Reading in standalone mode. Open this treatise in the complete 2-Column Sovereign Research Wiki Engine:Open Wiki Dashboard (117 Treatises) →
SFAIR & SecRACSUnified Asset Graph

IEC 62443 in Practice: SFAIR, SecRACS, and Security Level Targets

100% Complete & Untruncated 15 min read
Return to Research Tracks

J. McKenney

This paper is part of the WG-05-CAD DEXPI body of work, applying the DEXPI/CycloneDX graph model to the delivery of IEC 62443 industrial cybersecurity programmes for high-density compute facilities. It sits alongside WG-05-CAD-Supply-Chain-EU-CRA, which addresses the equivalent regulatory execution gap under the EU Cyber Resilience Act, and WG-05-CAD-DEXPI-CycloneDX-Joint-Graph-Validation, which addresses the underlying joint-graph validation this paper's Multi-BOM integration depends on.

Licence: CC BY 4.0. 17 September 2026.

Executive Abstract#

IEC 62443 states what a secure facility must have: security levels, segmented zones, and technical requirements. It does not state how to reach them across a twenty-year facility lifecycle, and that is where compliance breaks down. A consultant draws a zone diagram, the organization declares itself compliant, and the procurement contracts and field commissioning tests never pick up what the diagram promised.

This paper closes that gap for high-density compute facilities with three practitioner tools. SFAIR is a seven-stage delivery methodology with formal review gates between capital phases. SecRACS turns a security level target into a binding, testable requirement in a contract with a system integrator. A mathematical bridge between functional safety levels and cybersecurity levels gives a safety-critical asset cyber hardening in proportion to what it needs.

It closes by working through the legal test for so far as is reasonably practicable that the obligation rests on, the regulatory cost test under the EU Cyber Resilience Act, and how a completed hazard register and evidence package changes the terms a facility can expect from cyber-physical reinsurance, including the state-backed cyber-attack exclusion that Lloyd's Market Bulletin Y5381 requires regardless of how well the facility is hardened.

Abstract#

IEC 62443 establishes the foundational requirements for securing Industrial Automation and Control Systems (IACS): security levels (SL 1 to SL 4), zone and conduit segmentation, and foundational technical requirements. It dictates what deliverables must exist but gives no guidance on how to execute an engineering programme across the twenty-year facility lifecycle. Organizations produce zone diagrams, declare compliance, and find that security requirements never reached procurement contracts or field commissioning tests. This paper operationalizes the standard for high-density compute facilities through three frameworks. SFAIR (Scope, Find, Assess, Implement, Review) is a seven-stage delivery methodology governed by formal Zone Completion Reviews (ZCR-1 through ZCR-7) that create auditable gates between capital phases. SecRACS (Security Requirements Allocation and Compliance Specification) is the contractual instrument that translates Security Level Targets (SL-T) into binding deliverables with deterministic acceptance criteria. SIL-to-SL Convergence, adapted from ISA TR 84.00.09 and CENELEC TS 50701, couples Safety Integrity Levels (IEC 61508) to Security Levels (IEC 62443) so safety-critical assets receive proportionate cyber hardening. We formulate the disproportionate cost test for So Far As Is Reasonably Practicable (SFAIRP) and As Low As Reasonably Practicable (ALARP) under EU Cyber Resilience Act (Reg 2024/2847) enforcement, integrate DEXPI 2.0 plant graphs with CycloneDX 1.6+ multi-BOM manifests, and set underwriting criteria for cyber-physical reinsurance treaties written alongside the state-backed cyber-attack exclusion that Lloyd's Market Bulletin Y5381 requires.


1. The Execution Gap in Industrial Cybersecurity#

In industrial infrastructure, a profound disconnect separates theoretical standards compliance from physical plant security:

  • The Static Audit Trap: Organizations hire consultants to conduct an IEC 62443-3-2 risk assessment. The consultants generate a high-level zone drawing, assign arbitrary SL-T ratings in a spreadsheet, and exit.
  • The Procurement Disconnect: When the mechanical and electrical teams issue Request for Proposal (RFP) tenders for Coolant Distribution Units (CDUs), switchgear, and chiller controllers, the cybersecurity specifications are omitted. Equipment arrives on site with cleartext Modbus TCP, unauthenticated web consoles, and zero component-level certifications.
  • The Construction Laydown Hazard: Equipment sits in unsealed construction laydown yards for nine months, connected to temporary contractor networks, operating with factory-default passwords before commissioning begins.
ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

2. Multi-BOM and DEXPI Process Topology Integration#

To enforce IEC 62443 requirements systematically, the cyber-physical architecture couples the DEXPI 2.0 plant schematic, whose equipment classes come from the ISO 15926-4 reference data library, with the CycloneDX 1.6+ multi-BOM specification:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

By binding DEXPI physical tags to CycloneDX multi-BOM manifests, the digital twin automatically verifies whether a delivered physical component satisfies the specific IEC 62443-4-2 component security requirements (CRs) demanded by its zone conduit assignment.


