Email us at sales@ocgl.net
Blog
12Aug 2026

PLC network security is now the biggest gap on the Canadian plant floor. Attackers no longer break into control systems. They just log in.
In April 2026, CISA and its partner agencies found actors reaching PLCs that were open to the internet. First, those actors pulled down project files. Then they rewrote ladder logic. In some cases they switched off alarms and shutdowns. And they used no exploit at all. The controllers were simply reachable, and control protocols ask for no password.
That is the whole problem in one line. If a PLC can be reached, it can be changed. So every step below works toward one goal: keep the outside world away from your controllers.
Your office network guards data. Your plant network guards a moving process — a line, a mixer, a pump, a press. So the priorities flip. Uptime and safety come first, and secrecy comes last.
The gear is different too. For a start, most PLCs have no user accounts. They talk in plain text. And they will accept a new program from anything that can reach them. So good PLC network security starts from a blunt view. Treat every controller as wide open, because it cannot guard itself. All of the guarding has to happen in front of it.
The best single change you can make is an industrial DMZ, or IDMZ. It sits between your office network and your plant network. And it becomes the only route between the two.
Every remote session should stop in that zone. Then it starts again from a jump host you own. So a hacked laptop in a vendor’s office never gets a path to a PLC. The ISA/IEC 62443 standards call this a zone-and-conduit model. Even a small plant gains from naming its zones, because firewall rules and approvals hang off them.
Three rules keep the boundary honest:
If data really has to leave, copy the historian into the DMZ. Then let office and cloud users read that copy through a secure API.
Many plant networks run no Active Directory domain. That is a strength, so keep it. Pushing office AD onto the plant floor rebuilds the exact link that the split was meant to break. One stolen office account would then reach your PLCs.
Handle logins at the broker instead:
Standing remote access is a permanent open door, bought for rare convenience. Just-in-time access replaces it. An engineer asks for a window. Then a sponsor says yes. The broker opens the door, and it shuts on its own.
Above all, keep the last word with the people who can see the line running. Someone on site should confirm the session first. If a controller has a key switch, leave it in RUN, and move it only for an approved change. Finally, record every session. And make sure one person on shift can cut all remote access in a single move.
Vendor access is where PLC network security fails most often. You cannot manage an OEM’s laptop, so do not trust it to be clean. Better: give them a browser link to a jump host you own, with the engineering software already on it. As a result, their machine never gets a path into your network.
Two promises belong in the contract, not just the policy. First, the vendor uses your remote access tool and adds no other route in. Second, you may record and audit sessions, and cut access at once, with no notice.
Watch for vendor cellular gateways too. A 4G router in a machine panel walks around every control you own. And your firewall cannot see it.
Monitoring closes the loop. Attackers use the same software your integrators use, so you cannot find them by hunting for malware. Instead, you find them by knowing what was approved. So match every session log to its approval, and flag anything that has none.
A few alerts are worth a phone call at night:
Backups matter just as much. Keep gold copies of every PLC program, HMI screen set, and device setting, with hashes on record. Also store them offline, away from the plant network. Then check the running logic against the gold copy on a schedule. That one habit catches logic tampering that leaves no other trace.
In short, each one is a finding, not a note. Treat it that way.
Most of this work needs no purchase order. Start here:
Those five steps cut most of your risk before you spend a dollar. For the source material, CISA and the UK NCSC set out eight secure connectivity rules for OT in January 2026. And NIST SP 800-82r3 covers the design in more depth.
These projects tend to stall in the gap between two teams. Controls engineers know the process. IT teams know logins, firewalls, and monitoring. OPUS Consulting Group works on both sides of that line, so the design gets built.
In practice, that means:
We are local, with teams in Vancouver, Edmonton, and Toronto, and over a century of combined experience behind the work.
Every idle hour on a line has a price. So does a rewritten logic file that nobody spotted. Good PLC network security costs far less than either. Better still, the steps that help most cost nothing but attention.
Schedule a no-obligation conversation: sales@ocgl.net • 1-866-800-OPUS (6787) • visit www.ocgl.net.
Man working at programmable machine