Imagine this: your office IT is in good shape. The firewall is properly configured, staff have had training, backups run smoothly. And yet production grinds to a halt. Not because something is wrong with your computers, but because someone from outside gained access to the box that controls your machines. That is exactly the scenario the US government recently warned about: vulnerabilities in Siemens S7 PLCs, control systems widely used in factories around the world.
For Dutch SMEs in manufacturing and production, this is not a distant issue. It is a direct reason to think about a part of your business that often stays out of view when cybersecurity comes up: the shop floor.
What exactly is a PLC?
A PLC (Programmable Logic Controller) is essentially the brain behind a machine or production line. It is a small, rugged computer that reads sensors, controls motors, opens and closes valves, and keeps processes running as programmed. Siemens S7 is one of the most widely used PLC families in the world, also present in plenty of Dutch manufacturing, transport, and logistics companies.
What makes a PLC special is that it often runs unchanged for years. While a laptop gets replaced every few years and software updates regularly, a PLC can keep doing the same job for ten to fifteen years. That makes them reliable for production, but also vulnerable: security updates are applied less often, and older systems were sometimes never designed with today’s threat landscape in mind.
Why this often gets overlooked
At many manufacturing companies, cybersecurity attention has traditionally focused on IT: the office environment, email, files, administration. That’s understandable, since that’s where the visible risks live, like phishing and ransomware. But the machines on the floor, the so-called OT environment (Operational Technology), often fall outside that picture. They are managed by the technical department or the machine supplier, not by IT. There is rarely a clear overview of which systems are actually connected to the network, let alone whether they are up to date.
That is exactly why a warning like this matters. A PLC that is reachable over the network is an entry point. If an attacker gets in, they can slow down, disrupt, or completely halt a production line. Not in theory, but in practice: there are already examples worldwide of factories standing still for days because of exactly this kind of attack.
What the warning actually says
The US warning concerns vulnerabilities in Siemens S7 PLCs that could be exploited to gain unauthorized access or disrupt processes. Critical sectors are being urged to check whether their systems are vulnerable and to apply updates or additional security measures where needed. Even if your company doesn’t fall under a ‘critical sector’, the logic is the same: if you use Siemens S7 PLCs (or another brand, since the underlying issue applies more broadly), it’s worth knowing whether you’re exposed.
The link with NIS2
For companies that fall under the NIS2 directive, or that encounter it indirectly through customers and suppliers, this is exactly the kind of risk the legislation aims to address. NIS2 calls for risk management that goes beyond office IT alone. It concerns the continuity of your entire operation, including the systems that keep your production running. A PLC that isn’t part of your risk assessment is a blind spot that NIS2 is specifically meant to close.
What you can do right now
You don’t need to overhaul your entire production environment overnight. Start with an overview:
Map out which PLCs and industrial systems you have. Do you know the brand, the version, and whether they are connected to the network? This often turns out to be surprisingly unclear, especially when machines were installed by multiple suppliers over the years.
Check whether your systems are remotely accessible. Many PLCs were once connected for remote maintenance and never properly secured afterwards. That is exactly the kind of access attackers look for.
Separate your production network from your office network. If both run on the same network, a problem in the office can spread to the floor, and vice versa. A clear separation limits the damage if something goes wrong.
Ask your machine supplier about their update policy. Not every supplier proactively communicates about security updates. It’s up to you to ask.
Include OT in your risk assessment. If you’re working on NIS2 compliance, make sure the shop floor is explicitly part of that analysis, not just the office systems.
A step that shouldn’t wait for the next warning
This particular warning is about Siemens S7, but the underlying point is broader: production security deserves the same attention as office security. Not because it’s alarming, but because it’s simply part of running a solid business.
A few questions we’re often asked
We don’t use Siemens S7. Does this still matter for us?
It does. This warning is about Siemens, but the underlying issue, old control systems that run unchanged for years and are sometimes reachable over the network, applies to almost every PLC brand. The questions stay the same: what do we have, is it on the network, and who keeps it up to date?
Our machines are managed by the supplier. Do I still need to do anything?
Yes. The supplier knows the machine, but you’re responsible for keeping your production running. Ask specifically whether security updates exist, how remote access is secured and who has that access. If the answer stays vague, that’s a signal in itself.
Can I just update a PLC like a laptop?
Usually not. An update can affect production and often has to be planned with the supplier during a scheduled stop. That’s why network segmentation matters so much: if the PLC isn’t directly reachable from the office or the internet, you don’t have to patch every vulnerability immediately to stay safe.
Does the shop floor fall under NIS2 if my company does?
Yes. NIS2 is about the continuity of your entire operation, not just office IT. The systems that keep your production running belong explicitly in your risk assessment.
We’re happy to help manufacturing companies get a clear overview of their OT environment and make it part of their NIS2 approach. If you’re running into this or just want to know where you stand, feel free to get in touch.