3. The Seven Stages of SFAIR Implementation#

The SFAIR methodology structures IEC 62443 delivery into seven stage-gated phases, each concluding with a formal Zone Completion Review (ZCR):

Table 18.1: The SFAIR seven-stage delivery methodology.

StageNameKey Engineering ActivitiesPrimary DeliverablesStage Gate
Stage 1Scope (S)Establish facility boundary; inventory physical assets from DEXPI P&IDs; identify safety-critical nodes.System Architecture Definition; Criticality RegisterZCR-1
Stage 2Find (F1)Network topology discovery; passive OT network capture; protocol inventory (Modbus, BACnet, DNP3).Asset Inventory Matrix; Communication Flow GraphZCR-2
Stage 3Find (F2)Zone and conduit partitioning; identify trust boundaries; classify external connectivity vectors.IEC 62443-3-2 Zone & Conduit DiagramZCR-3
Stage 4Assess (A)Execute CyHAZOP workshop; score RPNc\text{RPN}_c; execute SIL-to-SL convergence mapping.Consolidated Master Hazard Log; SL-T AssignmentsZCR-4
Stage 5Implement (I1)Author SecRACS contracts; mandate CycloneDX multi-BOM in RFPs; vendor design reviews.SecRACS Specification; Procurement Contract AddendaZCR-5
Stage 6Implement (I2)Factory Acceptance Testing (FAT); Site Acceptance Testing (SAT); verify optical data diodes.FAT/SAT Test Reports; SL-A Verification MatrixZCR-6
Stage 7Review (R)Third-Party Programme Director audit; annual penetration testing; continuous VEX monitoring.Certificate of Compliance; Reinsurance WarrantyZCR-7

4. SecRACS: The Contractual Negotiation Instrument#

Security Level Targets (SL-T) assigned during risk assessments are useless if system integrators and equipment vendors do not build them into physical equipment. SecRACS (Security Requirements Allocation and Compliance Specification) converts IEC 62443 requirements into binding legal contract addenda:

ARCHITECTURAL MAP← Swipe horizontally to inspect →
rendering diagram

Derived from functional safety practice (EN 50126 / IEC 61508), Security-Related Application Conditions (SecRACs) specify the operational assumptions and constraints that the asset owner must enforce in the physical plant for the component's certification to remain valid:

  • SecRAC-01: The CDU controller network interface must be connected exclusively to a dedicated, port-isolated switch port within Zone 1.
  • SecRAC-02: Remote engineering access is permanently prohibited across wireless or cellular interfaces; access requires physical key-switch activation at the local panel.
  • SecRAC-03: All setpoint recommendations from enterprise optimization algorithms must pass through a hardwired, rate-of-change clamping ladder logic PLC before reaching actuators.

5. SIL-to-SL Convergence: Mathematical Rigor#

In critical infrastructure, functional safety engineers speak in Safety Integrity Levels (SIL 1 to SIL 4 per IEC 61508), while cybersecurity leads speak in Security Levels (SL 1 to SL 4 per IEC 62443). The two disciplines must converge on a unified mathematical formulation.

5.1 The Mathematical Convergence Formulation#

Under ISA TR 84.00.09 and CENELEC TS 50701, a safety-critical component cannot maintain its functional safety rating if its cyber attack surface is undefended. The required Security Level Target SL-T(k)\text{SL-T}(k) for component kk is formulated as a function of its Safety Integrity Level SIL(k)\text{SIL}(k) and its cyber Risk Priority Number RPNc(k)\text{RPN}_c(k):

SL-T(k)=min⁡(4,  max⁡(1,  SIL(k)+⌊RPNc(k)−100150⌋))\text{SL-T}(k) = \min\left(4, \; \max\left(1, \; \text{SIL}(k) + \left\lfloor \frac{\text{RPN}_c(k) - 100}{150} \right\rfloor \right)\right)

Where:

  • SIL(k)∈{0,1,2,3,4}\text{SIL}(k) \in \{0, 1, 2, 3, 4\} is the baseline functional safety integrity level.
  • RPNc(k)=S(k)⋅Oc(k)⋅Dc(k)\text{RPN}_c(k) = S(k) \cdot O_c(k) \cdot D_c(k) is the cyber-induced risk priority number.

