< ciso
brief />
Tag Banner

All news with #iec 62443 tag

4 articles

FortiOS v7.6.x Achieves IEC 62443-4-2 SL4

🔒 Fortinet announces that FortiOS v7.6.x has achieved IEC 62443-4-2 Security Level 4 (SL4) certification, the highest component assurance level for industrial automation and control systems. This complements the company’s IEC 62443-4-1 ML2 accreditation for secure product development and validates FortiOS technical capabilities across identification, integrity, confidentiality, availability, and response requirements. The certification applies across FortiGate platforms running v7.6.x, reinforcing operational resilience for OT and critical infrastructure environments.
read more →

Threat-Informed OT Security for Critical Infrastructure

🔒 Operational technology (OT) environments differ fundamentally from IT and demand a threat-informed approach to security that balances safety, uptime, and continuity. Traditional IT controls can disrupt industrial processes, so visibility, asset context, segmentation, and collaboration between IT and OT teams are essential. Fortinet recommends phased, visibility-first segmentation aligned with ISA/IEC 62443, OT-aware policies, passive discovery, and tailored protections such as virtual patching and secure remote access.
read more →

Fortinet Achieves IEC 62443-4-1 ML2 Certification for SPDL

🛡️Fortinet has achieved IEC 62443-4-1 Maturity Level 2 (ML2) certification for its Secure Product Development Lifecycle (SPDL). This independent certification verifies that Fortinet’s secure development processes are formalized, documented, repeatable, and consistently applied across design, development, verification, validation, release, and maintenance of its security products. SPDL embeds threat modeling, secure-by-design engineering, automated and manual testing, supply chain integrity controls, and a transparent FortiGuard Labs PSIRT vulnerability disclosure process to improve product integrity for IT, OT, and critical infrastructure customers.
read more →

Global survey of 100 energy sites finds widespread OT risks

🔍 A study by OMICRON based on multi-year deployments of its StationGuard IDS across more than 100 substations, power plants, and control centers found pervasive cybersecurity and operational shortcomings. Passive network monitoring exposed unpatched PAC devices, undocumented external connections, weak segmentation, and incomplete asset inventories—issues often visible within 30 minutes of connection. The findings emphasize the need for protocol-aware, network-level detection and automated asset discovery to meet frameworks such as IEC 62443 and NIST.
read more →