A PLC Should Not Be Directly Accessible from the Public Internet. In Critical Infrastructure, It Poses a Risk to Production Processes

27. augusta 2026

The digitalisation of industry, energy, transport, water management and other strategic sectors brings a marked increase in efficiency and opens up possibilities for automated control. At the same time, however, it creates an ever closer link between the digital and the physical world. It is precisely this link that represents one of the significant challenges for the protection and resilience of critical infrastructure.



The National Cyber Security Centre (NCKB) of the National Security Authority has warned of the danger of operating programmable logic controllers (PLCs) that are freely accessible from the public internet. PLCs are devices designed to control and automate technological and production processes, and they should not be directly accessible from the public internet. Such exposure can create scope for unauthorised access to, and interference with, the process the device controls.


From the perspective of critical infrastructure, this warning is important in a broader context as well. It shows how substantially cybersecurity now overlaps with physical security and the operational resilience of critical entities.


A Digital Risk Can Have a Physical Consequence


With an ordinary information system, we tend to associate a cyber incident primarily with the loss or misuse of data, system unavailability or economic damage. In the environment of industrial and control technologies, however, the consequences can be considerably wider.


These technologies feed directly into the control of physical processes – the generation and distribution of energy, the pumping and treatment of water, production lines, transport systems and other technological equipment. Under certain circumstances, a cyber vulnerability can therefore turn into an operational risk, a safety incident or an interruption in the provision of an essential service.

For critical entities, what matters is therefore not only the protection of information systems, but also the ability to anticipate the impact their disruption may have on real-world operations.


Protecting the Individual Device Is Not Enough


In the view of the Critical Infrastructure Association of the Slovak Republic, risks of this kind need to be seen systemically.


The security of critical infrastructure cannot be reduced to protecting an individual server, control element or piece of technological equipment. What is decisive is knowing the entire chain of dependencies that enables a particular essential service to be provided.

That chain encompasses the technological infrastructure, communication links, remote access, servicing and maintenance, updates, technology and software suppliers, subcontractors, and also the human capacity needed to handle an incident.


A single seemingly peripheral device may be part of a process on which a far more extensive operation depends. When assessing risks, it is therefore not enough to consider the importance of the component itself; above all, one must consider the scale of the consequences that its compromise or failure may cause.


The Weak Point May Not Be Where We Expect It


Modern critical infrastructure is made up of a multitude of interconnected technologies, organisations and supplier relationships. A risk can therefore also arise through service access, an external supplier or a technological component that receives insufficient attention in routine assessments.


For critical entities it is therefore increasingly important to build a map of their technological and supplier dependencies and to identify the points whose disruption could have a significant impact on the functioning of the organisation or the provision of an essential service.

Older industrial technologies deserve particular attention. Many were designed at a time when their present-day connection to corporate networks, remote management or the internet environment was not anticipated. Digitalisation can thus fundamentally change the security profile of equipment that was originally operated in a relatively isolated environment.


From Protecting Technologies to the Resilience of the Service


The evolution of security threats shows that the protection of critical infrastructure must gradually shift from the question “How do we protect this particular device?” to the broader question “Can we ensure the provision of the essential service even if some part of the system fails or is attacked?”


Such an approach presupposes working with disruption scenarios, having alternative modes of operation ready, ensuring that technologies and suppliers can be substituted, being able to identify an incident in good time, and restoring the functioning of the affected processes as quickly as possible.


Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic, notes in this connection: “The resilience of critical infrastructure is today decided also at the level of technologies that may not appear strategic at first glance. Yet if they control or influence an essential service, their security becomes part of the security of the entire system. That is why we must know not only our key technologies, but also the significant dependencies associated with their operation.”


The Security of Critical Infrastructure Is a Shared Task


The current warning from the National Security Authority is another example of why the exchange of information between the state, critical entities, technology companies and the professional and academic community matters in protecting critical infrastructure. Information about a specific vulnerability or risk is of greatest value when we can translate it into knowledge of our own infrastructure, an assessment of the possible consequences and, subsequently, into preventive measures.


The Critical Infrastructure Association of the Slovak Republic is working intensively to build professional capacities focused on risk monitoring, the analysis of technological and supplier dependencies, the exchange of experience between individual sectors, and the creation of scenarios for the possible disruption of essential services.



