Email us at sales@ocgl.net

service

PLC network security on a manufacturing plant floor control panel

PLC network security is now the biggest gap on the Canadian plant floor. Attackers no longer break into control systems. They just log in.

In April 2026, CISA and its partner agencies found actors reaching PLCs that were open to the internet. First, those actors pulled down project files. Then they rewrote ladder logic. In some cases they switched off alarms and shutdowns. And they used no exploit at all. The controllers were simply reachable, and control protocols ask for no password.

That is the whole problem in one line. If a PLC can be reached, it can be changed. So every step below works toward one goal: keep the outside world away from your controllers.

Why PLC network security is not just IT security

Your office network guards data. Your plant network guards a moving process — a line, a mixer, a pump, a press. So the priorities flip. Uptime and safety come first, and secrecy comes last.

The gear is different too. For a start, most PLCs have no user accounts. They talk in plain text. And they will accept a new program from anything that can reach them. So good PLC network security starts from a blunt view. Treat every controller as wide open, because it cannot guard itself. All of the guarding has to happen in front of it.

Put an industrial DMZ between the office and the plant floor

The best single change you can make is an industrial DMZ, or IDMZ. It sits between your office network and your plant network. And it becomes the only route between the two.

Every remote session should stop in that zone. Then it starts again from a jump host you own. So a hacked laptop in a vendor’s office never gets a path to a PLC. The ISA/IEC 62443 standards call this a zone-and-conduit model. Even a small plant gains from naming its zones, because firewall rules and approvals hang off them.

Three rules keep the boundary honest:

  • Deny all traffic by default, both ways, and log what you block.
  • Never allow a rule from the internet or the office straight into the plant network.
  • Keep plant protocols on the plant floor. Modbus, EtherNet/IP, S7comm and DNP3 check no password, so they must not cross the line.

If data really has to leave, copy the historian into the DMZ. Then let office and cloud users read that copy through a secure API.

Handle logins at the boundary, not in the plant

Many plant networks run no Active Directory domain. That is a strength, so keep it. Pushing office AD onto the plant floor rebuilds the exact link that the split was meant to break. One stolen office account would then reach your PLCs.

Handle logins at the broker instead:

  • Require phishing-resistant MFA for every remote session, with no exceptions. A FIDO2 key or a smartcard works. A text message does not.
  • Hold plant passwords in a vault. The broker types them in, so nobody learns them or tapes them inside a panel door.
  • Change every default password on day one, and use a different one on each device. This shows up in almost every PLC alert, because it still works far too often.
  • Give people their own accounts. A shared “engineer” login tells you nothing after an incident.

Give every session a start time and an end time

Standing remote access is a permanent open door, bought for rare convenience. Just-in-time access replaces it. An engineer asks for a window. Then a sponsor says yes. The broker opens the door, and it shuts on its own.

Above all, keep the last word with the people who can see the line running. Someone on site should confirm the session first. If a controller has a key switch, leave it in RUN, and move it only for an approved change. Finally, record every session. And make sure one person on shift can cut all remote access in a single move.

Keep vendors on your kit, never theirs

Vendor access is where PLC network security fails most often. You cannot manage an OEM’s laptop, so do not trust it to be clean. Better: give them a browser link to a jump host you own, with the engineering software already on it. As a result, their machine never gets a path into your network.

Two promises belong in the contract, not just the policy. First, the vendor uses your remote access tool and adds no other route in. Second, you may record and audit sessions, and cut access at once, with no notice.

Watch for vendor cellular gateways too. A 4G router in a machine panel walks around every control you own. And your firewall cannot see it.

Watch the network, and keep a clean copy of every program

Monitoring closes the loop. Attackers use the same software your integrators use, so you cannot find them by hunting for malware. Instead, you find them by knowing what was approved. So match every session log to its approval, and flag anything that has none.

A few alerts are worth a phone call at night:

  • Someone logging in outside an approved window.
  • A program download with no matching change ticket.
  • Any controller mode change.
  • Blocked traffic aimed at the plant on a control port.

Backups matter just as much. Keep gold copies of every PLC program, HMI screen set, and device setting, with hashes on record. Also store them offline, away from the plant network. Then check the running logic against the gold copy on a schedule. That one habit catches logic tampering that leaves no other trace.

PLC network security mistakes we find most often

  • A PLC or HMI reachable through a port forward, or sitting on a public IP.
  • An office VPN that drops the user straight onto the plant network.
  • A consumer screen-sharing tool on an HMI, added so someone could work from home once.
  • A firewall rule opened for a startup project three years ago that nobody closed.
  • An engineering laptop on Wi-Fi while plugged into the plant network. That bridges every boundary at once.
  • Controller backups on a share that ransomware can reach.

In short, each one is a finding, not a note. Treat it that way.

Where to start in the first 30 days

Most of this work needs no purchase order. Start here:

  1. Scan your public IP ranges, plus any cellular ranges used by plant gear, for open controllers and HMI screens. Then unplug whatever you find.
  2. List every remote access path you already have. Include vendor boxes, modems, and remote-desktop tools.
  3. Check firewall rules for any direct path from the internet or the office into the plant.
  4. Change all default passwords on PLCs, HMIs, drives, switches, and gateways.
  5. Take tested offline backups of every program and setting.

Those five steps cut most of your risk before you spend a dollar. For the source material, CISA and the UK NCSC set out eight secure connectivity rules for OT in January 2026. And NIST SP 800-82r3 covers the design in more depth.

How OPUS strengthens PLC network security

These projects tend to stall in the gap between two teams. Controls engineers know the process. IT teams know logins, firewalls, and monitoring. OPUS Consulting Group works on both sides of that line, so the design gets built.

In practice, that means:

  • A scored review of your setup against ISA/IEC 62443 and the 2026 CISA and NCSC rules. Afterwards, hand it to an auditor or your insurer.
  • Design and build of the industrial DMZ, the firewalls on both sides, and the hardened jump host. See our IT Infrastructure practice.
  • Brokered remote access with phishing-resistant MFA, a password vault, session recording, and just-in-time approvals, from our Cyber Security team.
  • Managed detection and response on your plant hosts. Logs flow one way to a SIEM the plant cannot reach back into. Our Managed IT Solutions cover the daily watch.
  • Offline, tested Data Backup of controller programs and settings, plus a scheduled check against the gold copy.
  • Vendor access rules that stick: the register, the approval steps, and the contract clauses. Our IT Consulting team writes them with you.

We are local, with teams in Vancouver, Edmonton, and Toronto, and over a century of combined experience behind the work.

Protect your plant floor

Every idle hour on a line has a price. So does a rewritten logic file that nobody spotted. Good PLC network security costs far less than either. Better still, the steps that help most cost nothing but attention.

Schedule a no-obligation conversation: sales@ocgl.net • 1-866-800-OPUS (6787) • visit www.ocgl.net.

Man working at programmable machine

Why Choose Us

Error: Contact form not found.