For decades, PLCs lived comfortably inside panels. Their wiring was clear, their reach was limited, and only those with the panel key could touch them. Security back then was about locks, not firewalls.
Then came the need for remote monitoring. Modbus RTU, which used to run on serial cables, was moved to Modbus TCP/IP. HMI was connected, then SCADA, followed by dashboards that could be accessed from the meeting room. Integration was complete, and production became more monitored. What often went unnoticed in the commissioning minutes was that at this point, the PLC changed status, from an isolated device to a node on the network.
The numbers are not small
The Kaspersky ICS CERT report for the first quarter of 2026 noted that 21.81 percent of industrial control system computers in Indonesia encountered dangerous objects that were successfully blocked. More than one in five. The global figure for the same period was 19.6 percent, meaning Indonesia sits above the world average.
Broken down by sector, oil and gas had the highest at 28 percent, followed by electricity and building automation at 24.5 percent each. Interestingly for automation professionals, the category of ICS engineering and integration itself was at 21.2 percent. The parties installing the systems also became targets, not just the factories using them.
"Old operational technology systems remain deeply embedded in manufacturing environments, making them vulnerable," said Evgeny Goncharov, Head of Kaspersky ICS CERT, in a statement accompanying the report.
Modbus was born in a trusting world
Modbus was designed by Modicon in 1979 to communicate with PLCs in closed networks. Simple, open, and still widely used today precisely because of its simplicity. Modbus TCP wraps the same messages into TCP/IP packets and listens on port 502.
The problem is, this protocol does not carry built-in authentication mechanisms. A legitimate write command and a write command from an unauthorized party look the same at the protocol level. This is not a design flaw. It is a consequence of its initial assumption: if you are on that network, you are indeed entitled to be there.
This assumption made sense in 1979. In factories where the control network and office network merged without barriers, the same assumption turned into a vulnerability.
Barriers, not just antivirus
The approach used by the IEC 62443 standard, published by ISA and IEC, is not to replace the protocol. What is done is to break the network architecture into zones, which are groups of assets with similar protection needs, and then organize conduits, the communication paths between zones. Each zone is assigned a security level target, starting from SL 1, which protects against accidental misuse, to SL 4 for advanced attacks with significant resources.
The practical implications are actually down-to-earth. Know exactly which devices are connected. Separate the control network from the office network. Change default credentials that are often left unchanged since commissioning. Limit who can write to registers, not just who can read.
The context of policies that are starting to harden
On the regulatory side, Presidential Regulation Number 47 of 2023 on the National Cybersecurity Strategy and Cyber Crisis Management places strengthening the protection of vital information infrastructure as one of the focus areas. The energy, electricity, and public services sectors are included. For engineers working in these sectors, network segmentation is slowly shifting from merely a good practice to part of compliance.
It should be emphasized that this does not mean automation engineers must pivot to become security analysts. A realistic portion is more about architectural awareness. The person who understands why one register can be written to and why another register should not is usually not the IT team, but the person who writes the logic.
Integrating PLCs with HMI and SCADA remains a technical task that is reasonable and indeed necessary. However, now there is an additional question worth asking before commissioning is closed: after everything is connected, who can actually send commands here?
Sources
- ItWorks (quoting Kaspersky ICS CERT) – ICS Computers Targeted in Indonesia Q1 2026, Oil and Gas Sector Most Targeted → itworks.id
- Detik Inet – 1 in 5 Industrial Computers in Indonesia Attacked by Malware, Oil and Gas Sector Vulnerable → inet.detik.com
- JDIH BPK Regulation Database – Presidential Regulation Number 47 of 2023 on the National Cybersecurity Strategy and Cyber Crisis Management → peraturan.bpk.go.id
- Indonesian Automation Association – Understanding the MODBUS Protocol → automation.or.id
- Fortinet – IEC 62443 Standard: Enhancing Cybersecurity for Industrial Automation and Control Systems → fortinet.com