The current geopolitical situation has created increased cybersecurity risks across all industrial sectors. This challenging environment also impacts the operational technology (OT) landscape, where we observe an intensification of threat activities.
Recently, CISA, FBI, DC3 and NSA published a joint advisory about an increased threat level for critical infrastructure and industrial control systems [0].
Given these developments, Siemens strongly recommends customers to review and implement the necessary measures to protect their infrastructure.
Keep the devices and systems updated to the latest version to limit the attack vectors that might exploit known vulnerabilities.
Disconnect or remove any devices from networks with inadequate security level (internet, unmaintained internal networks, inadequate physically secured environments etc.) or install additional protection measures (e.g. firewalls).
Use strong, unique passwords; do not use default password; use long enough and complex passwords.
Follow the Siemens Operational Guidelines for Industrial Security [1].
Siemens will continue to monitor the situation and will share any relevant updates for our customers via the Siemens ProductCERT News Website [2].
Subscribe to our mailing list [3] to get notified on the latest updates on Siemens devices.
[0] CISA.GOV Fact sheet [1] Siemens Operational Guidelines [2] Siemens ProductCERT News [3] Siemens ProductCERT Mailing List