20 August 2026
Executive Summary
Cybersecurity is normally associated with stolen data, compromised email accounts or ransomware locking employees out of computer systems.
A new US government warning highlights something considerably more physical.
The US Cybersecurity and Infrastructure Security Agency, NSA, FBI, Department of Energy and Environmental Protection Agency issued a joint advisory on 19 August warning of an active threat against Siemens S7 Series programmable logic controllers.
These PLCs are not ordinary office computers.
They are used to monitor and control industrial processes across sectors including manufacturing, energy, water and wastewater, chemicals, food and agriculture. US authorities warn that compromise could potentially cause process disruption, downtime, equipment damage and, depending upon the system involved, safety consequences.
The agencies also say attackers are using AI tools to reduce the time and technical expertise required to develop effective exploits.
This exposes an important corporate blind spot:
A company can secure its laptops and servers while leaving the equipment that physically runs the factory exposed.
UK Impact
This is highly relevant to UK businesses even though the latest warning originates in the United States.
Programmable logic controllers and industrial control systems are widely used in:
- Manufacturing.
- Water treatment.
- Food production.
- Chemical processing.
- Warehousing.
- Energy.
- Building management.
- Packaging.
- Pharmaceuticals.
- Utilities.
- Automated production lines.
The distinction between IT and operational technology — OT — matters enormously.
Traditional corporate cybersecurity concentrates on information:
- Emails.
- Financial records.
- Customer data.
- Servers.
- Cloud platforms.
Operational technology controls physical processes.
That can include:
- Opening and closing valves.
- Operating pumps.
- Controlling temperatures.
- Starting machinery.
- Managing production speeds.
- Monitoring pressure.
- Controlling industrial motors.
A compromised OT system can therefore create a business interruption without the attacker ever needing to steal a customer record.
Global Impact
The US advisory follows earlier warnings concerning attackers targeting programmable industrial equipment, including devices produced by Siemens, Rockwell Automation and Schneider Electric.
The potential consequences are materially different from a conventional data breach.
Authorities specifically warn that compromises can create:
- Disruption to critical processes.
- Safety incidents.
- Operational downtime.
- Equipment damage.
- Data compromise.
- Regulatory consequences.
- Cascading effects across interconnected systems.
This also demonstrates how AI may change the threat landscape.
AI does not necessarily need to invent a completely new form of cyberattack.
It can make existing technical attacks faster and easier to execute.
That potentially lowers the expertise threshold required to target industrial infrastructure.
Our View
Businesses should establish whether their cybersecurity programme properly includes operational technology, rather than assuming protection of corporate IT also protects industrial systems.
Companies should ask:
- Which PLCs and industrial controllers operate our critical processes?
- Who manufactured them?
- What software and firmware versions are running?
- Are those systems connected to corporate IT networks?
- Can they be reached remotely?
- Are default passwords still in use anywhere?
- Are obsolete controllers still operating because replacing them would interrupt production?
- Who monitors manufacturer security advisories?
- Are industrial systems segmented from ordinary office networks?
- Can equipment be operated manually if control systems fail?
- Are engineers included in cyber incident exercises?
- Would cyber insurance respond to physical equipment damage caused through a cyber event?
- Does the business-interruption policy contemplate an OT shutdown?
- Do critical suppliers have the same exposure?
The central lesson is that modern cyber risk no longer stops at the keyboard.
When computer systems control physical equipment, a cyberattack can cross the boundary between the digital and physical world.
The question businesses should increasingly ask is not only:
“Could someone steal our data?”
It is:
“Could someone tell our machinery what to do?”
Risk Indicator: HIGH
Does This Risk Affect Your Business?
Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.
From individual businesses to major international organisations, risk is our business.
TALK TO INVICTUS →Disclaimer
The information contained within these Market Alerts is provided for general market awareness and informational purposes only. It does not constitute financial, legal, investment, regulatory or insurance advice. Whilst every effort has been made to ensure accuracy at the time of publication using multiple reputable and independently verified sources, geopolitical events, legislation, regulation and market conditions may change rapidly. Readers should obtain appropriate professional advice before acting upon any information contained herein.
Invictus Risk Solutions LLP – Helping organisations stay ahead of emerging risks through informed insight and independent analysis.