For the Coolant Distribution Unit (CDU) secondary pump assembly:

  • SIL=2\text{SIL} = 2 (loss of cooling trips the whole rack off power inside fifteen seconds).
  • RPNc=567\text{RPN}_c = 567 (Severity 9, Occurrence 7, Detection 9).
SL-TCDU=min⁡(4,  max⁡(1,  2+⌊567−100150⌋))=min⁡(4,  2+⌊3.11⌋)=min⁡(4,  5)=4\text{SL-T}_{\text{CDU}} = \min\left(4, \; \max\left(1, \; 2 + \left\lfloor \frac{567 - 100}{150} \right\rfloor \right)\right) = \min\left(4, \; 2 + \lfloor 3.11 \rfloor\right) = \min(4, \; 5) = \mathbf{4}

Because the cyber RPN is extreme, the target security level escalates from SL-2 to SL-4 (protection against sophisticated state-sponsored threat actors with significant resources).

5.2 Probability of Failure on Demand (PFD) under Cyber Attack#

Classical functional safety models component failure as random hardware degradation, calculating Probability of Failure on Demand (PFDavg\text{PFD}_{\text{avg}}). In the presence of cyber attacks, the total effective failure probability PFDtotal(t)\text{PFD}_{\text{total}}(t) becomes:

PFDtotal(t)=1−(1−PFDmech(t))⋅(1−Pcyber_exploit(t))\text{PFD}_{\text{total}}(t) = 1 - \left(1 - \text{PFD}_{\text{mech}}(t)\right) \cdot \left(1 - P_{\text{cyber\_exploit}}(t)\right)

Where:

  • PFDmech≤10−3\text{PFD}_{\text{mech}} \le 10^{-3} for SIL-3 safety loops.
  • Pcyber_exploit(t)=1−exp⁡(−λexploit⋅t⋅[1−SL-C/SL-T])P_{\text{cyber\_exploit}}(t) = 1 - \exp(-\lambda_{\text{exploit}} \cdot t \cdot [1 - \text{SL-C} / \text{SL-T}]).

If the achieved security capability SL-C\text{SL-C} is zero (unauthenticated Modbus TCP), Pcyber_exploit→1.0P_{\text{cyber\_exploit}} \to 1.0, completely invalidating the mechanical SIL rating and driving system failure probability to near-certainty.

5.3 SFAIRP Disproportionate Cost Test Ratio#

Under legal standards in the United Kingdom, European Union, Australia, and New Zealand, operators must reduce risk "So Far As Is Reasonably Practicable" (SFAIRP) or "As Low As Reasonably Practicable" (ALARP). An engineering safeguard must be implemented unless the cost of the control is grossly disproportionate to the risk reduction achieved:

DF=Cost of ControlRisk Reduction=CcontrolΔALE≤DFthreshold\text{DF} = \frac{\text{Cost of Control}}{\text{Risk Reduction}} = \frac{C_{\text{control}}}{\Delta \text{ALE}} \le \text{DF}_{\text{threshold}}

Where:

  • ΔALE=ALEprior−ALEpost\Delta \text{ALE} = \text{ALE}_{\text{prior}} - \text{ALE}_{\text{post}} is the annual expected monetary loss mitigated.
  • DFthreshold∈[2.0,  10.0]\text{DF}_{\text{threshold}} \in [2.0, \; 10.0] is the statutory Disproportion Factor. For catastrophic life-safety and multi-million-dollar physical hazards, courts mandate DF=6.0 to 10.0\text{DF} = 6.0\text{ to }10.0.

If mitigating a $14,500,000 USD CDU thermal runaway loss costs $450,000 USD:

DF=$450,000$14,500,000−$120,000=$450,000$14,380,000=0.0313≪6.0\text{DF} = \frac{\$450{,}000}{\$14{,}500{,}000 - \$120{,}000} = \frac{\$450{,}000}{\$14{,}380{,}000} = 0.0313 \ll 6.0

Because the cost of control is less than 3.2%3.2\% of the risk reduction, failing to implement the safeguard constitutes statutory gross negligence under EU CRA and common-law tort regimes.

