

NEWS AND EVENTS
CISA warns of active attacks against Siemens S7 PLCs. This is exactly why PLC-level monitoring matters.
Tonje Rønneberg Skei, CEO i Securenok
CISA, NSA, FBI, DOE and EPA have issued a joint cybersecurity advisory warning industrial organizations of an active cyber threat targeting Siemens S7 Series PLCs.
The advisory describes threat actors conducting reconnaissance against Siemens S7 installations and using AI-generated exploitation scripts disguised as legitimate monitoring tools. Internet scanning services are being used to identify exposed PLCs running outdated software or otherwise lacking sufficient protection.
The sectors being targeted include critical manufacturing, energy, water and wastewater, chemicals, food and agriculture – environments where PLCs control physical processes.
For asset owners, this should reinforce an important principle:
Protecting the network is not enough. We also need visibility into what is happening inside the controller itself.
The PLC is the last line of the industrial process
In a Siemens PCS 7 environment, S7 PLCs perform the actual automation and control tasks.
Many industrial controllers were originally designed to operate in trusted environments. Security mechanisms such as authentication and encrypted communications were therefore not always fundamental parts of their original design. This is one reason whyOT cybersecurity requires a defense-in-depth approach rather than relying on a single security barrier.
Firewalls, segmentation, patching and access controls remain essential. But a sophisticated attacker may still reach the OT environment through compromised engineering workstations, remote maintenance connections, stolen vendor credentials or insider access.
And once an attacker reaches the PLC, the question changes from:
“Did someone get into our network?”
to:
“Has someone changed how our industrial process operates?”
Detecting manipulation directly at the Siemens S7 PLC
SecureNOK developed its SNOK PLC Threat Detection technology specifically for this problem.
Our PLC sensor monitors Siemens S7-300 and S7-400 controllers directly and analyzes information from the controller itself to identify changes that may indicate manipulation.
This includes detection of:
- changes to PLC properties
- runtime changes
- changes to PLC memory blocks, including changes caused by reprogramming

The sensor operates independently of mirrored network traffic and can therefore provide visibility even in industrial environments where conventional network monitoring is difficult to deploy.This capability was first developed by SecureNOK in 2016.
The latest CISA advisory demonstrates why this type of controller-level visibility is becoming increasingly important.
Defense in depth means detecting what gets through
CISA recommends that organizations inventory their Siemens S7 PLCs, apply critical patches, remove direct Internet exposure, strengthen access controls and monitor ICS environments for unauthorized or malicious activity.
We strongly support these recommendations. But industrial cybersecurity must assume that preventative controls can eventually fail. An engineering workstation can be compromised, credentials can be stolen, remote access can be abused, or an attacker can use legitimate industrial protocols and commands.
This is why detection needs to exist at several layers of the OT environment. Within the SNOK Cybersecurity Monitoring Platform, we combine network monitoring, endpoint monitoring and direct PLC monitoring to create visibility from the OT network all the way down to the industrial controller.
If an attacker moves through the network, compromises an engineering workstation and eventually attempts to manipulate an S7 PLC, those activities should create multiple opportunities for detection.
AI lowers the barrier for attacking industrial systems
The reported use of AI-generated exploitation scripts shows how quickly offensive capabilities are evolving. Knowledge that previously required highly specialized industrial cybersecurity expertise can increasingly be packaged, automated and made available to less sophisticated actors.
For industrial companies, the answer cannot be to assume that every attack can be prevented. The objective must also be to detect abnormal behavior early enough to act before an attacker can create physical consequences.

See more, fear Less. Explore
OT cybersecurity insights.
Insights from Norway’s cybersecurity experts
Mattilsynets nye veileder gjør én ting tydelig: Nå må vannverkene ta OT-sikkerhet på alvor
Mattilsynet har nå publisert den første offisielle veilederen til digitalsikkerhetsforskriften for drikkevann. Det er en viktig milepæl for norsk vannforsyning — og et tydelig signal om at myndighetene nå intensiverer arbeidet med digital sikkerhet i sektoren.
OT-sikkerhet i matindustrien starter med innsikt
Som prosjektleder i OT-sikkerhetsprosjekter møter jeg ofte det samme utgangspunktet hos industribedrifter: Man vet mye om produksjonen, prosessene og utstyret – men langt mindre om hvordan den digitale infrastrukturen faktisk ser ut i praksis.
Norskutviklet OT-sikkerhetsteknologi for industri og kritisk infrastruktur
Norsk industri blir stadig mer digitalisert. Produksjonslinjer, prosessanlegg, energisystemer og kritisk infrastruktur kobles tettere sammen med moderne IT-systemer, eksterne leverandører og digitale tjenester. Samtidig øker behovet for cybersikkerhetsløsninger som faktisk er utviklet for industrielle miljøer.

Sterk oppslutning rundt OT-konferansen 2026 – samler ledende fagmiljøer i Stavanger
OT-konferansen 2026 går av stabelen 29. april i Stavanger, og årets utgave peker seg allerede ut med et program som samler noen av de mest sentrale aktørene innen OT-sikkerhet og industriell digitalisering.
Økt behov for kontroll i komplekse automasjonsmiljøer i olje og gass
Digitaliseringen av olje- og gassindustrien har de siste årene gitt betydelige gevinster i form av effektivisering, bedre datagrunnlag og økt fleksibilitet. Samtidig har utviklingen ført til en betydelig økning i kompleksitet – og dermed også i risiko.

Hvordan få kontroll på OT-miljøet i praksis – erfaringer fra IVAR
For IVAR IKS er stabil drift ikke bare et mål – det er en forutsetning for at samfunnet skal fungere. Som leverandør av vann- og avløpstjenester til rundt 360 000 innbyggere på Nord-Jæren, forvalter virksomheten kritisk infrastruktur der konsekvensene av svikt er umiddelbare og omfattende.
Beredskapsåret 2026: Er vann og avløp i norske kommuner godt nok sikret?
Kommunal vannforsyning er blant samfunnsfunksjonene som omfattes av digitalsikkerhetsloven. Loven trådte i kraft 1. oktober 2025 og stiller grunnleggende krav til digital sikkerhet i virksomheter med særlig betydning for samfunnet. Regelverket innebærer også at ansvaret for digital sikkerhet er tydelig plassert hos virksomhetens øverste ledelse.

Stricter Security Requirements for Critical Services from 1 October 2025 under theDigital Security Act
O nFriday, 20 June, the Norwegian government decided in a Council of State meeting that the Digital Security Act will enter into force on 1 October 2025. At the same time, the Digital Security Regulation was adopted, entering into force concurrently with the Act.

Bremanger Breach: Lessons from a Norwegian Dam Hack
Earlier this year, unidentified hackers breached the control system of a Norwegian dam at Risevatnet, in Bremanger. The hackers discovered that the dam had a Human Machine Interface (HMI) exposed on the Internet and was able to gain access by exploiting a weak password.p
Digitalization: Opportunities and New Risks
Digitalization offers enormous opportunities for efficiency, but it also introduces new risks. When OT systems (Operational Technology) are connected to the internet, vulnerability to attacks increases—attacks that threaten not only data, but also lives, health, and critical societal functions.






