← Back to feed
AwarenessEmerging1 sourceSep 8, 2026 · 17:16via CSO Online

CISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting production

Brief

On a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only path to diagnostics. Close it without checking those dependencies and the security team may cause the outage it intended to prevent.

That is the implementation problem inside joint cybersecurity advisory AA26-231A , issued on August 19 by the NSA, CISA, FBI, Department of Energy and Environmental Protection Agency. The agencies warn of active targeting of Siemens S7 programmable logic controllers and recommend patching, removing internet exposure, strengthening access controls, monitoring S7 communications and disabling unnecessary services.

Every recommendation is reasonable.

Read more on CSO Online