5.4 Thermal Decay Governing Protection Speed#

When fluid circulation ceases in a 120 kW120\text{ kW} liquid-cooled rack, transient silicon junction temperature Tj(t)T_j(t) is governed by:

dTj(t)dt=Pdie−hconv(Q˙vol)⋅Adie⋅(Tj−Tcoolant)Cthermal\frac{dT_j(t)}{dt} = \frac{P_{\text{die}} - h_{\text{conv}}(\dot{Q}_{\text{vol}}) \cdot A_{\text{die}} \cdot (T_j - T_{\text{coolant}})}{C_{\text{thermal}}}

Where volumetric flow collapses from 122 L/min122\text{ L/min} PG25 to zero against an operating pressure of 6.0 bar, and a silicon heat flux of 75 W/cm275\text{ W/cm}^2 drives a junction temperature rate of change of 1.46∘C/s1.46^\circ\text{C/s} from a nominal junction temperature of 72.5 °C. The 94.0∘C94.0^\circ\text{C} emergency hardware shutdown trip point is reached within 14.8 seconds14.8\text{ seconds}, mathematically proving why SL-4 cryptographic rate limiters and hardwired SIL-3 thermal cutouts are non-negotiable SFAIRP mandates.

5.5 Return on Security Investment (ROSI) for SFAIR Programmes#

The programme-level financial return on implementing the SFAIR methodology across a 100 MW facility is quantified through:

ROSI=(ALEunmitigated−ALESFAIR)−CprogrammeCprogramme×100%\text{ROSI} = \frac{(\text{ALE}_{\text{unmitigated}} - \text{ALE}_{\text{SFAIR}}) - C_{\text{programme}}}{C_{\text{programme}}} \times 100\%

Where a comprehensive SFAIR implementation (Cprogramme=1,600,000 USDC_{\text{programme}} = 1{,}600{,}000\text{ USD}) reduces annualized loss expectancy from $17,403,000 USD to $1,850,000 USD, the modeled ROSI=872%\text{ROSI} = 872\%.

This figure is modeled, not measured. Three inputs drive it and the working group chose all three: the programme cost of 1,600,000 USD, the unmitigated annualized loss expectancy of 17,403,000 USD, and the residual 1,850,000 USD after the SFAIR controls are in place. No claims history, no operator loss run and no incident dataset is cited for any of them. The division is exact and reproduces to 872.06 percent, which is precisely why the number needs its assumption stated: a reader who checks the arithmetic confirms the arithmetic and learns nothing about the inputs. Halve the unmitigated ALE and the return falls to roughly 386 percent. Treat 872 percent as the output of a stated relation under stated assumptions, and re-run it against the facility's own loss data before it enters a business case.


6. The Master Hazard Register: Consolidated Facility Tracking#

The authoritative output of Stage 4 (Assess) is the Consolidated Master Hazard Register, mapping every facility node across CyHAZOP guide words, EMB3D threat properties, and MITRE ATT&CK for ICS techniques:

Table 18.2: Consolidated master hazard register.

Hazard IDNodeComponentDeviation ModeMITRE ATT&CKEMB3D PropertySL-TSOcO_cDcD_cRPNc\text{RPN}_cTable
HAZ-001N6CDU Pump AssemblyNO (Stop)T0814 (Denial of Service)Flow TamperingSL-4979567B
HAZ-002N6CDU Motorized ValveLESS (Throttle)T0836 (Modify Parameter)Valve State TamperingSL-4969486B
HAZ-003N2Block UPS InverterNO (Trip)T0858 (Change Operating Mode)Power Gating OverrideSL-3968432B
HAZ-004N1Substation RelayMORE (Delay)T0837 (Defeat Indicator)Protection BlindnessSL-31049360B
HAZ-005N5Chiller CompressorMORE (Temp)T0836 (Modify Parameter)Thermal Offset InjectionSL-3857280B
HAZ-006N8BMS SupervisoryCORRUPTEDT0869 (Manipulate State)SCADA RansomwareSL-2876336B
HAZ-007N10Gas SuppressionMORE (Discharge)T0814 (Denial of Service)Actuator Force-TripSL-3957315B
HAZ-008N15BESS Battery PackPOISONEDT0836 (Modify Parameter)Thermal OverchargeSL-31037210B

