Cyber-Informed Engineering Pushes PLCs Out of Shutdown Paths

Cyber-Informed Engineering Pushes PLCs Out of Shutdown Paths

Critical infrastructure security is quietly undergoing a philosophical rewrite. Instead of asking how to keep attackers out of the plant network, a growing group of engineers is asking a harder question: if the network is breached — and the working assumption is that it will be — what prevents a compromised controller from turning a process hazard into a catastrophe? That question sits at the heart of cyber-informed engineering, an approach that is now moving programmable logic controllers out of the final shutdown path altogether.

A feature published by Industrial Cyber on September 15, 2026 gave that shift a concrete face. Idaho National Laboratory (INL) controls engineer Lance Barnes described chemical dosing systems in which the final protective action rests on an independent, normally closed high-high level switch hardwired directly into the motor-starter circuit. The PLC — and every remotely accessible digital path bolted onto it — is removed from the last line of defense. A stuck output, an incorrect logic download or corrupted firmware can no longer keep the hazard alive.

Analyst Insight: The industry has spent two decades hardening the perimeter. Cyber-informed engineering inverts the math — it assumes the perimeter fails and hardens the physics instead. For asset owners, the measure of success stops being "did we block the intrusion?" and becomes "could the intrusion still cause harm?"

From Protecting Networks to Engineering Out Consequences

INL defines cyber-informed engineering (CIE) as an engineering discipline that reduces the consequences of cyberattacks by designing systems so that digital compromise cannot easily translate into physical harm. Its toolbox is deliberately unglamorous: manual overrides, analog redundancy, functional isolation, mechanical interlocks, relief devices and hardwired trips.

INL's consequence-driven variant, known as CCE, starts from a blunt premise — a skilled and determined adversary will penetrate the target network. Engineers therefore work backwards from the worst credible outcome, such as a toxic release, an overpressure event or a runaway exotherm, and then selectively reduce or eliminate the digital pathways that could drive the process there.

Market Trend: This philosophy is nudging operational technology budgets away from detection-heavy IT tooling and toward control-layer resilience — certified safety controllers, independent hardwired loops and hardware-rooted device trust. The purchase order is slowly moving from the CISO's office to the plant engineer's desk.

Inside the Hardwired Shutdown: How the Chemical Dosing Case Works

The chemical dosing example is instructive precisely because it is ordinary. Dosing systems are everywhere — water treatment, food and beverage, pharmaceuticals — and many of them route their last protective action through the same controller that runs normal production.

Barnes's design breaks that coupling. A normally closed high-high level switch sits on the vessel independent of the PLC. When the level reaches the trip point, the switch opens the motor-starter circuit directly. Energy is removed physically, not logically, and the plant returns to a safe state without asking permission from a programmable device.

Technical Comparison: Digital Trip vs. Cyber-Informed Hardwired Trip
Design Element Conventional Digital Trip Cyber-Informed Hardwired Trip
Final protective action PLC output de-energizes the motor starter Normally closed switch opens the motor-starter circuit directly
Logic dependency Stored program and firmware None — electromechanical path only
Remote attack surface Network, engineering workstation, logic downloads Effectively eliminated from the trip function
Failure modes neutralized Stuck output can sustain the hazard Stuck output, bad download or corrupted firmware cannot hold the hazard
Rearm procedure Software reset, sometimes remote Manual, physical rearm at the panel
Trade-off Flexibility, diagnostics, remote visibility Design discipline, spare parts, operator training

Why "Normally Closed" Is the Whole Argument

A normally closed contact is energized to permit operation and de-energizes to stop it. Lose power, lose the wire, lose the sensor — the process goes to a safe state. That is fail-safe behaviour encoded in copper rather than in code, and it is the reason a corrupted logic download cannot argue with the outcome.

The result is not simply a better-protected PLC. It is a hazard that no longer depends on a PLC to be contained.

The Independence Trap: Shared PLCs, Networks and Engineering Workstations

The article's central warning is one that safety engineers have traded on for years, now sharpened for the cyber era: protection layers are not truly independent if they share the same PLC, the same network or the same engineering workstation.

On paper, a plant may claim a basic process control layer, a safety instrumented system and an operator alarm layer. In practice, when all three terminate in the same chassis or the same Windows-based engineering station, a single compromised credential can defeat the entire stack. Common-cause failure is no longer a hardware failure mode — it is an access path.

Independence Audit: Six Questions to Ask About Every Safety Layer
  • Shared controller? Does the safety function execute in the same CPU that runs normal production logic?
  • Shared network? Does the trip signal traverse the same switches, gateways or VLAN boundaries as production traffic?
  • Shared engineering workstation? Can one laptop change control logic and safety logic in the same session?
  • Shared credentials and directory? Would one compromised account reach both domains?
  • Shared power and I/O? Do safety inputs and process control inputs sit on the same module or power rail?
  • Shared firmware supply chain? Would one malicious update bundle affect both systems?
Analyst Insight: Independence has quietly become a cyber property, not just a functional safety property. Standards such as IEC 61508 and IEC 61511 have always demanded separation and diversity between protection layers. What CIE adds is the recognition that a shared engineering workstation can collapse that separation from a laptop in another country, with no physical symptom until the trip fails to fire.

