Podcast: How AI changes cybersecurity for manufacturers
Key Highlights
- AI is accelerating cyberattacks, shortening the window manufacturers have to detect vulnerabilities and deploy defenses.
- Widely deployed PLCs are attractive targets, making OT cybersecurity critical for factories and infrastructure operators.
- Patching is essential, but large manufacturers face complex barriers from legacy systems, software versions and operational requirements.
In this episode of Great Question: A Manufacturing Podcast, IndustryWeek technology editor Dennis Scimeca and Smart Industry head of content Scott Achelpohl discuss the evolving cybersecurity challenges facing manufacturers. They examine recent attacks targeting PTC product lifecycle management software and Siemens S7 PLCs, highlighting the complexities of patching vulnerabilities across industrial environments. The conversation also explores how AI is accelerating cyberattacks and shortening the time available for organizations to respond.
Below is an excerpt from the podcast:
DS: Hello, and welcome to our next episode of the Great Question Podcast. I'm Dennis Scimeca, Senior Editor for Technology at IndustryWeek, and I'm joined by my friend and colleague Scott Achelpohl, Smart Industry's Head of Content.
SA: Heya, Dennis. Nice to be on the program.
DS: Thanks for joining us. So today we're talking cybersecurity, Scott. It's one of the least sexy topics we've covered at IndustryWeek, but also one of the most important. Scott's joining us today because cybersecurity is a much hotter topic over at Smart Industry, where they can get into some of the technical aspects of the hacks that we cover.
Now, IndustryWeek, of course, covered Verizon's annual Data Breach Investigations Report when it was released in late May. You can also look up additional coverage of that on Smart Industry. I recommend looking up these stories for a condensed 50,000-foot view of the cybersecurity situation as a whole, not only in manufacturing, but in terms of major events or attempts to break into a system with no tangible results and major breaches – roughly defined as successful attempts to break into systems that likely include data theft – 2026 has been fairly quiet.
That was until last week, when it rains, it pours, and we had two stories to report on, both at IndustryWeek and Smart Industry.
First, the CLOP — C-L-O-P — ransomware gang claimed responsibility for 43 cyber attacks against targets including GE, Philips, and Shell. The attacks were targeted specifically at two product life cycle management or PLM tools developed by PTC, Windchill, and Flex PLM. The number of victims gives you an idea as to how widely these systems are deployed. Now this story turned into a conversation about patching. Whenever you hear cybersecurity experts describe optimal cybersecurity hygiene, they always talk about the importance of patching. And in this case, PTC began releasing patches for this known vulnerability in mid-June.
So how do companies the size of GE, Phillips, and Shell, that ostensibly have large IT departments with people keeping an eye out for these patch releases, not have their systems patched two months later?
Well, we spoke to some experts, and it turns out that's an incredibly simplistic way to look at the problem. And we can't assume that GE Philips and Shell weren't on the ball here. In fact, the larger the company, the more difficult to apply patches org-wide.
There can be different versions of the software running across the org, and every version might not have a patch released at the same time. If the technology is old, especially an end-of-life system, it might not be easily updatable.
There might be operational or regulatory issues that slow things down. And for all anyone knows, the ransomware gang may have been inside these PTC environments long before anyone realized the security issue existed, in which case the security battle was over before it began.
So the short version is that cybersecurity experts can talk all they want about the importance of patching, but it isn't that simple. And we can't assume that just because a company fell victim to a known vulnerability, even with plenty of advance notice, that means said company isn't monitoring for patch releases and applying them as soon as possible.
The second story we covered a few days after the first, and concerned five S7 series PLC models manufactured by Siemens. Five different US federal agencies, the NSA, FBI, Department of Energy, Cybersecurity and Infrastructure Agency, and even the EPA issued a joint warning about the vulnerability, which suggests how widely these S7 series models are deployed across many different sectors.
And what makes this particularly interesting isn't that a breach took place, but rather the tools threat actors are using to try to crack the security. Smart Industry covered this really heavily, so Scott is really the better choice to get into the nitty gritty here. So Scott, what can you tell us about these tools that hackers are developing? What's the big deal?
SA: AI is the big deal. Over at Smart Industry, we've done a lot of coverage about how AI is being used as an accelerator, basically. Think of if you're throwing gas on a fire, that's essentially what AI is for cyber attackers. AI is incredibly useful, is proving to be useful in a positive way for manufacturers, but this is a way that it's occurring in a negative way.
