PLC security

A programmable controller does what it is told by whatever can reach it, and historically it does not ask who is asking.

These are the devices actually opening valves and starting motors. Many industrial protocols have no authentication at all, so the security has traditionally been the network around them rather than anything in them. A controller that can be reprogrammed by anybody with a route to it is a normal condition, not a misconfiguration.

Checked against the primary source.

More on OT, ICS & cyber-physical