Build and run an industrial cybersecurity program that holds up in a working plant. This course covers the ISA/IEC 62443 series end to end — segmentation, security levels, risk assessment, supply chain, patching, monitoring and incident response — so you can protect the control systems that run a physical process without interrupting the process itself.
ISA/IEC 62443 is the international series of standards for the cybersecurity of industrial automation and control systems — the PLCs, distributed control systems, SCADA platforms, engineering workstations and safety systems that run physical processes in energy, water, manufacturing, transport and pharmaceuticals. It was developed jointly by the ISA99 committee and IEC Technical Committee 65, and is organised into four groups covering general concepts, policies and procedures, system design, and component development.
What separates the series from IT security frameworks is that it is written around the realities of an operating plant. Safety and availability come first, and a control system cannot simply be rebooted to apply a patch. The standards answer that with zones and conduits for segmentation, seven foundational requirements, and security levels that let you specify how much protection each zone genuinely needs instead of applying a single standard everywhere.
Industrial cybersecurity has moved from an engineering concern to a board-level and regulatory one. Operators across critical sectors are now expected to secure their industrial systems to the same standard as their corporate IT, and ISA/IEC 62443 is the framework most widely adopted to do it. People who can lead that work are genuinely scarce, and this course is built to close that gap.
Everyone who takes this course sits the same exam — the PECB Certified ISA/IEC 62443 Lead Implementer exam. What differs is which credential you can apply for afterwards, based on the experience you can evidence. There is no separate exam or extra study for a higher tier; it is the same certification, recognised at a level that matches your background.
| Credential | Professional experience | IACS project experience |
|---|---|---|
| Provisional Implementer | None | None |
| Implementer | 2 years (1 in industrial automation and control management) | 200+ hours of project activity |
| Lead Implementer | 5 years (2 in industrial automation and control management) | 300+ hours of project activity |
| Senior Lead Implementer | 10 years (7 in industrial automation and control management) | 1,000+ hours of project activity |
IACS stands for Industrial Automation and Control Systems — the operational technology that makes a physical process happen, as opposed to the IT that moves data around. Time spent designing, operating, maintaining, securing or managing PLCs, DCS, SCADA, HMIs, safety instrumented systems and the networks they sit on all counts.
Each tier sets two bars rather than one. Lead Implementer, for example, asks for five years of general professional experience, of which two must be specifically in industrial automation and control management, plus 300 documented project hours. Every tier also requires signing the PECB Code of Ethics.
Coming from an IT security background with no plant time yet? You will qualify for Provisional Implementer immediately after passing — a fully valid PECB credential — and can apply for a higher tier later as your industrial experience builds, without retaking the course.