Protected By Scarcity
Operational technology was never as protected by its software as by its labour market. Attacking a programmable logic controller meant understanding an industrial protocol, a specific vendor’s hardware and the physical process behind it, and very few people on earth could do all three. That scarcity was the control. On 19 August 2026 five United States agencies confirmed that it has gone.
What happened
On 19 August 2026 the National Security Agency, the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, the Department of Energy and the Environmental Protection Agency issued joint advisory AA26-231A. It warns of an active campaign building AI-assisted attack tooling for Siemens S7 programmable logic controllers, the family of industrial computers that runs turbines, pumps, production lines and safety systems across the physical economy.
The method described is deliberately unremarkable at every step except one. Attackers use commercial internet scanning services to find S7 controllers that are exposed to the internet or sit behind poor network segmentation. They then deploy Python exploitation scripts, generated with the assistance of AI and built on the open-source snap7 library, disguised as legitimate operational technology monitoring tools. Once connected, those scripts give an attacker read and write access to PLC memory, configuration and ladder logic over the S7comm protocol on TCP port 102. In plain terms, the attacker can read how the plant is run and rewrite it.
The agencies do not describe a single catastrophic breach. They describe something a board should find more uncomfortable: patient work. They assess the activity as persistent reconnaissance and pre-positioning for future effects operations, and they characterise it as an active threat. The exploit tooling is being built and staged now, against targets that have not yet been struck.
The dated sequence
- 22 July 2026An earlier joint advisory, AA26-097A, is updated. Carrying seven authoring agencies, it attributes exploitation of internet-exposed S7 controllers to Iranian-affiliated actors and documents a United States water site where the shutdown and alarm logic on a controller was disabled. The count of affected states rises from seven to a reported twelve. The exposure and the intent were already established.
- 19 August 2026AA26-231A is published by five agencies. The same class of target, but a different capability: AI-generated Python tooling built on the snap7 library, disguised as monitoring software, giving read and write control of S7 controllers over S7comm. The agencies assess persistent reconnaissance and pre-positioning for effects operations.
The scope is broad
The advisory covers all CPU variants of the S7-200, S7-300, S7-400, S7-1200 and S7-1500 ranges, including the F-series safety controllers whose entire purpose is to bring a process to a safe state. The named sectors are critical manufacturing, energy, water and wastewater, chemical, food and agriculture, commercial facilities, and the defence industrial base. If your organisation makes, moves, treats or powers anything physical, an S7 controller is very likely inside the process.
Why this one is different
Most industrial control system advisories tell you that a vulnerability exists and that a patch or mitigation is available. This one tells you that the economics of the attacker have changed.
The barrier that protected operational technology was human, not technical. Writing a working exploit for a specific PLC required an engineer who understood the S7comm protocol, the target hardware and the industrial process well enough not to simply trip an obvious fault. That combination of skills is rare and slow to acquire, and that rarity did more to defend industrial estates than most of the security controls layered on top of them.
AA26-231A is the first official, multi-agency confirmation that AI removes that constraint. The advisory states plainly that AI dramatically reduces the technical expertise and the time needed to develop working ICS exploitation scripts. The scarce specialist is no longer required. The barrier that was doing the quiet work of protection has been lowered, and it will not be raised again.
The estate did not change. The defences did not weaken. The number of people capable of writing the attack simply stopped being small. That is the whole event.
The commercial exposure for UK organisations
This is a United States advisory, but the exposure it describes is structural, and the structure is the same on this side of the Atlantic. Siemens S7 is the dominant PLC family across UK and European manufacturing, water and energy. That is precisely the estate that regulators have designated as essential and important entities. The advisory is, in effect, describing the control systems that sit under the NIS2 perimeter.
Regulatory. Operators of essential services in the UK already sit under the NIS Regulations 2018 and are assessed against the NCSC Cyber Assessment Framework. The Cyber Security and Resilience Bill enters Lords committee stage on 1 September 2026, and it will widen the population of in-scope organisations and tighten reporting duties. Organisations with European operations are inside NIS2, whose obligations reach the security of the systems they acquire and maintain. A regulator will read a five-agency advisory naming a specific, widely deployed controller family as notice. Inaction after notice is a different conversation from inaction before it.
Financial. The loss event here is not a data notification. It is physical: halted production, damaged plant, emergency response and the reconstruction of control logic, alongside the safety and environmental consequences of a process taken out of its safe envelope. Because AI lowers the cost and time of building the exploit, the expected frequency of this class of event rises, and expected frequency multiplied by a high per-event cost is what insurers and finance functions actually price.