7. The Role of the Third-Party Programme Director#

The final stage of SFAIR (Review, ZCR-7) mandates an independent, certified Third-Party Programme Director:

  • Organizational Independence: The Programme Director reports directly to the Board Audit Committee and reinsurers, completely isolated from project schedule and budget pressures.
  • Physical Verification Authority: The Director verifies that every SecRAC condition is satisfied in the physical plant, witnesses Factory Acceptance Tests (FAT), and verifies cryptographic firmware hashes against CycloneDX manifests.
  • Issuance of Certificate of SFAIRP Due Diligence: The formal certificate issued by the Director provides the legal defense against gross negligence claims under EU CRA Article 64.

8. Actuarial and Reinsurance Treaty Structuring#

Operationalizing IEC 62443 through SFAIR and SecRACS transforms the facility's risk profile under international reinsurance treaties:

Underwriting ParameterLegacy Ad-Hoc FacilitySFAIR / SecRACS Assured FacilityActuarial Consequence
Property Catastrophe DeductiblePunitive $25,000,000 deductible; mandatory thermal sub-limits.$2,500,000 deductible; full affirmative replacement cost coverage.Working capital released; retention points optimized.
Business Interruption (BI) Sub-LimitsRestrictive $15,000,000 sub-limit; 7-day waiting period.Full affirmative BI coverage up to $75,000,000; 12-hour waiting period.Protection against multi-month equipment replacement queues.
Lloyd's Y5381 State-Backed Cyber-Attack ExclusionTotal claim denial during state-sponsored cyber campaigns.The exclusion Y5381 requires stays in the wording; what the evidence package moves is the underwriter's view of frequency and severity.Physical air gaps recorded in the as-built DEXPI topology and walked down on site by the loss adjuster give containment something inspectable.
Portfolio Accumulation Loading40% capital surcharge to protect against correlated cluster-wide blackout.0% accumulation surcharge; zones documented as decoupled, each carrying its own conduit inventory and its own power and cooling feed.Eliminates systemic capital loadings across multi-campus portfolios.
Consequential Loss ProtectionExcluded under standard mechanical breakdown policies.Affirmatively underwritten; full consequential loss indemnification.Statutory board liability completely hedged.

Every deductible, sub-limit and surcharge in the table above is a modeled placement, not a quoted one. The figures describe the terms this working group expects a syndicate to offer against an assured facility, and they are set from engineering judgment about what the evidence package is worth to an underwriter. They are not extracted from a bound slip, a broker submission or a treaty wording. Read them as the shape of the argument a facility can make with a complete hazard register in hand, and price the actual placement with a broker.


9. Summary of Engineering Principles#

Operationalizing IEC 62443 in practice establishes five immutable principles:

  1. Checklists Do Not Build Security: IEC 62443 deliverables must be executed through a stage-gated engineering methodology (SFAIR) with formal completion reviews.
  2. Contractual Binding is Mandatory: If security requirements are not written into SecRACS procurement addenda with acceptance criteria, they will not exist in the plant.
  3. Safety and Security Must Converge: Functional safety ratings (SIL) are invalid if cyber security levels (SL) are undefended. The two must be mathematically coupled.
  4. SFAIRP Demands Disproportionate Investment: Under modern regulatory and legal frameworks, operators must fund security controls unless their cost is grossly disproportionate to the risk.
  5. Independent Auditing Unlocks Capital: Third-party verification of physical and cryptographic invariants provides the verifiable evidence trail required to secure favorable reinsurance terms.

10. References#

The technical and legal claims above rest on the standards and instruments applied in the body text: IEC 62443 and its security-level framework, IEC 61508 functional safety, ISA TR 84.00.09 and CENELEC TS 50701 for the SIL-to-SL convergence, the EU Cyber Resilience Act (Regulation 2024/2847), DEXPI 2.0 and CycloneDX 1.6+ for the plant and bill-of-materials graphs, and Lloyd's Market Bulletin Y5381 for the state-backed cyber-attack exclusion. The financial and actuarial figures in sections 5 and 8 are this working group's own modeled scenarios rather than figures drawn from a claims history, an operator loss run, or a bound placement, and are disclosed as such where they appear.

Eigenia Labs Open Scientific Publishing Standard
Licensed CC BY 4.0
Exact Verification Audit: 25,595 chars