The challenge
A small electric vehicle assembler ran welding robots, battery-line PLCs and an office network that had grown into each other. The insurer's questionnaire asked ISA-99 questions the plant could not answer: which systems can reach the controllers, who did what and when, and how would you know if a record had been altered?
Our approach, zoned on IEC 62443
The deployment follows zones and conduits. Zone A is the control network: robots, PLCs, readers, untouched. Zone B is an operations DMZ holding the connector runner: the only software that speaks to Zone A (OPC UA, Modbus, reader host-mode), always initiating outbound, on its own host. Zone C is the business layer: dashboard, worker, database, users. Zone C never initiates into Zone A; the conduit map is short enough to draw on a whiteboard, which is precisely the point.
Component requirements (62443-4-2) are answered in the product: named accounts with MFA, five enforced roles with unit scoping, rate limits and circuit breakers, and two hash chains: the settlement ledger and the audit trail itself, both verifiable on demand. Every audit row and high-severity alert also leaves as a syslog line to the customer's SIEM.
What the assessor sees
The zone diagram matches the running processes. The audit chain verifies in front of them. Maintenance is a closed loop with work orders raised automatically when predictive risk crosses the line, which answers the availability questions insurers actually care about. The register carries IATF 16949, GB type approval and UNECE R100 alongside IEC 62443 itself, statused and superseded correctly.
The outcome
The insurer's questionnaire went from an embarrassment to an afternoon. Segmentation became something the plant can show, not describe. And the same evidence that satisfied the assessor runs the morning meeting.