A PLC Should Not Be Directly Accessible from the Public Internet. In Critical Infrastructure, It Poses a Risk to Production Processes
The digitalisation of industry, energy, transport, water management and other strategic sectors brings a marked increase in efficiency and opens up possibilities for automated control. At the same time, however, it creates an ever closer link between the digital and the physical world. It is precisely this link that represents one of the significant challenges for the protection and resilience of critical infrastructure.
The National Cyber Security Centre (NCKB) of the National Security Authority has warned of the danger of operating programmable logic controllers (PLCs) that are freely accessible from the public internet. PLCs are devices designed to control and automate technological and production processes, and they should not be directly accessible from the public internet. Such exposure can create scope for unauthorised access to, and interference with, the process the device controls.
From the perspective of critical infrastructure, this warning is important in a broader context as well. It shows how substantially cybersecurity now overlaps with physical security and the operational resilience of critical entities.
A Digital Risk Can Have a Physical Consequence
With an ordinary information system, we tend to associate a cyber incident primarily with the loss or misuse of data, system unavailability or economic damage. In the environment of industrial and control technologies, however, the consequences can be considerably wider.
These technologies feed directly into the control of physical processes – the generation and distribution of energy, the pumping and treatment of water, production lines, transport systems and other technological equipment. Under certain circumstances, a cyber vulnerability can therefore turn into an operational risk, a safety incident or an interruption in the provision of an essential service.
For critical entities, what matters is therefore not only the protection of information systems, but also the ability to anticipate the impact their disruption may have on real-world operations.
Protecting the Individual Device Is Not Enough
In the view of the Critical Infrastructure Association of the Slovak Republic, risks of this kind need to be seen systemically.
The security of critical infrastructure cannot be reduced to protecting an individual server, control element or piece of technological equipment. What is decisive is knowing the entire chain of dependencies that enables a particular essential service to be provided.
That chain encompasses the technological infrastructure, communication links, remote access, servicing and maintenance, updates, technology and software suppliers, subcontractors, and also the human capacity needed to handle an incident.
A single seemingly peripheral device may be part of a process on which a far more extensive operation depends. When assessing risks, it is therefore not enough to consider the importance of the component itself; above all, one must consider the scale of the consequences that its compromise or failure may cause.
The Weak Point May Not Be Where We Expect It
Modern critical infrastructure is made up of a multitude of interconnected technologies, organisations and supplier relationships. A risk can therefore also arise through service access, an external supplier or a technological component that receives insufficient attention in routine assessments.
For critical entities it is therefore increasingly important to build a map of their technological and supplier dependencies and to identify the points whose disruption could have a significant impact on the functioning of the organisation or the provision of an essential service.
Older industrial technologies deserve particular attention. Many were designed at a time when their present-day connection to corporate networks, remote management or the internet environment was not anticipated. Digitalisation can thus fundamentally change the security profile of equipment that was originally operated in a relatively isolated environment.
From Protecting Technologies to the Resilience of the Service
The evolution of security threats shows that the protection of critical infrastructure must gradually shift from the question “How do we protect this particular device?” to the broader question “Can we ensure the provision of the essential service even if some part of the system fails or is attacked?”
Such an approach presupposes working with disruption scenarios, having alternative modes of operation ready, ensuring that technologies and suppliers can be substituted, being able to identify an incident in good time, and restoring the functioning of the affected processes as quickly as possible.
Tibor Straka, President of the Critical Infrastructure Association of the Slovak Republic, notes in this connection: “The resilience of critical infrastructure is today decided also at the level of technologies that may not appear strategic at first glance. Yet if they control or influence an essential service, their security becomes part of the security of the entire system. That is why we must know not only our key technologies, but also the significant dependencies associated with their operation.”
The Security of Critical Infrastructure Is a Shared Task
The current warning from the National Security Authority is another example of why the exchange of information between the state, critical entities, technology companies and the professional and academic community matters in protecting critical infrastructure. Information about a specific vulnerability or risk is of greatest value when we can translate it into knowledge of our own infrastructure, an assessment of the possible consequences and, subsequently, into preventive measures.
The Critical Infrastructure Association of the Slovak Republic is working intensively to build professional capacities focused on risk monitoring, the analysis of technological and supplier dependencies, the exchange of experience between individual sectors, and the creation of scenarios for the possible disruption of essential services.
The protection of critical infrastructure is increasingly becoming a question of the ability to see individual technologies as part of a wider system. True resilience does not lie only in whether we can prevent an incident, but also in whether we can keep an essential service running when one occurs despite the measures taken.




Gas as a Test of Slovakia's Resilience: Energy Security Does Not End with the Price of the Commodity




