Oper­a­tional Com­plexity: Oper­ating per­sonnel do not require exten­sive Secu­rity exper­tise because the archi­tec­ture inher­ently pro­tects Safety.
  • Higher Avail­ability: Diag­nostic data remains acces­sible without opening pro­tected areas.
  • Greater Flex­i­bility: Safety sys­tems such as safety con­trollers (e.g. the PNOZ­multi 2 con­fig­urable small con­troller) or safety relays (e.g. myPNOZ) can be inte­grated inde­pen­dently of the stan­dard automa­tion sup­plier.
  • Lower Costs: Reduced sup­port require­ments, fewer licences and fewer inter­ven­tions con­tribute to a lower total cost of own­er­ship.

Diagnostic information always available

Click here to view the con­tent from Vimeo.
Learn more in Vimeo’s pri­vacy policy (opens in a new tab).

Diag­nostic data despite seg­men­ta­tion: How impor­tant diag­nostic infor­ma­tion remains avail­able without opening the pro­tected Safety zone.

Knowledge Creates Security

In addi­tion to the right archi­tec­ture, exper­tise plays a cru­cial role. Through training courses such as “Fun­da­men­tals of Indus­trial Secu­rity” and the CESA (Cer­ti­fied Expert for Secu­rity in Automa­tion) cer­ti­fi­ca­tion, Pilz sup­ports com­pa­nies in assessing Secu­rity risks and designing secure net­work archi­tec­tures.

Click here to view the con­tent from Vimeo.
Learn more in Vimeo’s pri­vacy policy (opens in a new tab).

Plan securely, operate securely: The right exper­tise exactly where it is needed.

Com­pa­nies that con­sis­tently seg­ment and pro­tect safety func­tions not only meet nor­ma­tive and reg­u­la­tory require­ments. They also create the foun­da­tion for increased safety, higher avail­ability and more eco­nom­ical oper­a­tion throughout the entire machine life­cycle.

„The more Safety func­tions are iso­lated from the pro­duc­tion net­work, the better pro­tected they are.“

Andreas Willert, Head of Indus­trial Secu­rity, Pilz Aus­tria


Share with your network!


Did you enjoy reading?

(Be the first to give a rating!)

Leave a Reply

Your email address will not be published. Required fields are marked *.