
VTechFusion Team
VTechFusion Technologies
CISA's advisory on the Siemens PLC threat recommends network segmentation as a top mitigation — genuinely correct guidance, but high-level. Here's a practical, hands-on checklist for engineers actually implementing that recommendation, not just acknowledging it.
Starting With a Real Inventory, Not an Assumed One
CISA's first recommendation — inventory all Siemens S7 Series PLCs — sounds basic but is frequently incomplete in practice: PLCs added by contractors, integrators, or legacy installations outside the current IT team's direct knowledge are a common, genuine gap, and segmentation work built on an incomplete inventory leaves real exposure that looks addressed on paper.
A Practical Segmentation Checklist
- Conduct an active network scan specifically for PLC and industrial protocol traffic (not just relying on an asset management system that may already be stale) to catch devices missing from documented inventory
- Verify zero direct internet accessibility for every identified PLC — not just "should be behind a firewall" as a policy statement, but an actual, tested confirmation from outside the network
- Implement genuine network-layer segmentation (VLANs, dedicated OT network segments, industrial firewalls) between IT and OT networks, not just access-control-list rules on a shared network — segmentation needs to survive a compromised IT-side credential, not just casual unauthorized access
- Test segmentation effectiveness with an actual internal red-team exercise attempting to reach OT systems from a compromised IT starting point — untested segmentation is a documented intention, not a verified control
Frequently Asked Questions
Why is a complete PLC inventory often harder to achieve than it sounds?
PLCs added by contractors, integrators, or from legacy installations are frequently outside the current IT team's direct knowledge or asset management system — an active network scan for industrial protocol traffic, not just a documentation review, is usually needed to catch these gaps.
What's the difference between "should be behind a firewall" and genuine network segmentation?
Access-control-list rules on a shared network can still be bypassed by a compromised IT-side credential. Genuine segmentation (VLANs, dedicated OT segments, industrial firewalls) needs to survive that scenario specifically, and should be verified with an actual internal red-team test, not just documented as policy.
Enjoyed this article?
Get new articles delivered to your inbox — no spam, unsubscribe anytime.
Ready to Build Something Great?
Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.