Now, in this particular attack on the Siemens gear, and it affected a total of five Siemens PLCs, programmable logic controllers, the attackers used what was reported as Python scripts that use the Snap 7 DLL and the Python Snap 7 libraries to infiltrate Siemens S7 PLC devices. The five are the 200, the 300, the 400, the 1200 and the 1500.
And obviously the reason why we cover these is because these are incredibly common plant OT devices. You can find them in a wide range of kinds of factories. You also particularly find them in critical infrastructure, water, water treatment, electric plants, places like that. And that's why it raised such a large, this story to such a large profile. And the fact that these PLCs are were targets and they're so common, and the fact that this was, in the time we've covered this, maybe the most prominent example of AI-enabled cyber attacks.
We've had two or three collaborators talk with us recently about how AI was accelerating cyber attacks, and this was a prime example of how it was happening. I mean, Siemens is a victim of their own success here, that their plant OT is so popular that it serves as such a large target and it dovetailed a little bit with some coverage that we had back in the fall about other Siemens gear an industrial device called the RuggedCom ROXOS II which apparently is quite popular. That particular piece of gear was identified with vulnerabilities by a security engineer whom we worked with, and it was fixed with patching. There was actually no cyber incursion involved in that.
But related to this story, we talked to a cyber CISO, a cybersecurity specialist at a company called Kiteworks that we talk to quite often. And he pointed out something very interesting, particularly about the Siemens attack was that the fact that yes, AI is supercharging cyber attacks and what makes that so dangerous is that number one, Frank said, organizations had better know who and what can reach their systems.
In other words, they’d better know what their own vulnerabilities are and get them patched quickly. Sometimes patching alone can't even close the gap if you don't know where your vulnerabilities are. And he said that, described it exactly as I mentioned, that AI is an accelerant here and it's really shortening the time in between scripts can be written to run these cyber attacks and the actual cyber attacks themselves. So it's really shortening the amount of time that people in IDT departments who are structuring their cyber defenses can erect those defenses and get them up in time before these attacks actually occur.
So that was basically a rundown. I wrote a blog a little bit about some of our other coverage and I encourage those of you who are listening to go read the blog and give us your thoughts.
DS: Do you ever in your stories come across AI-based security tools? Do the good guys get to use AI or is it mostly the hackers right now? Do you know?
SA: So far it’s the hackers. The defenders are still trying to write defenses, essentially. And because the AI defenses are so murky right now, or that the attacks are so murky right now, and it's just territory that's still being plowed, quite honestly, with AI cyber attacks.
Security that will be based on AI, that's to come. I'm sure we'll be doing a lot of reporting on the AI tools that manufacturers in our case will use to defend themselves against these attacks.
DS: I would say that's about it. So we're going to go ahead and wrap this one up. I'm Dennis Scimeca, Senior Editor for Technology at IndustryWeek, and I was joined by friend and colleague Scott Achelpohl, Smart Industry’s Head of Content. Thank you for joining us on Great Question.
About the Podcast
Great Question: A Manufacturing Podcast offers news and information for the people who make, store and move things and those who manage and maintain the facilities where that work gets done. Manufacturers from chemical producers to automakers to machine shops can listen for critical insights into the technologies, economic conditions and best practices that can influence how to best run facilities to reach operational excellence.
Listen to another episode and subscribe on your favorite podcast app
About the Author
Dennis Scimeca
Dennis Scimeca is a veteran technology journalist with particular experience in vision system technology, machine learning/artificial intelligence, and augmented/mixed/virtual reality (XR), with bylines in consumer, developer, and B2B outlets. At IndustryWeek, he covers the competitive advantages gained by manufacturers that deploy proven technologies. If you would like to share your story with IndustryWeek, please contact Dennis at [email protected].
Scott Achelpohl
Scott Achelpohl is the managing editor of Smart Industry. He has spent stints in business-to-business journalism covering U.S. trucking and transportation for FleetOwner, a sister website and magazine of SI’s at Endeavor Business Media, and branches of the U.S. military for Navy League of the United States. He's a graduate of the University of Kansas and the William Allen White School of Journalism with many years of media experience inside and outside B2B journalism.


