Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

ICS/OT

Siemens Notifies Customers of Microsoft Defender Antivirus Issue

Siemens is working with Microsoft to address a Defender Antivirus problem that can lead to no malware alerts or plant disruptions.

Siemens cybersecurity

Siemens informed customers on Tuesday that it’s working with Microsoft to address an issue related to Microsoft Defender Antivirus (MDAV) and Simatic PCS products. 

According to the advisory published by the industrial giant, the problem is that Defender Antivirus currently does not provide ‘alert only’ functionality. 

Siemens’ documentation for Simatic PCS 7 and PCS Neo process control systems describes Microsoft Defender Antivirus configurations for specifying threat alert levels at which no default action is taken when a threat is detected. 

The problem is that if the product is set to ‘ignore’, then no action is taken and no alert is generated for the plant operator and administrator when malware is detected. 

If a different setting is used, Defender Antivirus may delete or quarantine files flagged as potential malware (both true and false positives), which can lead to disruptions if the system is relying on the potentially infected file.

“The result could be that affected devices will not work anymore, which can lead to loss of monitoring and control of the plant,” Siemens explained.

Advertisement. Scroll to continue reading.

Until the company works out a solution with Microsoft, plant managers relying on Simatic PCS are advised to conduct a risk assessment to determine whether they want to be alerted about malware infections, or risk disruptions if the antivirus deletes potentially important files.

Customers can cluster impacted devices and apply different configurations to each cluster depending on their needs and requirements. 

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.
ICS Cybersecurity Conference
October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Related: Misconfigured HMIs Expose US Water Systems to Anyone With a Browser

Related: Ramnit Malware Infections Spike in OT as Evidence Suggests ICS Shift

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

With "Shadow AI" usage becoming prevalent in organizations, learn how to balance the need for rapid experimentation with the rigorous controls required for enterprise-grade deployment.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Chris Sistrunk has been promoted to Practice Leader for Mandiant's OT Security Consulting.

Nudge Security has appointed Patrick Dillon as its Chief Revenue Officer.

AutoNation has appointed Brian Fricke as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.