BLOG / PLC

PLC Security Hardening: The Baseline Every Networked S7 Deserves

21 Mart 2024 SecurityS7-1500OT SecurityHardening

The moment a PLC touches a routable network, “we’re just a machine shop” stops being a security policy. The baseline below is cheap, boring and effective — which is the point.

The checklist

  1. Access protection on: configure CPU access levels with real passwords (read, write, HMI tiers as your operations require). Recent firmware moved toward individual protection improvements — use the strongest scheme your version offers.
  2. Secure PG/HMI communication (TLS-based, available on current 1500 firmware) enabled; legacy unencrypted access disabled where the fleet allows.
  3. Web server and OPC UA: HTTPS only, per-user roles, certificates managed — and both services off where unused. Every enabled service is attack surface.
  4. Segment: machine network behind the CPU’s second interface or a cell firewall; engineering access via a defined maintenance VLAN or remote-access solution with logging — never the office LAN straight into X1. Display protocols and cloud tunnels each get a deliberate decision, not an inherited default.
  5. Know your exposure: if any control gear is reachable from the internet (it happens more than anyone admits — see also the Zsense-style dashboards world), put an authenticating proxy or VPN in front this week.
  6. Care and feeding: firmware advisories tracked (Siemens ProductCERT), project archives protected (they contain the keys to everything), spare cards stored like keys, and departures followed by password rotation.

FAQ

Does hardening break maintenance? Done with roles and documented credentials, it speeds maintenance — the 3 a.m. engineer finds a guest book, not a mystery.

Is an air gap still a plan? It is a claim — verify it annually; the forgotten cellular router in the panel is a cliché because it is common.


Zone Otomasyon includes an OT security pass in retrofits — quiet machines should stay quiet. Security-aware engineering.