Five Agencies Named Your S7 Controllers

On August 19, 2026 the NSA, CISA, FBI, Department of Energy and EPA published joint advisory AA26-231A on Siemens S7 series PLCs. Liquid assesses S7 exposure at your site and does the controls work to close it. We are controls engineers. We read the ladder logic, we know the process, and we can work on a live plant safely.

What AA26-231A Says

The facts below are taken from the advisory itself. Read it in full at the link at the bottom of this section.

Issued by
NSA, CISA, FBI, Department of Energy and EPA, jointly. Published August 19, 2026.
What it describes
An active threat, not a theoretical vulnerability. The agencies assess the activity as persistent reconnaissance and pre-positioning for future disruption.
Devices named
S7-200, S7-300, S7-400, S7-1200 and S7-1500, including the F-series safety controllers.
How targets are found
Actors use Censys and ZoomEye to locate internet-exposed PLCs running outdated firmware or weak authentication.
Tooling
AI-generated Python scripts built on snap7.dll and python-snap7, disguised as legitimate OT monitoring software. They communicate over S7comm and provide read and write access to PLC memory, configuration data and ladder logic.
Priority mitigation
Remove S7 PLCs from internet exposure. Port 102 should not be reachable from the public internet. Where remote monitoring is operationally necessary, route it through a VPN with multi-factor authentication. Not port forwarding. Not an unmanaged cellular modem.
Other directed mitigations
Inventory all S7 assets. Apply security updates. Strengthen access controls. Monitor for anomalous S7comm activity.
Scope
The advisory states that targeting is broader than Siemens and that all PLC owners should apply the mitigations.

Source: Joint Cybersecurity Advisory AA26-231A, Defending Against an Active Threat to Siemens S7 Series PLCs. CISA, August 19, 2026.

Sectors Named,
And Everyone Else

The advisory names these sectors:

Critical Manufacturing Energy Water and Wastewater Chemical Food and Agriculture Commercial Facilities Defense Industrial Base

If you run S7 controllers, you are in scope regardless of sector. The sector list describes where the activity has been observed. It does not describe the boundary of it. The advisory is explicit that targeting is broader than Siemens and that all PLC owners should apply the mitigations.

Eight Things You
Can Verify Today

Your own people can answer all eight. Nothing here needs us. Work through the list, and the answers you cannot give are the ones worth a conversation.

01

Is port 102 reachable from outside?

S7comm listens on TCP port 102. From a connection outside your plant network, try to reach the public address in front of each control network segment on that port. If anything answers, that is the finding.

02

What firmware is on each S7?

Record the exact firmware version per controller, not per model. Then compare each one against Siemens current release. A plant that has never had a reason to upgrade is usually several versions behind.

03

Is a protection level set?

Check whether each PLC has a protection level configured and an access password set. Many controllers ship at the permissive default and stay there because nothing in commissioning forced the question.

04

How does remote access actually reach the floor?

Trace the real path, not the documented one. Port forward on the plant firewall, cellular modem on a skid, vendor support tunnel, a laptop bridging two networks. Follow it end to end and write down what you find.

05

Who holds the program backups?

Name the person and the location. If the answer is a folder on one engineer's laptop, or an integrator you last spoke to in 2019, you have your answer.

06

When was logic last checked against a known-good copy?

Pull the running program off a controller and compare it to your archived copy. If no comparison has been done, you cannot currently tell an authorized change from an unauthorized one.

07

Is your S7 asset list complete?

Include controllers on skids you did not specify. OEM equipment arrives with its own PLC, its own remote support arrangement, and its own firmware, and it rarely appears on the plant asset list.

08

Would you see anomalous S7comm traffic?

The advisory directs monitoring for it. Ask whether anything on your network is watching S7comm today, and who would receive the alert if it fired at 02:00 on a Sunday.

No form, no email address, no download. Send this list to your controls team and use it.

The Controls Side
Of the Work

Your IT group can tell you which ports are open. It cannot tell you whether closing one stops a filler mid-cycle, which firmware upgrade requires a rebuild of the safety program, or whether the logic on that controller matches what the process actually needs. That is the gap this work sits in. We are an automation integrator, not a security firm, and this is the part an integrator is qualified to do.

Tier 01

S7 Exposure Assessment

  • Asset inventory of all S7 controllers
  • Firmware and patch status per controller
  • S7comm exposure check
  • Remote access path mapping
  • Written findings mapped to AA26-231A
Duration

3 to 5 days per site

Indicative

$4,500 to $7,500

Per site. Scoped per site.

Tier 02

Remediation Engineering

  • Firmware upgrades
  • Unused services disabled
  • PLC protection levels and access passwords set
  • Port 102 exposure eliminated
  • VPN and MFA remote access design
  • Segmentation to Purdue model levels
Duration

2 to 6 weeks

Indicative

$15,000 to $45,000

Scoped per site.

Tier 03

Program Integrity Baseline

  • Golden-copy ladder logic archive
  • Change detection
  • Documented recovery runbook
  • Scheduled re-verification
Duration

Ongoing retainer

Indicative

$1,500 to $3,000

Per site, per month. Scoped per site.

Engineers Who Already
Work On These Systems

We commission this hardware

Our engineers specify, program and commission S7 controllers as ordinary project work. Reading a protection level or a firmware revision off a live controller is not a specialist exercise for us.

We already maintain plants

Food and beverage, mining and general manufacturing. We work on running lines, we understand what a stop costs, and we plan the work around production rather than against it.

We stay inside our scope

We do controls engineering. We do not do penetration testing, threat hunting or incident response, and we will say so rather than take work we are not the right firm for.

Engineers are available now

Assessments can be scheduled without waiting on a hiring cycle. Tell us the site and the approximate controller count and we will tell you when we can be there.

Talk To An
Automation Engineer

Tell us what you run and how it is reached today. You will speak with an automation engineer, not a sales rep. We respond within one business day.

If you are not ready to talk Work through the self-check list. It costs nothing and it will tell you whether you have a problem.
Advisory AA26-231A, August 19, 2026

Start With The Inventory

The advisory directs every S7 owner to inventory their assets, confirm firmware, and close internet exposure. Most plants cannot answer the first question with confidence. An assessment gives you a written answer, mapped to AA26-231A, that you can act on or hand to a customer or auditor.