Industry 4.0, digital twins, predictive maintenance. The vision sounds great. On the factory floor, the software is often decades behind. Stuxnet exploited unpatched Windows XP and hardcoded default passwords on Siemens STEP 7 controllers to physically destroy Iranian centrifuges.1 The Colonial Pipeline shutdown in May 2021 came down to a single compromised password on a legacy VPN without multi-factor authentication. Fuel supply across the US East Coast was disrupted for six days.2
The gap between the connected factory vision and the legacy reality grows wider every year.
1 Symantec W32.Stuxnet Dossier, 2010
2 CISA Alert AA21-131A, May 2021
3 IBM X-Force Threat Intelligence Index, 2022