Jagannathan Raghunathan is director of cyberphysical security services at Bureau Veritas and co-chair of the PLC Security Top 20 List. In this interview, he outlines how the PLC Security Top 20 List addresses programmable logic controller (PLC) vulnerabilities by offering practical, engineering-focused guidance across the hardware lifecycle. Rather than relying solely on high-level IT security frameworks, the initiative leverages the built-in capabilities of industrial controllers to enforce core hardening principles. His recommendations include eliminating direct Internet exposure, replacing default credentials, restricting engineering workstation access, enforcing granular role-based authentication and maintaining off-line logic backups to ensure controllers remain in a known secure state.
Legacy PLCs were originally engineered decades ago with a focus on uptime and availability within physically isolated networks. However, the shift toward remote operations during the COVID-19 pandemic, alongside the rise of cloud-hosted SCADA platforms, cellular modems and AI-driven programming, has expanded the attack surface. Because foundational industrial protocols like Modbus were designed without native encryption or authentication, modern connectivity options have left legacy hardware susceptible to basic Internet scans and open-source intelligence tools, says Raghunathan.
He urges industry stakeholders to eliminate undocumented remote access pathways, secure unavoidable connections and adopt a security-by-design methodology, rather than attempting to bolt on safeguards post-commissioning.
Chapters
- 00:00 – CISA Warning on PLC Threats
- 01:17 – PLC Security Top 20 Initiative
- 03:13 – History & Purpose of the PLC Top 20 Group
- 04:50 – Why PLCs Are Vulnerable by Design
- 09:10 – Remote Access, Cloud SCADA & AI Impacts
- 15:20 – System Integrators & Machine Builders
- 17:46 – Security by Design