Contractual. Most S7 controllers were installed, connected and configured by a systems integrator or an equipment supplier, not by the asset owner. The advisory itself acknowledges the awkward consequence: asset owners frequently cannot see their own internet exposure, because a third party created it. If your contracts with those integrators are silent on internet exposure, segmentation, credential standards and a right to test, you have not transferred that risk. You have only lost sight of it.
Governance. The advisory offers mitigations, and the first of them is to inventory all of your S7 PLCs. For a large share of operators that single instruction is the hardest one on the list, because the estate was assembled over years by multiple suppliers and no complete, current inventory exists. The uncomfortable truth is that the first recommended mitigation is an exercise most organisations cannot actually complete today. Until it can, every control that follows it is being applied to a map with gaps in it.
What leaders should decide now
These are board decisions, not engineering tickets. Each one is a commitment of authority and budget, not a patch.
1. Commission the inventory as a funded programme, not a request. Direct that a complete, current inventory of S7 controllers and their network reachability be produced, and resource it as the multi-supplier exercise it actually is. Treat the absence of that inventory as the primary finding until it exists.
2. Assume exposure you did not create. Require confirmation, from evidence rather than assurance, of which controllers are reachable from the internet or across weakly segmented networks, including exposure introduced by integrators and suppliers.
3. Reset the contractual boundary with integrators and suppliers. Make internet exposure, segmentation, credential hygiene and a right to test explicit obligations in the contracts that govern your control systems, rather than assumptions about them.
4. Fund detection at the protocol layer. Ensure that unexpected S7comm activity on port 102, and write operations to controllers, generate an alert that someone is accountable for, so that reconnaissance is seen while it is still reconnaissance.
5. Rehearse the safe-state and recovery decision. Confirm that the organisation knows how it would bring affected processes to a safe state and restore verified control logic, and that the people who would make that call have practised it before the day they need it.
Three questions for leadership
Executives do not need to read the S7comm specification. They need three answers.
1. Can we produce, today, a complete list of our S7 controllers and say which are reachable from a network we do not fully control?
2. If a controller began behaving abnormally next week, would we detect it as an attack, and how quickly could we bring the process to a safe state?
3. Where an integrator or supplier created our connectivity, what right do we hold to test their configuration, and when did we last exercise it?
If the first question cannot be answered with a document, the other two are theoretical.
The strategic takeaway
For a decade, industrial operators have benefited from a defence they never bought and rarely acknowledged: the sheer difficulty of finding someone able to weaponise their control systems. AA26-231A is the moment the state confirmed that this defence has expired. The software did not become more vulnerable. The pool of people able to exploit it stopped being small.
The organisations that come through this well will not be the ones that patched fastest. They will be the ones that already knew what they owned, where it was reachable, who connected it and how they would respond. That knowledge is inexpensive to build in advance of an incident. Discovering its absence during one is not.
The barrier that protected operational technology was scarcity. Scarcity is not a control you can rely on any longer.
Can you name every S7 controller you own and every network that can reach it?
A focused assessment of your operational technology exposure: which controllers are reachable and by whom, what your integrator and supplier contracts actually oblige, where protocol-layer detection sits, and what evidence you could put in front of a regulator, an insurer or an enterprise client tomorrow.
Start the Conversation →Sources: CISA and partners, Joint Cybersecurity Advisory AA26-231A, “AI-assisted exploitation tooling targeting Siemens S7 programmable logic controllers”, 19 August 2026 (NSA, CISA, FBI, DOE, EPA). CISA and partners, Joint Cybersecurity Advisory AA26-097A, updated 22 July 2026 (seven authoring agencies). Siemens ProductCERT guidance on S7 controller hardening. Snap7 open-source library documentation. UK Parliament, Cyber Security and Resilience (Network and Information Systems) Bill, Lords committee stage 1 September 2026. NCSC Cyber Assessment Framework. Directive (EU) 2022/2555 (NIS2). GCS Threat Briefings translate live advisories into the governance and commercial decisions boards and security leaders need to make.
Garzon Cyber Solutions delivers cybersecurity advisory, compliance certification, and specialist technology recruitment as one integrated capability. We are a young firm, the founder personally runs the work, and our perspective comes from a career spent inside cybersecurity and compliance across the sales, marketing and technical sides of the industry.