The PLCs Were Not Hacked. They Were Logged Into.
It is 11:40 on a Tuesday night and line 3 is down. The controls engineer lives ninety minutes away. The OEM's support tech in another state needs to see the drive fault himself, so someone walks out to the panel, plugs the cellular modem back in, and reads him the number off the label.
He connects. He clears the fault. The line runs by midnight and the order ships on time.
Nobody unplugs the modem.
Three years later it is still there. It is not on the network diagram. It is not in the asset inventory. The integrator who installed it has been acquired. The engineer who read the number off the label works somewhere else now.
The Assumption
Underneath that night is a belief most plants run on without saying out loud.
Security is something you add to operational technology after it is running.
The machine comes first. It proves itself on the floor. Then someday, when there is budget and a slower quarter, someone comes back and secures it. Security as a project. A thing you bolt on.
1. Why That Made Sense
It used to be true, and every incentive pointed that way.
- The RFQ never asked. It covered cycle time, tooling, changeover, spare parts, and uptime. It did not ask how the machine authenticates a remote session or what it is permitted to talk to.
- Ownership was split. The OEM owned the controls. The integrator owned commissioning. IT owned the office. Nobody owned the space between the panel and the switch.
- The machine really was alone. One HMI. One panel. No path off the line.
Only the third has changed. The gap the other two leave has a familiar sound. IT says it is the machine. The vendor says it is the network. The line is down and somebody is standing in the middle with no answer.
2. What Changed
The connection did not arrive in one decision. It arrived in a hundred small reasonable ones.
- Remote support became the warranty model. The OEM needed a way in, so the OEM got one.
- Analytics needed tag data. The historian needed a path up to MES and ERP.
- Firmware needed updating without flying someone out.
Each was right in the moment. The result is a plant floor built to be isolated that is now reachable, and no one decided that.
3. What the Advisories Actually Say
It started with water utilities. Since late July, utilities in at least seven states have reported incidents to the FBI, and some of that activity degraded operations.
Now read what the FBI, EPA, and CISA published, and notice what is not in it.
No zero day. No custom malware. The joint advisory states it directly: it is not highlighting a new vulnerability. It is describing opportunistic targeting.
What is in it:
- Small controllers you probably own. The FBI named Allen-Bradley MicroLogix 1100 and 1400. The joint advisory adds CompactLogix, Micro850, Modicon M340, and S7-1200. Not exotic utility gear. These are the controllers bolted inside OEM skids on plant floors.
- The attackers turned the passwords on. After reaching internet-facing devices, they changed IP addresses and set passwords, causing a loss of monitoring and control. The protection was sitting there waiting to be enabled. The intruder configured it. The owner never had.
- The plant's own engineering software. Studio 5000, TIA Portal, and EcoStruxure on rented infrastructure. The same tools your integrator opens on a Tuesday. Project files were pulled out and altered.
- Undocumented cellular connections. CISA warned these get installed by operators, vendors, or integrators and may never appear in a routine scan. At one victim, the actors installed their own SSH service on the modem to hold the door open.
- The integrator's template. The FBI noted that similar network setups provided by third parties can let one working technique multiply across that provider's other customers.
Read that last one twice. Your exposure may not be a decision you made. It may be a build standard you inherited.
They did not break the PLC. They logged into it.
But We Have a VPN Gateway
Most manufacturers reading this are ahead of a small municipal utility. There is a real gateway at the edge with multifactor authentication on it. That is the right control, and the advisory recommends exactly that. It is also not the same thing as knowing what happens after someone is through it.
Look at how the agencies wrote it. A gateway in front of the PLC is one mitigation. Access control lists, so only expected control devices can talk to each other, is a separate one. They are listed apart because they do different jobs.
A gateway answers who gets in. An ACL answers what they can reach.
If the tunnel lands on a flat controls network, the OEM who came to look at one drive fault can see every controller on the floor. The gateway did its job. The specification never said where the job ended.
4. What It Actually Costs
When a controller is compromised, the failure does not look like a data breach. It looks like a production event.
The shift. The operator loses the HMI. The credentials stop working. The line goes manual or it goes down.
The program. Then the harder question. Who has the last known good project file? Not the department. The person. On most floors the honest answer is the integrator, and on too many floors that integrator no longer exists under the same name. Federal guidance now tells operators to compare the running program against known good logic. You cannot run that check without a copy you trust.
The instrumentation. In one case the FBI found a downloaded project file that left the downstream ladder logic intact while adding logic that overrode the instructions holding safe operating parameters. Shutdown and alarm logic went dead, and the operator displays were altered to match. Equipment ran outside safe conditions and the screen said everything was fine.
The paperwork. Everything produced during the window is suspect. Batch records do not reconcile. Your customer's supplier quality group asks what changed, and the honest answer is that something did and you did not authorize it. Now you are writing a corrective action and facing requalification on a process nobody meant to touch.
The line stop is one shift. The paperwork is one quarter.
Security Is a Specification, Not an Upgrade
Here is the sentence that should end the argument.
The advisory says plainly that it is not highlighting a new vulnerability in these products. Seven federal agencies looked at disrupted infrastructure and found no flaw to patch. They found equipment installed in a way that made the attack unnecessary.
There is no upgrade for that. There is only how it was specified.
The government has now said as much. The advisory points owners to a guide called Secure by Demand, built to help OT owners put security requirements into the selection of digital products. Not after go-live. At selection.
That is an RFQ document with a federal seal on it.
A specification sits on the RFQ next to cycle time and spare parts. It answers four questions:
- How does this machine authenticate a remote session?
- Who is allowed to reach it, and what is the tunnel permitted to touch?
- What is the machine permitted to talk to on its own?
- Who holds the current program, by name?
An upgrade is what you fund after the fact, if there is money left, which there rarely is.
Specified means it arrives correct. Bolted on means undoing four years of reasonable decisions with the line running.
The practical test fits on one line.
If it connects, it is in scope.
Not if it is critical. Not if it is new. If it has a path, it belongs in the inventory, in the segmentation plan, and in the next specification.
How We Approach It
At InsITe we start by mapping what is actually connected, not what the diagram claims, because those two are almost never the same. We put the controls team and the IT team in one room to decide what each asset is allowed to reach, so there is one team and one call when something breaks at the boundary. Then we write those decisions into the specification for the next machine, before it ships. We stay after go-live, because a specification nobody maintains is just a document.
Three Questions Worth Sitting With
If your largest OEM lost remote access tomorrow morning, how long would it take you to notice?
Who holds the current program for your most constrained line? Name the person, not the department.
When your OEM comes through the gateway to look at one machine, what else can they see?
The Curve You Are Already On
The utilities that got hit were not careless. Their equipment became connected faster than their specifications did.
Manufacturing is on the same curve, with the same controllers, and more of them.
You cannot bolt on what you never specified.
Security is a specification, not an upgrade.
ABOUT INSITE BUSINESS SOLUTIONS:
Most West Michigan manufacturers know they need to connect their shop floor systems with their business systems. But figuring out how to bridge that gap is like playing vendor roulette. They often end up picking either an IT shop or an automation house, or a combination of both.
InsITe has IT and OT engineers on staff. One call, one team, one point of accountability across the full tech stack. Before we recommend anything, we walk your shop floor and then design the solution, execute the implementation, and own the outcome through managed services, security, and ongoing support.
If you're looking for IT or OT help from people who understand the ins and outs of manufacturing, we can help.
