ICS/OT

Siemens Notifies Customers of Microsoft Defender Antivirus Issue

Siemens is working with Microsoft to address a Defender Antivirus problem that can lead to no malware alerts or plant disruptions.

Siemens cybersecurity

Siemens informed customers on Tuesday that it’s working with Microsoft to address an issue related to Microsoft Defender Antivirus (MDAV) and Simatic PCS products. 

According to the advisory published by the industrial giant, the problem is that Defender Antivirus currently does not provide ‘alert only’ functionality. 

Siemens’ documentation for Simatic PCS 7 and PCS Neo process control systems describes Microsoft Defender Antivirus configurations for specifying threat alert levels at which no default action is taken when a threat is detected. 

The problem is that if the product is set to ‘ignore’, then no action is taken and no alert is generated for the plant operator and administrator when malware is detected. 

If a different setting is used, Defender Antivirus may delete or quarantine files flagged as potential malware (both true and false positives), which can lead to disruptions if the system is relying on the potentially infected file.

“The result could be that affected devices will not work anymore, which can lead to loss of monitoring and control of the plant,” Siemens explained.

Advertisement. Scroll to continue reading.

Until the company works out a solution with Microsoft, plant managers relying on Simatic PCS are advised to conduct a risk assessment to determine whether they want to be alerted about malware infections, or risk disruptions if the antivirus deletes potentially important files.

Customers can cluster impacted devices and apply different configurations to each cluster depending on their needs and requirements. 

Learn More at SecurityWeek’s ICS Cybersecurity Conference
The leading global conference series for Operations, Control Systems and OT/IT Security professionals to connect on SCADA, DCS PLC and field controller cybersecurity.

October 27-30, 2025 | Atlanta
www.icscybersecurityconference.com

Related: ICS Patch Tuesday: Vulnerabilities Addressed by Siemens, Schneider, Aveva, CISA

Related: Misconfigured HMIs Expose US Water Systems to Anyone With a Browser

Related: Ramnit Malware Infections Spike in OT as Evidence Suggests ICS Shift

Related Content

ICS/OT

NMFTA research shows a Bendix EC80 brake controller safety recall also patched remote code execution and DoS vulnerabilities.

ICS/OT

Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption.

ICS/OT

The grants will help local governments assess and improve cyber defenses amid a multistate campaign targeting water and wastewater infrastructure.

ICS/OT

Michigan, South Dakota, and Georgia are reportedly on the list of states whose water systems have been targeted by Iran-linked hackers.

ICS/OT

CISA is urging water and wastewater utilities to lock down internet-exposed controllers, days after intrusions hit dozens of Minnesota systems.

ICS/OT

The guidance details steps organizations can take to isolate vital OT and supporting systems, and operate in isolation for an extended period.

ICS/OT

State and federal agencies respond after intrusions disrupt automated controls at municipal water and wastewater utilities.

Cybersecurity Funding

The company will use the fresh investment to grow its customer success and AI R&D teams.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version