A PLC Should Not Be Directly Accessible from the Public Internet. In Critical Infrastructure, It Poses a Risk to Production Processes

27. augusta 2026

The digitalisation of industry, energy, transport, water management and other strategic sectors brings a marked increase in efficiency and opens up possibilities for automated control. At the same time, however, it creates an ever closer link between the digital and the physical world. It is precisely this link that represents one of the significant challenges for the protection and resilience of critical infrastructure.



The National Cyber Security Centre (NCKB) of the National Security Authority has warned of the danger of operating programmable logic controllers (PLCs) that are freely accessible from the public internet. PLCs are devices designed to control and automate technological and production processes, and they should not be directly accessible from the public internet. Such exposure can create scope for unauthorised access to, and interference with, the process the device controls.


From the perspective of critical infrastructure, this warning is important in a broader context as well. It shows how substantially cybersecurity now overlaps with physical security and the operational resilience of critical entities.


A Digital Risk Can Have a Physical Consequence


With an ordinary information system, we tend to associate a cyber incident primarily with the loss or misuse of data, system unavailability or economic damage. In the environment of industrial and control technologies, however, the consequences can be considerably wider.


These technologies feed directly into the control of physical processes – the generation and distribution of energy, the pumping and treatment of water, production lines, transport systems and other technological equipment. Under certain circumstances, a cyber vulnerability can therefore turn into an operational risk, a safety incident or an interruption in the provision of an essential service.

For critical entities, what matters is therefore not only the protection of information systems, but also the ability to anticipate the impact their disruption may have on real-world operations.


Protecting the Individual Device Is Not Enough


In the view of the Critical Infrastructure Association of the Slovak Republic, risks of this kind need to be seen systemically.


The security of critical infrastructure cannot be reduced to protecting an individual server, control element or piece of technological equipment. What is decisive is knowing the entire chain of dependencies that enables a particular essential service to be provided.

That chain encompasses the technological infrastructure, communication links, remote access, servicing and maintenance, updates, technology and software suppliers, subcontractors, and also the human capacity needed to handle an incident.


A single seemingly peripheral device may be part of a process on which a far more extensive operation depends. When assessing risks, it is therefore not enough to consider the importance of the component itself; above all, one must consider the scale of the consequences that its compromise or failure may cause.


The Weak Point May Not Be Where We Expect It


Modern critical infrastructure is made up of a multitude of interconnected technologies, organisations and supplier relationships. A risk can therefore also arise through service access, an external supplier or a technological component that receives insufficient attention in routine assessments.


For critical entities it is therefore increasingly important to build a map of their technological and supplier dependencies and to identify the points whose disruption could have a significant impact on the functioning of the organisation or the provision of an essential service.

Older industrial technologies deserve particular attention. Many were designed at a time when their present-day connection to corporate networks, remote management or the internet environment was not anticipated. Digitalisation can thus fundamentally change the security profile of equipment that was originally operated in a relatively isolated environment.


From Protecting Technologies to the Resilience of the Service


The evolution of security threats shows that the protection of critical infrastructure must gradually shift from the question “How do we protect this particular device?” to the broader question “Can we ensure the provision of the essential service even if some part of the system fails or is attacked?”


Such an approach presupposes working with disruption scenarios, having alternative modes of operation ready, ensuring that technologies and suppliers can be substituted, being able to identify an incident in good time, and restoring the functioning of the affected processes as quickly as possible.


Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic, notes in this connection: “The resilience of critical infrastructure is today decided also at the level of technologies that may not appear strategic at first glance. Yet if they control or influence an essential service, their security becomes part of the security of the entire system. That is why we must know not only our key technologies, but also the significant dependencies associated with their operation.”


The Security of Critical Infrastructure Is a Shared Task


The current warning from the National Security Authority is another example of why the exchange of information between the state, critical entities, technology companies and the professional and academic community matters in protecting critical infrastructure. Information about a specific vulnerability or risk is of greatest value when we can translate it into knowledge of our own infrastructure, an assessment of the possible consequences and, subsequently, into preventive measures.


