CISA

Defending Against an Active Threat to Siemens S7 Series PLCs

From Cybersecurity and Infrastructure Security Agency ↗

Executive summary

Note: This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape.

Top Mitigations

Inventory all Siemens S7 Series programmable logic controllers (PLCs)

Apply critical security patches 

Ensure PLCs are not accessible from the Internet

Strengthen access controls

Monitor for unauthorized activity

Harden PLC services, protocols, and ladder logic integrity 

Hunt for anomalies that may indicate a compromise

The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), Federal Bureau of Inves...