Government Advisory

Urgent Warning: Active Cyberattacks Targeting Industrial Control Systems, Including Siemens PLCs

CISA · 19 Aug 2026
Key Takeaway If your business uses any industrial control equipment or PLCs, ensure they are never directly exposed to the internet and are kept up to date with the latest security patches.

A coalition of US agencies—including the NSA, CISA, FBI, Department of Energy, and Environmental Protection Agency—has issued an urgent advisory about active threat activity targeting Siemens S7 Series programmable logic controllers (PLCs). These devices are widely used to control machinery and processes in manufacturing, utilities, and other industrial settings. The agencies stress that while Siemens PLCs are the specific focus of this alert, the broader threat extends to PLCs from other vendors as well, meaning any business using industrial control systems should take note.

The advisory outlines several priority actions for organisations to reduce risk: keeping a full inventory of PLCs in use, applying critical security patches promptly, ensuring PLCs are never directly accessible from the internet, tightening access controls, and monitoring systems for unauthorized activity. Agencies also recommend hardening PLC services and protocols, verifying the integrity of ladder logic (the programming that controls device behaviour), and actively hunting for signs of compromise.

While this advisory is aimed primarily at larger industrial operators, many Australian small and medium businesses rely on connected machinery, building automation, or manufacturing equipment that use similar PLC technology. Even smaller operations should review their exposure, particularly around internet-facing industrial equipment, which remains one of the most common entry points for attackers targeting critical infrastructure.

ICS Security Siemens PLC Critical Infrastructure CISA Advisory Industrial Cybersecurity

Summarised by CISO AI from CISA. We link back to every original so you can read it yourself.