PLC (Programmable Logic Controller)
A PLC is the industrial computer that runs the control logic of a machine or process. How PLCs work, which standards apply and where their security typically fails.
Updated This page as Markdown
In short
A PLC (programmable logic controller) is a ruggedised industrial computer that runs a control program in a fixed cycle: read inputs, execute logic, write outputs, in milliseconds. It is programmed in the languages of IEC 61131-3 and talks to sensors, drives, HMIs and SCADA over fieldbuses and industrial Ethernet. Security requirements for PLCs are defined in IEC 62443-4-2; most installed PLCs still accept program downloads and stop commands from anyone on the network.
What is a PLC?
A programmable logic controller (PLC) is the industrial computer that runs the control logic of a machine or process. It executes a program in a fixed cycle: read all inputs, run the logic, write all outputs, typically within a few milliseconds, and repeat. It is built for the factory floor: wide temperature ranges, vibration, 24 V I/O, decades of service. Everything from a packaging machine to a waterworks is controlled by one or more PLCs.
A PLC connects downwards to sensors, actuators and drives through I/O modules and fieldbuses (PROFINET, EtherNet/IP, EtherCAT, Modbus), upwards to HMIs and SCADA, and sideways to the engineering workstation from which it is programmed. Safety PLCs run safety functions such as emergency stop and guard monitoring with redundant hardware.
Where is it defined?
The IEC 61131 series defines programmable controllers. Part 3 standardises the five programming languages: ladder diagram, function block diagram, structured text, instruction list and sequential function chart. Security requirements for a PLC as a component come from IEC 62443-4-2 (identification and authentication, use control, integrity, data confidentiality, restricted data flow, timely response to events, resource availability), and the manufacturer’s development process from IEC 62443-4-1. Many vendors certify current PLC families to both. The BSI’s IT-Grundschutz Compendium has a dedicated building block, IND.2.2, for the PLC. For operators and integrators, the community document Top 20 Secure PLC Coding Practices collects measures that can be implemented in the control program itself. New PLCs placed on the EU market fall under the Cyber Resilience Act.
What it means in practice
Typical findings when we look at PLCs in plants and in the lab:
- No access protection. The protection level is set to none or to read-only with a password that is in the project file. Anyone who reaches the engineering port can upload the program, change it and download it back.
- Stop and start from the network. The engineering protocol allows a CPU stop without authentication. A single packet halts the machine.
- No integrity check of the logic. The PLC does not verify who changed the program and when; the HMI shows the process, not the code.
- Web servers and services. Built-in web servers with firmware from years ago, SNMP with default communities, FTP for recipe files, all reachable from the office network because the PLC sits in a flat network.
- Secrets in the project. Hard-coded passwords and IP addresses in the control program and the HMI project, which end up on every integrator’s laptop.
- Debug interfaces. On the hardware side, service ports and unprotected firmware images allow extraction and modification of the firmware on the bench.
Fixes start with the network: PLCs belong in their own zone, reachable only from the engineering workstation and the HMI through a conduit with protocol filtering. Then the device: access protection at the highest level the plant can live with, program and firmware signed where the vendor supports it, logging of logic changes, firmware updated in maintenance windows. Zyberum tests PLCs in test cells and in the hardware lab (firmware extraction, protocol fuzzing on bench units), reviews control programs against the secure coding practices, and runs IEC 62443-4-2 gap analyses for controller manufacturers.
Common misunderstandings
A password in the engineering software is not a protection on the PLC unless the controller enforces it. Control logic is attack surface: incidents from Stuxnet onwards have manipulated PLC programs, not just IT systems. And a safety-rated PLC is not a secure PLC; the two certifications test different things.
FAQ
Frequently asked questions
Can a PLC be hacked?
Yes, and usually without an exploit. Most installed PLCs accept a program download, a CPU stop or a variable write from any host that can reach their engineering port, because access protection is off or set to a low level. An attacker who reaches the control network can change the logic. Firmware vulnerabilities exist too, but the configuration is the bigger problem.
Does a safety PLC protect against attacks?
No. A safety PLC is designed to detect random hardware failures and bring the machine to a safe state, according to IEC 61508, IEC 62061 or ISO 13849. It assumes its logic is correct. An attacker who can change that logic or feed it false inputs defeats the safety function. Security protects the safety function; it is not provided by it.
How do you test a PLC without stopping production?
On a spare unit or in a test cell with the same firmware and configuration. We analyse the firmware, test the engineering protocol, the web server and the access protection there, and fuzz the protocol stack where the manufacturer wants it. In the running plant we only capture traffic and review configurations. Written authorisation and an agreed scope come first.
Sources
- IEC 61131-3: Programmable controllers, Part 3: Programming languages
- IEC 62443-4-2: Technical security requirements for IACS components
- IEC 62443-4-1: Secure product development lifecycle requirements
- Top 20 Secure PLC Coding Practices
- BSI: IT-Grundschutz-Kompendium (building block IND.2.2 Speicherprogrammierbare Steuerung)
Related pages
- GlossarySCADASCADA systems supervise and control distributed processes such as power grids, water networks and pipelines. Architecture, protocols and the security issues they bring.
- GlossaryModbusModbus is the simplest and most widespread industrial protocol: RTU over serial lines, TCP on port 502. How it works, why it has no security and how to protect it anyway.
- GlossaryIEC 62443IEC 62443 is the standard series for the cybersecurity of industrial automation and control systems (IACS). Parts, the three roles, and how it is used in practice.
- GlossaryOT SecurityOT security protects the operational technology that controls physical processes: PLCs, SCADA, HMIs, drives. How it differs from IT security and what typically fails.
- InsightsOT Penetration Testing Without Downtime: How It Is DoneHow to test a plant without stopping production: passive analysis, test benches and twins, what belongs in a maintenance window, what is never done on a live plant.
- ServicesKeep production running when IT and OT converge.Security assessments, pentests and IEC 62443 consulting for PLC, SCADA and DCS. Protect production and critical infrastructure against cyberattacks.
