Skip to content
Zyberum Cyber Security Firm
Menu
GlossaryOT

PLC (Programmable Logic Controller)

A PLC is the industrial computer that runs the control logic of a machine or process. How PLCs work, which standards apply and where their security typically fails.

Updated This page as Markdown

In short

A PLC (programmable logic controller) is a ruggedised industrial computer that runs a control program in a fixed cycle: read inputs, execute logic, write outputs, in milliseconds. It is programmed in the languages of IEC 61131-3 and talks to sensors, drives, HMIs and SCADA over fieldbuses and industrial Ethernet. Security requirements for PLCs are defined in IEC 62443-4-2; most installed PLCs still accept program downloads and stop commands from anyone on the network.

What is a PLC?

A programmable logic controller (PLC) is the industrial computer that runs the control logic of a machine or process. It executes a program in a fixed cycle: read all inputs, run the logic, write all outputs, typically within a few milliseconds, and repeat. It is built for the factory floor: wide temperature ranges, vibration, 24 V I/O, decades of service. Everything from a packaging machine to a waterworks is controlled by one or more PLCs.

A PLC connects downwards to sensors, actuators and drives through I/O modules and fieldbuses (PROFINET, EtherNet/IP, EtherCAT, Modbus), upwards to HMIs and SCADA, and sideways to the engineering workstation from which it is programmed. Safety PLCs run safety functions such as emergency stop and guard monitoring with redundant hardware.

Where is it defined?

The IEC 61131 series defines programmable controllers. Part 3 standardises the five programming languages: ladder diagram, function block diagram, structured text, instruction list and sequential function chart. Security requirements for a PLC as a component come from IEC 62443-4-2 (identification and authentication, use control, integrity, data confidentiality, restricted data flow, timely response to events, resource availability), and the manufacturer’s development process from IEC 62443-4-1. Many vendors certify current PLC families to both. The BSI’s IT-Grundschutz Compendium has a dedicated building block, IND.2.2, for the PLC. For operators and integrators, the community document Top 20 Secure PLC Coding Practices collects measures that can be implemented in the control program itself. New PLCs placed on the EU market fall under the Cyber Resilience Act.

What it means in practice

Typical findings when we look at PLCs in plants and in the lab:

  • No access protection. The protection level is set to none or to read-only with a password that is in the project file. Anyone who reaches the engineering port can upload the program, change it and download it back.
  • Stop and start from the network. The engineering protocol allows a CPU stop without authentication. A single packet halts the machine.
  • No integrity check of the logic. The PLC does not verify who changed the program and when; the HMI shows the process, not the code.
  • Web servers and services. Built-in web servers with firmware from years ago, SNMP with default communities, FTP for recipe files, all reachable from the office network because the PLC sits in a flat network.
  • Secrets in the project. Hard-coded passwords and IP addresses in the control program and the HMI project, which end up on every integrator’s laptop.
  • Debug interfaces. On the hardware side, service ports and unprotected firmware images allow extraction and modification of the firmware on the bench.

Fixes start with the network: PLCs belong in their own zone, reachable only from the engineering workstation and the HMI through a conduit with protocol filtering. Then the device: access protection at the highest level the plant can live with, program and firmware signed where the vendor supports it, logging of logic changes, firmware updated in maintenance windows. Zyberum tests PLCs in test cells and in the hardware lab (firmware extraction, protocol fuzzing on bench units), reviews control programs against the secure coding practices, and runs IEC 62443-4-2 gap analyses for controller manufacturers.

Common misunderstandings

A password in the engineering software is not a protection on the PLC unless the controller enforces it. Control logic is attack surface: incidents from Stuxnet onwards have manipulated PLC programs, not just IT systems. And a safety-rated PLC is not a secure PLC; the two certifications test different things.

FAQ

Frequently asked questions

Can a PLC be hacked?

Yes, and usually without an exploit. Most installed PLCs accept a program download, a CPU stop or a variable write from any host that can reach their engineering port, because access protection is off or set to a low level. An attacker who reaches the control network can change the logic. Firmware vulnerabilities exist too, but the configuration is the bigger problem.

Does a safety PLC protect against attacks?

No. A safety PLC is designed to detect random hardware failures and bring the machine to a safe state, according to IEC 61508, IEC 62061 or ISO 13849. It assumes its logic is correct. An attacker who can change that logic or feed it false inputs defeats the safety function. Security protects the safety function; it is not provided by it.

How do you test a PLC without stopping production?

On a spare unit or in a test cell with the same firmware and configuration. We analyse the firmware, test the engineering protocol, the web server and the access protection there, and fuzz the protocol stack where the manufacturer wants it. In the running plant we only capture traffic and review configurations. Written authorisation and an agreed scope come first.

Sources

Related pages

Get started

A term that applies to your product?

In 15 minutes we tell you what it means for you in practice, which requirement follows from it and what the sensible next step is.

  • Direct answer from a security engineer
  • Which standard or law applies to you
  • Free and without obligation
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usAsk a security engineer

Pick a time that suits you

Open in a new tab