Skip to content

Cybersecurity

OT cybersecurity in logistics and automated warehouses: heterogeneous systems and high turnover

Modern automated warehouses run complex OT networks: a WMS wired to the automation, heterogeneous PLCs from many vendors, AGVs and mixed protocols. High turnover and frequent vendor work break segmentation, and downtime hits the supply chain instantly.

6 min read
Automated warehouse with AS/RS systems, vertical racking and AGVs on the floor

Logistics automation as the new OT frontier

Logistics has changed radically over the past decade. Modern warehouses are no longer passive storage spaces: they are complex cyber-physical systems where dozens of different technologies (automated storage and retrieval systems, AS/RS, sorters, conveyors, automated guided vehicles, AGVs, robotic picking systems) cooperate in real time to move thousands of SKUs per day.

This automation has made logistics more efficient, but it has also created an OT attack surface that few organizations know they have, and even fewer know how to protect. A mid-sized automated warehouse can hold dozens of PLCs from different vendors, hundreds of sensors, and mixed protocols ranging from Modbus to OPC-UA all the way to proprietary protocols from the AS/RS vendor: all networked, all dependent on continuous operation.

The risk is not theoretical. In 2021 a cyberattack on the IT network of a large international transport company spread to the warehouse management systems, halting sorting operations for several days. The fallout on the supply chains of the logistics operator's customers was felt for weeks. The automated warehouse has become a critical node in the value chain: stopping it has immediate cascading effects.

Warehouse OT architecture: heterogeneous complexity

The OT architecture of a modern automated warehouse is structurally more complex than that of a manufacturing plant with a single production line. The reason is variety: a manufacturing plant often relies on a limited number of vendors for its control systems, while a warehouse integrates systems from different suppliers that were selected independently over time.

The WMS as integration hub. The Warehouse Management System is the brain of the warehouse: it manages storage locations, orchestrates movements and coordinates the automated systems. The WMS is typically an IT application (a Windows or Linux server, a relational database, a web interface or a thick client) that talks directly to the OT systems (conveyor PLCs, AS/RS control systems, AGV management software) through integration interfaces. This hub position makes it a prime attack vector: compromising it means gaining access to the interfaces toward every automated system.

Heterogeneous PLCs. The sorters may come from one vendor, the conveyors from another, the AS/RS from a third and the AGVs from a fourth. Each vendor uses its own PLCs (Siemens, Allen-Bradley, Beckhoff, Mitsubishi) and its own communication protocols. Managing these systems requires different tools and skills for each vendor; security monitoring has to understand protocols that no single product supports fully.

Mixed protocols. A typical warehouse uses Modbus for simple sensors and actuators, OPC-UA for integration with the WMS, the vendor's proprietary protocols for communications internal to the AS/RS, and Wi-Fi for the AGVs. Each protocol has its own security characteristics (OPC-UA supports authentication and encryption, while Modbus has no authentication mechanism at all) and its own specific vulnerabilities.

High staff turnover: the human risk in logistics

The logistics sector has historically had one of the highest staff turnover rates in manufacturing. In automated warehouses this translates into a specific security problem: a large number of people with access, even partial, to the control systems change frequently, and access management processes (creating, modifying and revoking credentials) rarely keep pace.

Unrevoked credentials belonging to former employees are one of the simplest and most often overlooked access vectors. A technician who leaves the company but keeps their VPN credentials or WMS access is a concrete vulnerability. In a sector with high turnover and HR processes under pressure, this scenario is more common than it should be.

The problem is not limited to direct staff. Automated warehouses frequently rely on temporary workers, agency staff and third-party operators for seasonal peaks or for specific operational phases. These workers are granted system access (even just to picking terminals or to the conveyor HMI panels) that is rarely managed with the same care reserved for permanent staff.

The technical answer to this problem is twofold: rigorous access lifecycle management processes (systematic onboarding and offboarding, including for temporary staff), and monitoring that detects anomalous credential use, such as unusual hours, access to systems the user does not normally touch, and logins from unexpected geographic locations.

Vendor maintenance: frequent and poorly tracked access

Logistics automation systems require regular maintenance: PLC firmware updates, sensor calibration, tuning of AGV routing algorithms, corrective work on faults. This maintenance is often carried out by the vendors of the individual systems, who have remote access, or physical on-site access, to their own components.

