Manufacturing Cybersecurity

Is Your Factory Floor Visible From the Internet?

Internet-exposed PLCs can put production, equipment and process data at risk. Learn what small manufacturers should ask their IT providers and vendors.

In this article:

  • Why attackers search for exposed industrial controllers
  • How legitimate remote access can make a factory system publicly visible
  • Five questions small manufacturers should ask their IT providers and vendors

Attackers are searching for exposed industrial controllers

You should read this if your plant relies on PLCs, HMIs, industrial gateways or vendor remote access. You do not need to know the equipment’s brand or configuration to ask whether someone outside the company can find it.

In August 2026, the NSA, CISA, FBI, Department of Energy and EPA issued a joint cybersecurity advisory about an active threat to Siemens S7 programmable logic controllers. The advisory says threat actors are using internet-scanning services and AI-assisted scripts to locate exposed or poorly protected PLCs.

PLCs are industrial computers that help control machines and production processes. They are common in manufacturing environments – and they were not designed to serve as public websites. Critical Manufacturing is among the sectors most heavily targeted by this activity.

An attacker does not necessarily need to know your company in advance. If a controller or the system providing remote access to it is visible from the public internet, it can appear in a search.

How does a factory system become publicly visible?

Most manufacturers do not deliberately place production equipment on the internet. Exposure often begins with a legitimate business need:

  • A machine builder needs remote access for troubleshooting.
  • A systems integrator creates a connection during installation.
  • A vendor installs a gateway for monitoring or predictive maintenance.
  • A temporary firewall rule remains in place after a service call.
  • An old VPN, remote desktop or web-management interface is never retired.

Why should a small manufacturer care?

Attackers do not need to encrypt every office computer to stop a manufacturer. Interfering with the systems that control production may be enough.

That can mean reduced throughput, altered processes, equipment damage, extended downtime, stolen process data or delays to customers and downstream supply chains. For a small manufacturer, even a short outage can mean missed shipments, expedited freight, overtime and scrap.

The practical point is simple: an exposed PLC is not just an IT finding. It may be a publicly visible path to the operation that generates your revenue. This article gives you five questions to take to your IT provider, machine builder or systems integrator.

Visible does not mean compromised

Finding evidence of an externally visible industrial system does not prove that it is vulnerable or that an attacker has accessed it.

Exposure means a system or service is publicly discoverable or reachable. Vulnerability requires validation of the product, firmware, configuration and surrounding safeguards. Compromise requires evidence of unauthorized access or activity.

The right response is not panic – or unsafe scanning of production equipment. It is to determine what is visible, identify who owns it and validate whether the connection is necessary and properly protected.

Five questions to ask this week

A plant owner does not need to become an industrial-control engineer. But someone should be able to provide clear, evidence-supported answers to five questions:

Ask for the asset inventory, network diagram, named owner, authorized vendor list and date of the last external-access review. “The integrator handles it” is not the same as knowing the exposure has been verified.

  • What PLCs, HMIs, industrial gateways and remote-access systems are connected at this facility?
  • Can any of them be reached directly or indirectly from the public internet?
  • Which vendors and integrators have remote access, and is that access always on?
  • Are remote connections protected by strong authentication, limited to the equipment involved and logged?
  • Can production systems be isolated from the office network or internet without creating a safety issue?

Start with what an outsider can see

You cannot validate an external connection you do not know exists.

The Free Exposure Review from Securing Your Biz examines public evidence associated with your business and helps identify externally visible systems that warrant confirmation with your IT provider, MSP or systems integrator. It is an independent review designed to work alongside those providers – not replace them.

Start My Free Exposure Review and see what is visible before deciding what needs deeper validation.

The Free Exposure Review identifies observable public exposure. It is not an intrusive OT assessment and does not, by itself, establish that an industrial system is vulnerable or compromised.

Sources

Need an evidence-backed starting point?

The free Exposure Review shows what is publicly observable. The Business Security Baseline verifies the essential controls protecting the business.