Prazamana
Blog

Can You Install Antivirus on a PLC? Why the Question Is the Wrong One

Prazamana3 min read

A plant manager asked us last week whether they could install antivirus software on their PLCs.

It's a reasonable question. But the answer is usually no, and the reason says a lot about how OT security differs from IT security.

A PLC Isn't a Small Industrial Laptop

A PLC is designed to execute control logic predictably, often within tightly defined scan-cycle and timing constraints. Adding conventional endpoint security software can introduce processing overhead, compatibility issues, and unpredictable behaviour that simply isn't acceptable for a device controlling a physical process.

There's another problem: many PLCs run specialised or proprietary operating environments, often with limited support for conventional endpoint protection or modern patching mechanisms. You can't always treat a PLC the way you would treat a Windows workstation.

The Protection Model Has to Be Different

That doesn't mean the PLC doesn't need protection. Quite the opposite — it means the protection model has to be different.

Instead of putting antivirus on every controller, OT security typically starts with architecture:

  • Segmenting control networks
  • Restricting who and what can communicate with PLCs
  • Controlling engineering access
  • Managing remote connections
  • Maintaining secure configurations
  • Monitoring for abnormal activity

The Question Worth Asking Instead

The question isn't really "How do we install antivirus on the PLC?"

It's: "How do we prevent an unauthorised system from reaching the PLC in the first place, and how would we know if something unusual happened?"

That's the shift from thinking about OT as IT infrastructure to thinking about it as a system that controls the physical world.

Need Help With Compliance?

Talk to Prazamana about machine safety standards and CE marking for your equipment.