LB-2026-04 · Landscape Briefing · July 2026
Security by Default, Legacy by Deployment: The Encryption Gap in the Installed S7 Base
Executive Summary
Siemens S7 communication has moved decisively towards encryption by default. Current controllers, configured with the current engineering toolchain, protect programming and HMI traffic with certificate-based transport security as a native, preconfigured feature. This briefing documents a gap between that norm and the field: the installed base of S7 controllers remains, in its majority, communication that a passive observer can read. Three regimes coexist across the estate, from cleartext S7comm on the widely deployed S7-300 and S7-400 families, through application-layer encrypted S7CommPlus, to S7CommPlus wrapped in TLS on current hardware. The field is dominated by the readable regimes, and the gap persists through economics rather than ignorance. For any approach that passively observes S7 traffic, the implication is mixed rather than bleak: across most of the deployed estate, passive observation remains viable because the traffic is readable; where encryption is in force, it marks the boundary of the passive vantage. Encryption is the state of the art in S7 communication. It is not yet the state of the field.
Cite this report
@techreport{salmazo_s7gap_2026,
author = {Bruno Salmazo},
title = {Security by Default, Legacy by Deployment: The Encryption Gap in the Installed S7 Base},
institution = {Liscere},
year = {2026},
month = jul,
number = {LB-2026-04},
type = {Landscape Briefing},
url = {https://liscere.com/research/lb-2026-04/}
}