OT security · Practitioner toolkit

IEC 62443 Implementation Toolkit by Kai London

Reading the standard is the easy part. This is the working kit — the registers, worksheets and evidence structures that turn IEC 62443 from a shelf document into a programme a site can actually run and an assessor can actually test.

Available on Amazon. An independent practitioner guide — not affiliated with or endorsed by any standards body or certification scheme.

What is inside

Zone and conduit registers

Templates for defining, documenting and maintaining zones and conduits that survive a plant change and an audit.

Risk assessment worksheets

High-level and detailed risk assessment structures, consequence scaling, and how to keep the results defensible.

Security level planning

Setting target levels, testing achieved levels, and recording the gap with a remediation route rather than an excuse.

Supplier and integrator requirements

Procurement language, acceptance criteria and handover evidence for system integrators and product suppliers.

Policies and procedures

The security programme documents an asset owner needs, written for people who maintain equipment, not lawyers.

Audit evidence packs

How to assemble, version and present the evidence so assessment does not become an archaeology exercise.

Who it is for: asset owners and OT programme managers building to IEC 62443, system integrators proving conformity to clients, and internal auditors testing industrial control environments.

IEC 62443NIS2NERC CIPNIST CSF 2.0
“

A control you cannot evidence is a control you do not have.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.