OT Security All-in-One · Volume 3

IEC 62443, Governance, Compliance and Board by Kai London

Industrial operators now answer to more than one regulator, several standards and a supply chain that asks its own questions. Volume 3 turns that overlapping demand into a single governance system — one set of controls, one evidence base, and a board report that says something.

Available on Amazon.

What is inside

IEC 62443 as a governance spine

Using the standard as the organising structure that the other obligations map onto.

NIS2 and the Cyber Resilience Act

Scope, duties, incident reporting and product obligations for operators and manufacturers alike.

NERC CIP and sector regimes

Where prescriptive regulation differs from risk-based standards, and how to satisfy both without duplicating work.

Supplier and product risk

Assessing OEMs and integrators, security requirements in procurement, and evidence of product security claims.

Audit evidence

What to collect, where it lives, and how to show a control was operating across a reporting period.

Executive and board reporting

Industrial cyber risk expressed as consequence to operations, with the assurance behind each statement.

Who it is for: OT governance and compliance leads, internal and external auditors, procurement and supplier assurance, and the executives and directors of industrial and infrastructure operators.

IEC 62443NIS2Cyber Resilience ActNERC CIPISO/IEC 27001

One control set, one evidence base, many regulators. Anything else is a compliance treadmill.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.