Once It’s In: Where Can an Unauthorized Device Go?

unauthorized device on a plant network

Schedule a Portnox Cloud demo today.

Contents

In manufacturing, you can ask your team for a device inventory. You’ll probably get one. But ask what any single device or non-human identity (NHI) on that list is allowed to reach, and the room gets quiet. That second question is the one that matters, because an unauthorized device on a plant network doesn’t cause damage by existing, it causes damage going places it was never meant to be. This piece walks the attack path: from entry, through the historian and the engineering workstation, to the domain controller that also serves your front office.

The Device Connects Without Question or Challenge

The path starts in a mundane way. A contractor plugs into a live jack in the conference room off the plant floor. A barcode scanner fails mid-changeover and maintenance swaps in the spare from the crib, setting it to the static IP the old one had. Same address, different firmware revision, running an embedded web server the previous unit didn’t. Or perhaps a machine comes back from the OEM’s depot with a cellular modem the service tech added for remote diagnostics, which nobody on your team was told about.

None of these looks suspicious enough to question. The device that hurts you usually doesn’t arrive looking like a threat. It arrives looking like a normal thing on a normal Tuesday. That’s the profile of an unauthorized device on a plant network: unremarkable, until it moves.

Why the Floor Says Yes

Ports stay open because most Programmable Logic Controllers (PLCs), drives, and remote I/O blocks have no 802.1X supplicant — they can’t authenticate on their own, so the workaround is a MAC Authentication Bypass (MAB) entry for each one, admitting a device on its hardware address alone. That was a defensible tradeoff, not negligence; nobody’s revisited it since the plant converged with IT.

Segmentation doesn’t save you either. Most plants aren’t flat — there’s a firewall at the boundary, maybe VLANs per cell — but the access control lists between cells were written by an integrator who’s long gone, and they’ve been widened every time something didn’t talk to something else at 2am. The network’s default answer to an unauthorized device on a plant network is “yes,” and there’s rarely anything downstream ready to say “no.”

The Walk: Where an Unauthorized Device on a Plant Network Goes

Switch port to historian. The historian accepts connections from anything on the plant floor, by design – that’s its job. It runs on a Windows Server build that’s behind on patches because patching it means scheduling downtime, and with three shifts there is no maintenance window.

Historian to engineering workstation. The engineering workstation holds vendor programming software, project files for every PLC on the line, and cached domain credentials belonging to a controls engineer with broad rights.

Engineering workstation to HMI. The human-machine interface stations run on shared credentials, frequently auto-login, frequently identical across the plant. Alongside them sit the non-human identities that keep the line running – service accounts for the historian connection, machine credentials issued at commissioning – and they authenticate exactly as well as a person would.

Engineering workstation to domain controller. This is the pivot that matters. That workstation is domain-joined to the same Active Directory (AD) serving accounting and email. The plant boundary you built stops traffic. It does not stop identity.

The attack path doesn’t require touching a PLC. It requires ordinary Windows infrastructure sitting on the plant floor.

 

unauthorized device on a plant network

 

The Line Stops in an IT Event, Not an OT Event

From the domain controller, anything domain-joined can be reached as a trusted user – and nearly everything is domain-joined, including the file servers sitting in the front office.

Nobody reprograms a PLC or changes a setpoint, the temperature or line speed a machine is told to hold. The file server your Manufacturing Execution System (MES) depends on gets encrypted. The MES issues work orders to the floor and records what got built. Work orders stop reaching the floor, production can’t be recorded, and quality can’t release finished goods. The line stops because the system that tells it what to build, and proves what it built, is gone.

That’s the part worth sitting with. Your hit to Overall Equipment Effectiveness (OEE) came from a file server in the front office, not from anything on the plant floor. And the per-minute math is unforgiving. In ABB’s 2025 downtime report, 83% of industrial decision-makers put the cost of unplanned downtime at $10,000 an hour or more, and 76% put it as high as $500,000. That’s somewhere between $170 and $8,300 a minute. The range is that wide because it spans every kind of plant. Yours is a single number, and someone in operations can tell you what it is this afternoon.
For manufacturing, the damage is measured in minutes of line stoppage, not in compromised controllers.

The Distance Nobody Measures

Reach is what turns a contractor laptop into a line stoppage — the real cost of an unauthorized device on a plant network. Manufacturing has been the most-attacked industry for five consecutive years, at 27.7% of all cyberattacks in 2025, according to IBM’s 2026 X-Force Threat Intelligence Index and the reason isn’t attacker sophistication. It’s a plant floor built to say yes to anything that asks, and never asked to prove otherwise.

Changing that answer doesn’t mean locking the plant floor down. Portnox profiles each device as it connects – identifying it from its traffic patterns, DHCP behavior, and MAC address rather than trusting what it claims to be — then enforces what that specific device is permitted to reach. A barcode scanner gets scanner access, not a path to the domain controller. Equipment that can’t run an 802.1X supplicant is admitted through profiled MAC authentication instead of an open port, which also catches the spare that came back with different firmware. And because Portnox’s Device Trust evaluates policy continuously rather than only at login, a device that changes fingerprint after it connects triggers an alert or gets pulled off the network automatically — no one has to walk to a switch.

Learn more at Portnox.com.

Share

About the Author

Picture of Janna Bureson

Janna Bureson

Janna Bureson helps SaaS companies translate complex technical topics into stories for broader audiences. As a product marketer at Portnox, she writes about how enterprise organizations can modernize access control, from passwordless authentication and zero trust to AI identity governance.

About the Author

Picture of Janna Bureson

Janna Bureson

Janna Bureson helps SaaS companies translate complex technical topics into stories for broader audiences. As a product marketer at Portnox, she writes about how enterprise organizations can modernize access control, from passwordless authentication and zero trust to AI identity governance.

Related Reading

Artificial IntelligencePortnox Product Release

Your Employees Already Gave ChatGPT (and Half a Dozen Other Tools) Access to Everything. Did You Notice?

September 22, 2026
Network SecuritySecurity Trends

The Three Parties Now Asking Manufacturers to Prove What’s on Their Network

September 22, 2026
Network Access ControlNetwork Security

What the Jaguar Land Rover Breach Really Exposed

September 18, 2026