The Critical Infrastructure Association of the Slovak Republic is working intensively to build professional capacities focused on risk monitoring, the analysis of technological and supplier dependencies, the exchange of experience between individual sectors, and the creation of scenarios for the possible disruption of essential services.



The protection of critical infrastructure is increasingly becoming a question of the ability to see individual technologies as part of a wider system. True resilience does not lie only in whether we can prevent an incident, but also in whether we can keep an essential service running when one occurs despite the measures taken.

 


27. augusta 2026
Digitalizácia priemyslu, energetiky, dopravy, vodného hospodárstva či ďalších strategických odvetví prináša výrazné zvýšenie efektivity a možnosti automatizovaného riadenia. Zároveň však vytvára čoraz tesnejšie prepojenie medzi digitálnym a fyzickým svetom. Práve toto prepojenie predstavuje jednu z významných výziev pre ochranu a odolnosť kritickej infraštruktúry.
27. augusta 2026
The Ministry of the Interior of the Slovak Republic has made public the open part of the National List of Critical Entities of the Slovak Republic. The list is based on Act No. 367/2024 Coll. on Critical Infrastructure and on Amendments to Certain Acts, by which the Slovak Republic transposed the European CER Directive on the resilience of critical entities, and it is the outcome of the critical entity identification process carried out at national level.
27. augusta 2026
Ministerstvo vnútra SR sprístupnilo verejnú časť Národného zoznamu kritických subjektov Slovenskej republiky. Zoznam vychádza zo zákona č. 367/2024 Z. z. o kritickej infraštruktúre a o zmene a doplnení niektorých zákonov, ktorým Slovenská republika prebrala európsku smernicu CER o odolnosti kritických subjektov a je výsledkom procesu identifikácie kritických subjektov realizovaného na národnej úrovni.
25. augusta 2026
In our series gradually introducing the individual essential services under Act No. 367/2024 Coll. on Critical Infrastructure, we continue with another service in the Nuclear Energy subsector: the construction, commissioning, operation and decommissioning of a nuclear installation.
25. augusta 2026
V našej sérii, v ktorej postupne predstavujeme jednotlivé základné služby podľa zákona č. 367/2024 Z. z. o kritickej infraštruktúre, pokračujeme ďalšou službou v podsektore Jadrovej energetiky: výstavba, uvádzanie do prevádzky, prevádzka a vyraďovanie jadrového zariadenia.
21. augusta 2026
The upcoming heating season is a reminder that security of energy supply is not merely a question of the market. The Echo24 portal has drawn attention to an analysis by Oxford Economics, according to which this may be the European Union's most demanding winter in terms of energy supply since the crisis period of 2021–2022. The reasons cited are a combination of slower filling of storage facilities, geopolitical risks, supply outages, drought affecting electricity generation, and higher demand for gas in the power sector. 
21. augusta 2026
Nadchádzajúca vykurovacia sezóna pripomína, že bezpečnosť dodávok energie nie je len otázkou trhu. Portál Echo24 upozornil na analýzu Oxford Economics, podľa ktorej môže byť pre Európsku úniu najnáročnejšou zimou z hľadiska dodávok energie od krízového obdobia rokov 2021 – 2022. Dôvodom má byť kombinácia pomalšieho plnenia zásobníkov, geopolitických rizík, výpadkov dodávok, sucha ovplyvňujúceho výrobu elektriny a vyššieho dopytu po plyne v energetike.
17. augusta 2026
We continue our series dedicated to essential services under Act No. 367/2024 Coll. on critical infrastructure. This time we focus on a service whose importance is growing alongside the transformation of the energy sector – electricity storage.
17. augusta 2026
Pokračujeme v našej sérii venovanej základným službám podľa zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Tentoraz sa zameriavame na službu, ktorej význam rastie spolu s transformáciou energetiky – uskladňovanie elektriny.
12. augusta 2026
Commentary by the Critical Infrastructure Association of the Slovak Republic  Europe is experiencing another wave of extreme heat, which is shifting from an exceptional phenomenon into a new standard. Record temperatures, prolonged drought, and the overheating or decline of watercourses can no longer be viewed solely as an environmental problem. They are increasingly affecting the functioning of the state and threatening the continuity of its basic services.