The protection of critical infrastructure is increasingly becoming a question of the ability to see individual technologies as part of a wider system. True resilience does not lie only in whether we can prevent an incident, but also in whether we can keep an essential service running when one occurs despite the measures taken.

 


8. októbra 2026
Information about a possible entry of the Slovak and Czech governments into the ownership of the Tesco retail chain raises a broader question than simply the future of one retail company. According to information published by Marker on 7 October, both governments are considering acquiring Tesco’s operations in the Czech Republic and Slovakia. According to the newspaper’s sources, the Slovak part could be worth approximately €400 million. However, no transaction has been decided. The Slovak Antimonopoly Office has also pointed out that these are media reports and that, at the time of its latest statement, it had not been notified of any concentration related to Tesco.
8. októbra 2026
Informácia o možnom vstupe slovenskej a českej vlády do vlastníctva siete Tesco otvára širšiu otázku, než je samotná budúcnosť jedného obchodného reťazca. Podľa informácií, ktoré 7. októbra priniesol Marker, obe vlády uvažujú o kúpe Tesca v Česku a na Slovensku. Podľa zdrojov denníka má slovenská časť predstavovať približne 400 miliónov eur. Zároveň však nejde o rozhodnutú transakciu. Aj Protimonopolný úrad SR upozornil, že ide o medializované informácie a v čase jeho posledného vyjadrenia mu nebola oznámená žiadna koncentrácia súvisiaca s Tescom.
7. októbra 2026
A drone flying over a power plant, airport or water facility does not have to cause any physical damage to disrupt its operations. It may be enough for it to appear in the wrong place at the wrong time, while the critical entity has no idea what it is doing there. This is precisely why attention in Europe is shifting from technologies designed to neutralise drones to something less visible: the ability of critical entities to detect an incident in time, assess it correctly and manage it without unnecessary losses.
7. októbra 2026
Dron nad elektrárňou, letiskom alebo vodárenským objektom nemusí nič poškodiť, aby narušil jeho fungovanie. Stačí, že sa objaví v nesprávnom čase na nesprávnom mieste a kritický subjekt nevie, čo tam robí. Práve preto sa pozornosť v Európe presúva od samotných technológií na zneškodnenie dronov k niečomu menej viditeľnému: k schopnosti kritických subjektov incident včas zachytiť, správne vyhodnotiť a zvládnuť bez zbytočných strát.
2. októbra 2026
A series of expert articles by the Critical Infrastructure Association of the Slovak Republic on essential services under Annex No. 1 to Act No. 367/2024 Coll. on Critical Infrastructure
2. októbra 2026
Séria odborných článkov Asociácie kritickej infraštruktúry Slovenskej republiky o základných službách podľa prílohy č. 1 zákona č. 367/2024 Z. z. o kritickej infraštruktúre
29. septembra 2026
The incident at the primary school in Staškov brings back a topic that deserves continuous attention, not just attention in the aftermath of an incident. The protection of soft targets should form part of a systematic security policy, with clearly defined measures, responsibilities and preparedness for various types of threats.
29. septembra 2026
Udalosť v základnej škole v Staškove pripomína tému, ktorá si zaslúži pozornosť priebežne, nie až po incidente. Ochrana mäkkých cieľov by mala byť súčasťou systematickej bezpečnostnej politiky, s jasne nastavenými opatreniami, zodpovednosťami a pripravenosťou na rôzne typy hrozieb.
24. septembra 2026
We are continuing the series of expert articles by the Critical Infrastructure Association of the Slovak Republic, in which we gradually introduce the individual essential services listed in Annex No. 1 to Act No. 367/2024 Coll. on Critical Infrastructure. Having covered the operation of pipelines for the transport of crude oil and motor fuels, today we move one step upstream to a service that stands at the very beginning of the entire oil chain: crude oil extraction.
24. septembra 2026
Pokračujeme v sérii odborných článkov Asociácie kritickej infraštruktúry Slovenskej republiky, v ktorej postupne predstavujeme jednotlivé základné služby uvedené v prílohe č. 1 zákona č. 367/2024 Z. z. o kritickej infraštruktúre. Po tom, ako sme sa venovali prevádzkovaniu potrubí na prepravu ropy a pohonných látok, sa dnes posúvame o krok proti prúdu k službe, ktorá stojí úplne na začiatku celého ropného reťazca: ťažbe ropy.