Industrial cybersecurity is becoming one of the most important issues in the automation industry as attackers increasingly target operational technology environments.
Recent incidents involving industrial infrastructure and automation suppliers have highlighted the risks associated with internet-connected PLCs, remote access systems and industrial networks.
One recent case involved Micro-Comm, a Kansas-based supplier of technology used by water utilities. The company was targeted in a cyberattack that resulted in the exposure of a large volume of company data.
The incident attracted attention because Micro-Comm supplies PLC technology used in wastewater facilities.
Although the incident did not mean that customers' operational systems had been compromised, cybersecurity experts warned that information exposed during attacks could potentially help attackers understand industrial environments.
The incident demonstrates why cybersecurity must be considered throughout the industrial automation supply chain.
PLCs are designed primarily to control physical processes.
They can operate:
Traditionally, many PLC systems operated inside isolated industrial networks.
That architecture is changing.
Modern factories and infrastructure facilities increasingly connect PLCs to:
Connectivity provides important operational benefits.
However, it also creates additional security considerations.
Water and wastewater facilities rely heavily on automation.

A modern water treatment facility may use PLCs and SCADA systems to control:
If these systems are disrupted, operators may face significant operational challenges.
This makes water infrastructure an important target for cybersecurity protection.
Utilities increasingly need to evaluate not only their own security but also the security of technology suppliers and contractors.
Industrial organizations depend on a large network of technology suppliers.
A factory or utility may purchase:
from multiple vendors.
A cybersecurity weakness at a supplier can potentially create risks for customers.
This means industrial cybersecurity cannot focus only on the plant network.
Companies also need to understand their technology supply chain.
Remote access is widely used in industrial automation.
Engineers can troubleshoot PLCs and SCADA systems without traveling to a facility.
This can reduce maintenance costs and improve response times.
However, poorly configured remote access can create security weaknesses.
Industrial organizations should carefully control:
Access should be limited to authorized users and necessary functions.
Many industrial facilities operate automation systems for long periods.
Legacy PLCs can continue to perform their original control functions reliably.
However, older systems may not provide modern cybersecurity features.
Companies therefore face a difficult decision.
Replacing a complete control system can be expensive.
But continuing to operate unsupported equipment can increase security and maintenance risks.
A phased modernization strategy can provide a practical solution.
Network segmentation is one of the most important principles of OT security.
Industrial organizations can separate systems into different zones.
For example:
Controlled communication can then be established between zones.
This approach reduces unnecessary exposure and helps limit the impact of security incidents.
Security monitoring is becoming increasingly important.
Industrial organizations can establish a baseline of normal network behavior.
Unusual activity can then trigger investigation.
Monitoring can identify:
This provides greater visibility into the industrial environment.
In industrial environments, cybersecurity and functional safety cannot always be treated as separate issues.
A cyber incident that affects a PLC or safety-related system could potentially influence physical processes.
For example, industrial equipment may operate under specific temperature, pressure or speed conditions.
Unauthorized changes could create operational and safety concerns.
This makes cybersecurity an important part of overall industrial risk management.
Automation engineers traditionally focus on:
Modern engineers increasingly need additional cybersecurity knowledge.
Important areas include:
The goal is not to turn every PLC engineer into a cybersecurity specialist.
Instead, cybersecurity needs to become part of normal automation engineering practices.
Automation equipment suppliers can also contribute to improved OT security.
When supplying replacement equipment, suppliers should provide accurate information about:
Customers increasingly need this information when modernizing legacy automation systems.
For international automation distributors, technical accuracy is becoming increasingly important.
Artificial intelligence is creating both opportunities and risks.
Industrial companies can use AI to analyze:
However, attackers may also use AI to accelerate research and develop more sophisticated attack techniques.
This means industrial cybersecurity strategies will need to evolve continuously.
Industrial automation is becoming increasingly connected.
Factories, power plants, water utilities and process facilities are adopting:
These technologies provide significant benefits.
But secure architecture must be included from the beginning.
Security cannot simply be added after a system has already been connected.
Future PLC and DCS systems will increasingly include cybersecurity features as standard requirements.
Industrial organizations will focus more heavily on:
Cybersecurity will become a normal part of automation system design.