Schneider Electric Deepens OT Security as Attacks Target PLCs

Schneider Electric Deepens OT Security as Attacks Target PLCs

Why it matters now: The industrial threat model has fundamentally changed. Attackers are no longer content to steal data from corporate networks—they are reaching directly into PLC cybersecurity territory, tampering with programmable logic controllers to stall production lines, damage machinery and put operators at risk. Against that backdrop, Schneider Electric has deepened its OT security collaboration with French specialist SECLAB, a signal that controller-level protection is moving from a niche engineering concern to a board-level priority.

Analyst Insight: The pivot is deliberate. For years, OT security budgets flowed toward network monitoring and IT-style firewalls. The 2025–2026 attack wave—nation-state actors rewriting PLC logic and ransomware crews triggering physical shutdowns—exposed the gap: visibility on the wire does not stop a malicious command that the controller happily executes. The new frontier is enforcement at the device and protocol layer.

Schneider Electric and SECLAB: Inside the Expanded Partnership

The two companies are combining their operational technology expertise to adapt SECLAB technology to Schneider Electric's automation architectures. The stated goal is fine-grained, application-level filtering of the industrial protocols exchanged between programmable logic controllers (PLCs), distributed control systems (DCS) and safety instrumented systems (SIS).

The collaboration is designed to deliver a level of protection that goes beyond software-only defenses, embedding an additional enforcement layer directly into the control architecture. SECLAB, founded in 2011 and headquartered in France, is ANSSI-certified and has built its reputation on securing the systems of France's most critical operators.

Yann Bourjault, Vice President of Digital Transformation & Cybersecurity Europe at Schneider Electric, framed the move as a matter of operational continuity rather than pure IT hygiene.

“Our responsibility as an industrial company is to protect the continuity of our operations and those of our customers, while advancing the compliance and resilience of the industrial architectures we deploy,” he said. “This partnership allows us to deliver complementary OT protection that has been proven with our automation systems, is integrated by our experts, and is maintained over time within existing service contracts.”

Technical Scope: What the Schneider–SECLAB Integration Filters

The expanded collaboration focuses on deep inspection and control of traffic that speaks directly to field devices and safety systems.

  • Protected assets: Programmable Logic Controllers (PLCs), Distributed Control Systems (DCS) and Safety Instrumented Systems (SIS).
  • Filtering layer: Fine-grained application-level inspection of industrial protocols moving between controllers and supervisory systems.
  • Target protocols: Widely deployed industrial standards including Modbus, PROFINET, OPC UA and DNP3.
  • Deployment model: Complementary protection integrated by Schneider Electric experts and maintained within existing service contracts.

The emphasis on the SIS layer is notable. Safety instrumented systems are the last line of defense against physical industrial accidents, and a compromise there converts a cyber event into a safety event.

The Threat Landscape: Adversaries Move Downstream to the Controller

The partnership did not emerge in a vacuum. Government advisories have chronicled a sustained, multi-year campaign that targets the controller itself rather than the systems around it. Rather than defacing screens or encrypting data, these attackers manipulate process logic to produce real-world consequences.

A significant driver has been the convergence of legacy protocols and internet-facing exposure. Modbus, one of the most widely deployed industrial protocols, was engineered for reliability on isolated networks and carries no authentication mechanism—any device that can reach the port can issue commands.

Market Trend: Detection is falling behind intent. Industry research indicates that roughly 88% of OT organizations struggle with detection and response, while more than half cannot see below the IT/OT boundary. Attackers are exploiting that blindness to spend longer inside control environments mapping control loops before they act. Hardware-enforced filtering is increasingly marketed as a way to close the visibility gap without depending on a mature SOC.

Market Data: OT/ICS Risk in Numbers (2025–2026)
  • 508 ICS advisories covering 2,155 vulnerabilities were tracked in 2025—a record volume since industry tracking began.
  • Only 22% of 2025 ICS vulnerabilities carried an associated CISA ICS advisory, down from 58% in 2024, leaving a large share of risk untracked.
  • OT sites experiencing cyberattacks with physical consequences rose 146% year-on-year, according to Q3 2025 industry reporting.
  • 37% of OT attacks with physical consequences in 2024 hit the transportation sector, with discrete manufacturing close behind.
  • 13% of physically consequential attacks directly impacted OT automation systems; roughly 90% caused physical effects indirectly through surrounding infrastructure.

The data points to a single conclusion: the controller is no longer an abstract endpoint. It is the target.

Why Software-Only Defense Is No Longer Sufficient

Traditional OT security stacks rely on passive monitoring, anomaly detection and IT-style segmentation. Each has value, but each assumes an attacker must first do something visibly unusual. A compromised PLC running altered logic can report normal readings to the HMI while the physical process behaves abnormally—operators see a healthy plant on screen while equipment degrades on the floor.

SECLAB's proposition targets exactly that blind spot. Its technology is built around electronically breaking network and USB communication protocols, eliminating the class of risk that stems from software flaws in the cybersecurity appliances themselves. In practice, the approach layers a deterministic control between systems rather than relying solely on pattern recognition.

FAQ: What Plant Operators Need to Know

Does this mean existing PLCs must be replaced?
Not necessarily. The collaboration describes adapting filtering technology to Schneider Electric automation architectures, which suggests retrofit and integration paths rather than wholesale hardware replacement. Confirming compatibility with specific controller families and firmware revisions remains the first step for any site.

Is this only relevant to large critical infrastructure operators?
No. Disruption economics punish mid-sized discrete manufacturers heavily. Downtime is measured in output lost per hour, supply-chain penalties and safety incidents—not just IT cleanup costs.

How does this differ from a traditional industrial firewall?
Conventional firewalls filter by address, port and sometimes protocol signature. The described approach applies fine-grained, application-level filtering to the commands exchanged between controllers, DCS and safety systems—enforcement at the language of the process, not just the perimeter.

What is the primary attack vector being addressed?
Unauthorized modification of controller logic, often via insecure protocols or misconfigured, internet-exposed programming interfaces. Locking controllers into run mode and restricting program access remain foundational controls.

What It Means for Plant Operators and System Integrators

The practical takeaway for automation engineers is that OT security is migrating from a bolt-on service to a design specification. Procurement conversations increasingly include questions about protocol-level filtering, controller hardening and safety-system isolation alongside traditional I/O counts and scan times.

This also raises the stakes on asset lifecycle management. Organizations running long-lived controller platforms must reconcile the desire for modern security enforcement with fleets of legacy hardware that cannot simply be patched into compliance.

Analyst Insight: Expect OT security partnerships to become a competitive differentiator in automation procurement. Vendors that can demonstrate proven, integrated protection—rather than a roadmap of standalone tools—will increasingly win architecture decisions. For operators, the strategic question is no longer whether to invest in controller-level defense, but how quickly an existing installed base can be retrofitted before it becomes the softest target in the network.

The Bigger Picture: Controller Security as a Procurement Requirement

The Schneider Electric–SECLAB expansion is a marker of a maturing market. Cyber resilience for PLCs, DCS and SIS is being folded into the standard lifecycle of industrial equipment, backed by service contracts and expert integration rather than ad hoc projects.

For the global automation sector, the direction is clear. As adversaries continue to shift from data theft toward process manipulation, defense must follow the command path all the way to the controller. The organizations that treat PLC cybersecurity as an engineering discipline—not an IT afterthought—will be the ones whose lines keep running.

Need a quote for this part?

Send us the part number or article link — we will confirm price, availability and lead time.

WhatsApp us

Related Articles

Вернуться к блогу