Most IEC 62443 zoning exercises fail for the same reason: they start from a generic reference diagram instead of the facility's actual engineering reality. A defensible zone model has to be built from your process, not borrowed from a textbook.

Start with consequence, not topology

Before drawing a single boundary, list the physical consequences that matter most at this facility -- safety shutdowns, process integrity, environmental release, production loss. Assets that share a consequence profile are strong candidates to sit in the same zone. Assets with very different consequence profiles almost never belong together, even if they happen to sit on the same physical network segment today.

Define conduits by purpose, not by cable

A conduit is not simply 'the wire between two zones' -- it is a defined communication relationship with a specific, documented purpose. 'Vendor remote access for SCADA support' and 'historian data replication to the corporate reporting server' are two different conduits, even if they happen to traverse the same physical firewall, because they should be governed by different rules, different monitoring, and different approval processes.

Set SL-T deliberately, not by default

Every zone needs a deliberately chosen Target Security Level, justified by the consequence of compromise, not defaulted to whatever level the vendor's product happens to support. A safety instrumented system zone and a non-critical environmental monitoring zone should almost never share the same SL-T.

Validate before you trust it

A zone boundary that has never been tested is a hypothesis, not a control. Firewall rule reviews, segmentation testing, and periodic validation that no undocumented conduit has appeared are what turn a zoning diagram into an actual, defensible security boundary.