Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Siemens Notifies Customers of Microsoft Defender Antivirus Issue

Siemens is working with Microsoft to address a Defender Antivirus problem that can lead to no malware alerts or plant disruptions.

Siemens cybersecurity

Siemens informed customers on Tuesday that it’s working with Microsoft to address an issue related to Microsoft Defender Antivirus (MDAV) and Simatic PCS products. 

According to the advisory published by the industrial giant, the problem is that Defender Antivirus currently does not provide ‘alert only’ functionality. 

Siemens’ documentation for Simatic PCS 7 and PCS Neo process control systems describes Microsoft Defender Antivirus configurations for specifying threat alert levels at which no default action is taken when a threat is detected. 

The problem is that if the product is set to ‘ignore’, then no action is taken and no alert is generated for the plant operator and administrator when malware is detected. 

If a different setting is used, Defender Antivirus may delete or quarantine files flagged as potential malware (both true and false positives), which can lead to disruptions if the system is relying on the potentially infected file.

“The result could be that affected devices will not work anymore, which can lead to loss of monitoring and control of the plant,” Siemens explained.

Advertisement. Scroll to continue reading.

Until the company works out a solution with Microsoft, plant managers relying on Simatic PCS are advised to conduct a risk assessment to determine whether they want to be alerted about malware infections, or risk disruptions if the antivirus deletes potentially important files.

Customers can cluster impacted devices and apply different configurations to each cluster depending on their needs and requirements. 

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Related: Misconfigured HMIs Expose US Water Systems to Anyone With a Browser

Related: Ramnit Malware Infections Spike in OT as Evidence Suggests ICS Shift

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Stephen Garcia has been named Chief Information Security Officer at BreachRx.

Kasper Lindgaard has been appointed Vice President of Security Strategy at CoreView.

Chaim Mazal has been named Chief Information Security Officer at GitLab.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.