What the 2025 ICS/OT Data Actually Shows

The engineering argument is reinforced by the incident data. The SANS Institute's State of ICS/OT Security 2025 survey, drawn from more than 330 industry professionals, found that roughly half of reported ICS/OT incidents began with unauthorized external access — while only a small minority of organizations had deployed advanced OT-aware remote access controls.

Detection is improving. Recovery still is not. That gap is exactly where consequence-driven engineering earns its keep: if remediation takes weeks, the plant needs a design that keeps people and equipment safe regardless of how long the adversary retains a foothold.

SANS 2025 ICS/OT Security: The Numbers Behind the Urgency
  • 21.5% of organizations reported an ICS/OT cyber incident in the past year.
  • 40% of those incidents caused operational disruption.
  • 50% of reported incidents began with unauthorized external access.
  • 13% had implemented advanced OT-aware remote access controls such as session recording or OT-specific authentication.
  • 22% of incidents took two to seven days to fully remediate.
  • Nearly 1 in 5 (19%) took more than a month to remediate; a further 3% took over a year.
  • 53% of respondents lacked an ICS-specific incident response plan and relied on IT-centric processes.

Market Signal: Safety Controllers and Hardwired Logic Remain a Growth Story

The commercial picture supports the engineering trend. Even as the broader PLC market grows at a steady single-digit pace, the safety-certified segment is expanding faster, and safety logic is one of the quickest-growing application categories in regional PLC spending.

PLC and Safety PLC Market Data at a Glance
  • Safety PLC market: projected to grow from USD 2.58 billion in 2025 to USD 4.91 billion by 2034, a CAGR of roughly 7.4%.
  • Regional lead: Asia Pacific held about 38.3% of the safety PLC market in 2025.
  • Safety PLC remote I/O: estimated at USD 2.68 billion in 2025, heading toward USD 4.03 billion by 2030 at an 8.4% CAGR.
  • Overall PLC market: approximately USD 12.79 billion in 2025, forecast to reach about USD 16.4 billion by 2031 at a 4.24% CAGR.
  • Europe: safety logic within the PLC market is forecast to grow at roughly 4.96% annually through 2031, faster than most other application categories.
  • Certification baseline: SIL 2 and SIL 3 capable systems account for roughly 31% of PLC-based safety installations.
Market Trend: Growth is not coming purely from certified controllers. Watch the demand for hardwired instrumentation — level switches, pressure pilots, mechanical interlocks and electromechanical relay interfaces — as brownfield retrofits add a physical trip layer behind existing digital control.

A Practical Playbook for Plant Engineers

1. Start with the worst credible consequence

Identify the handful of events that would injure people, breach containment or trigger regulatory action. Everything else is secondary. Rank them by severity, not by likelihood of attack.

2. Map the final protective action, not the alarm list

For each top-tier consequence, name the single device that must act last. If that device is a PLC output, trace every digital path that can influence it.

3. Break the common-cause chain

Separate controller, network, power, I/O and engineering workstation. Where separation is impossible, document the residual risk explicitly rather than claiming independence that does not exist.

4. Reintroduce physical and mechanical defenses

Relief devices, mechanical interlocks, analog redundancy and normally closed hardwired trips do not have firmware to corrupt. They are slow to retrofit but permanent once installed.

5. Keep the human in the loop deliberately

Manual overrides and local shutdown handles matter most when remote systems are unavailable, untrusted or actively compromised. Train operators to use them without hesitation.

Frequently Asked Questions

What is cyber-informed engineering in simple terms?

It is an engineering approach that treats cyber risk as a design input rather than a bolt-on. Instead of defending digital systems, engineers design processes so that a successful cyberattack cannot produce severe physical consequences — using independent hardwired trips, analog redundancy, manual overrides and functional isolation.

Does removing the PLC from the trip path violate functional safety standards?

No — it typically strengthens the claim. IEC 61508 and IEC 61511 require protection layers to be independent and to avoid common-cause failure. A hardwired, normally closed trip that shares no controller, network or workstation with the basic process control system is a textbook example of genuine independence, though it must still be verified, tested and documented within the safety lifecycle.

Is a hardwired trip enough on its own?

Rarely. Layered protection means the hardwired trip is the last line, not the only line. Alarms, diagnostics, segmentation and monitoring still reduce how often that final layer is called upon. The CIE principle is simply that the last line must not depend on a remotely reachable digital device.

Does this mean PLCs are unsafe and should be replaced?

No. PLCs remain the most efficient way to run production, and safety-certified controllers handle many protective functions reliably. The argument is about placement, not abandonment: a programmable device should not be the singular barrier between a hazard and the outside world.

Where should a brownfield plant begin?

Pick one high-consequence process, such as a chemical dosing loop, and pilot a hardwired, independent final trip. Instrument it, test it, and use the results to build an internal business case. Retrofits at a single critical point are far easier to fund than site-wide programmes.

The Takeaway

Cyber-informed engineering is not a rejection of digital control. It is a reordering of priorities. When the assumption shifts from "we will keep them out" to "they will get in," the design question changes from protecting networks to engineering out consequences.

A normally closed level switch wired into a motor starter is a small, unglamorous piece of copper. It is also a statement about where trust should ultimately sit in an industrial plant — in the physics of the process, not in the firmware of a controller that someone, somewhere, can reach.

Related Articles

Back to blog