PLC Cybersecurity: What the 2026 CISA Alerts Mean
October 5, 2026 | Samantha Mariano
If your plant runs on Allen-Bradley or Siemens controllers, the federal warnings issued over the past few months were written with you in mind. Between April and August 2026, CISA, the FBI, the NSA, the EPA, and the Department of Energy released a series of advisories warning that attackers are actively going after programmable logic controllers that can be reached from the internet. The most recent one lists Critical Manufacturing first among the sectors most targeted.
This isn't a post about firewalls and IT policy. It's about the controllers, panels, modems, and remote connections that live on your plant floor, and the practical steps your maintenance and controls teams can take right now.
Three Warnings in Five Months
April: Rockwell Controllers Targeted
On April 7, 2026, federal agencies released advisory AA26-097A. It described Iranian-affiliated actors using Rockwell's own programming software to connect to internet-exposed CompactLogix and Micro850 PLCs. A July 22 update widened the scope to include Schneider Electric Modicon M340 and Siemens S7-1200 controllers.
July: Operators Locked Out
In late July, more than 30 community water systems in Minnesota were targeted in a coordinated attack. On July 30, the FBI and EPA warned that utilities in at least seven states had reported incidents involving internet-facing Allen-Bradley MicroLogix 1100 and 1400 PLCs. In several cases, the attackers changed IP addresses and passwords, and operators lost the ability to monitor and control their systems. Closer to home, Columbus Water Works in Georgia confirmed an incident and switched to manual operations, with no impact on the water supply.
August: Siemens S7 Controllers in the Spotlight
On August 19, five federal agencies released joint advisory AA26-231A. It warns that threat actors are using AI-assisted scripts, disguised to look like ordinary monitoring tools, to probe exposed Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500 controllers, including F-series safety PLCs. The advisory makes clear this is an active threat, not a hypothetical one.
Why Manufacturers Can't Treat This as a Water Problem
Most of the headlines focused on water towers and lift stations, but the controllers involved are the same ones running conveyors, mixers, packaging lines, and process skids in plants across the Carolinas, Georgia, Texas, Ohio, and beyond. AA26-231A names Critical Manufacturing, Energy, Chemical, and Food and Agriculture right alongside water.
The other detail worth noticing is that there's no single patch that makes the problem go away. According to the advisory, attackers are taking advantage of known weaknesses, default or weak passwords, and controllers that never should have been reachable from outside the plant. That means most of the fix comes down to configuration and architecture, and a lot of that work happens inside the control panel.
Where Exposure Actually Hides on the Plant Floor
When we walk a facility, the risky connections are rarely the ones on the network drawing. They usually look like this:
- Cellular modems inside panels. A modem added years ago so an OEM or integrator could dial in for support, still powered and still connected.
- Vendor remote access that never got shut off. A temporary connection from a startup or warranty period that quietly became permanent.
- Flat networks. Office PCs, HMIs, and PLCs all sitting on the same network with nothing separating them.
- Engineering laptops. Machines loaded with programming software that travel between the plant, home, and other job sites.
- Key switches left in Remote or Program. On controllers with a physical mode switch, leaving it out of Run makes remote program changes possible.
None of these are unusual. They're leftovers from normal projects, which is exactly why they get missed.
A Practical Checklist for Plant and Controls Teams
The federal advisories and the manufacturers' own guidance point to the same core actions. Here's how they translate to the plant floor:
- Inventory every controller. Record the make, model, firmware version, location, and what each one controls. You can't protect a PLC you don't know about.
- Find every path to the internet. Trace each controller's network connections, including modems and vendor gateways. If a PLC doesn't need to be reached from outside, disconnect it. If remote access is truly needed, route it through a secure gateway or VPN with multifactor authentication.
- Put the key in Run. For controllers with a physical mode switch, federal guidance recommends keeping it in Run to block remote changes to the program.
- Back up logic offline and compare it. Keep tested copies of PLC programs and configurations on secured offline media, and periodically compare what's running against your known-good version.
- Change defaults and turn on protection. Replace default passwords, enable the controller's built-in password and access protection, and disable services you don't use.
- Patch on a plan. Firmware updates matter, but test them before they go into production and schedule them during planned outages.
- Bring your integrators and contractors in. AA26-231A specifically tells owners who rely on integrators or service providers to share the advisory with them and ask them to put the recommendations in place.
Any hands-on work inside control panels still falls under your electrical safety program, so make sure proper lockout/tagout procedures are followed before anyone pulls modems or swaps hardware.
Where Security Meets Controls Upgrades
Older controllers often lack the security features found on newer platforms, and some can't be updated at all. If your review turns up controllers that are near or past end of life, it makes sense to fold security into your upgrade planning. Our post on planning an obsolete PLC upgrade walks through how to prioritize.
Any change to controllers, firmware, or network wiring should also be verified before production restarts. That means confirming I/O still reads correctly with a proper loop check wherever signals were disturbed, and following a structured commissioning process for larger changes.
How HRE Can Help
HRE Construction is an industrial electrical and instrumentation contractor. We're not a cybersecurity firm, and we don't replace your IT or OT security team. What we do is handle the physical and controls side of the work, safely and with clear documentation. That includes:
- Walking your facility to inventory PLCs, HMIs, I/O, and the network and modem hardware inside your control panels
- Documenting controller models, firmware versions, and connections so your security team has an accurate picture
- Removing unneeded modems and network hardware, and rewiring panels to support the segmented network your team or integrator has designed
- PLC program backups and backup verification for Allen-Bradley, Siemens, ABB, Modicon, and Automation Direct platforms
- Firmware updates and controller replacements during planned shutdowns, followed by testing and startup
- Controls upgrades when legacy hardware can't be properly secured
Learn more about our instrumentation and PLC services.
Don't Wait for a Lockout to Find Out
The facilities that handled this summer's attacks best were the ones that could switch to manual operation and knew exactly what was connected to what. If you aren't sure how many of your controllers can be reached from outside your plant, that's the place to start.
Contact HRE Construction to request a quote for a controls walkdown, PLC backup and inventory, or upgrade planning. We serve industrial facilities across 11 licensed states, including South Carolina, North Carolina, Georgia, Ohio, and Texas.
Frequently Asked Questions
What is PLC cybersecurity?
PLC cybersecurity is the set of practices that keep programmable logic controllers from being accessed or changed by unauthorized people. For most plants, that means keeping controllers off the public internet, controlling remote access, changing default passwords, enabling built-in protection features, and keeping verified offline backups of PLC programs.
Which PLCs did the 2026 federal advisories warn about?
AA26-097A covered Rockwell CompactLogix and Micro850 PLCs and was later expanded to include Schneider Modicon M340 and Siemens S7-1200. The July FBI and EPA warning involved Allen-Bradley MicroLogix 1100 and 1400 controllers. AA26-231A covers Siemens S7-200, S7-300, S7-400, S7-1200, and S7-1500, including F-series safety controllers. The agencies stress that other brands should apply the same protections.
Is there a patch that fixes the problem?
No single patch addresses it. The advisories describe attackers taking advantage of known weaknesses, default or weak passwords, and unnecessary internet exposure. Firmware updates help, but removing internet exposure, securing remote access, and hardening controller settings are the main defenses.
Does setting the PLC key switch to Run really help?
For controllers with a physical mode switch, federal guidance recommends keeping it in Run to prevent remote program changes. It's one layer of protection, not a complete fix, and it works best combined with network isolation, strong passwords, and offline backups.