The access pattern of logistics automation vendors differs from that of vendors in other sectors: it is frequent (periodic maintenance, small interventions, updates), it involves several different vendors at the same site, and it often happens unscheduled (fault response with minimal notice). This makes it hard to apply the access controls that would be feasible in a planned maintenance context.

In practice, many warehouses manage vendor access with generic VPN solutions, credentials shared among the vendor's technicians (often the same account used for years), and no systematic logging of what is done during each session. Knowing that "vendor X logged in on Tuesday" is not enough: you need to know which systems they accessed, which configurations they changed and which commands they ran.

A pragmatic solution: implement a Privileged Access Management (PAM) solution specific to OT vendor access, one that records sessions completely and lets you tie every change to an identified technician. The PAM does not have to be integrated with every OT system: even a solution that manages perimeter access and records sessions at the network level adds significant value compared with the current situation.

WMS-TMS-ERP integration: where segmentation ends

The warehouse is not an island: it is integrated with the Transport Management System (TMS) for shipment planning, with the ERP for inventory management and purchase orders, and with customer portals for shipment visibility. Each of these integrations is a potential propagation path for an attack.

The logistics supply chain is particularly exposed to this risk because data flows in both directions: the warehouse receives orders from the ERP, but it also sends status data and confirmations in real time toward systems that are often owned by customers or partners. A logistics operator that integrates the systems of dozens of customers has a very wide attack surface.

The concept of segmentation, fundamental in OT security, is put under pressure by these integrations. The point is not to eliminate the integrations, which are necessary for the business to run, but to make them controlled: well-defined API interfaces instead of direct database connections, strong authentication for every integration, monitoring of the traffic that crosses the perimeter, and the ability to isolate individual integrations in case of compromise without shutting down the entire warehouse.

Operational continuity: the cost of downtime is immediate

Unlike other OT environments where a production stoppage has effects that show up over hours or days, downtime in an automated warehouse has immediate, measurable impact: orders are not processed, shipments do not leave, customers do not receive their goods. In an e-commerce or just-in-time manufacturing context, even a few hours of downtime have effects that spread rapidly through the supply chain.

This impact profile makes automated warehouses an attractive target for ransomware attacks: the pressure to pay quickly to restore operations is very high. And it makes incident response decisions particularly difficult: shutting systems down to contain an attack means halting operations; continuing to operate with potentially compromised systems is a risk.

Operational continuity planning for an automated warehouse must explicitly consider the OT attack scenario: which operations can be carried out manually (degraded mode), for how long, and at what capacity? Having that answer before an incident occurs significantly reduces decision time when it counts.

Some organizations have started to include manual operating procedures in their OT continuity plans: mapping the critical operations that can be performed without automated systems, training staff for those procedures, and periodically verifying that the procedures actually work. It is an investment they hope never to need, but one that has enormous value the moment it becomes necessary.


Automated logistics has entered the category of critical OT infrastructure without the culture of industrial security following the same path. The first step, valid for any automated warehouse regardless of size, is to build visibility into what is in the OT network and how it communicates. From that visibility the real priorities emerge, far more useful than any theoretical framework applied without knowing the specific environment.

The MON5 angle

Dozens of PLCs from different vendors, mixed protocols from Modbus to OPC-UA all the way to the AS/RS vendor's proprietary ones: the OT network of an automated warehouse is exactly the heterogeneous environment that calls for unified visibility. MON5 builds it passively, listening to traffic on the native OT protocols and maintaining a continuous inventory of systems, firmware and communication relationships between the WMS and the automation, without stopping any movement.

Continuous monitoring with anomaly detection then catches anomalous credential use and vendor sessions that fall outside the usual patterns, two of the risks that high staff turnover makes concrete. To really know what is in your network, you start with an OT assessment.

Related articles

Industrial OT network assessment with passive traffic analysis and ICS device profiling

Cybersecurity

How an OT Assessment Is Conducted: Phases, Methods and What You Really Find

An OT network assessment is not a vulnerability scan run on corporate IT. Different methodology, different risks, and often surprising results: here is what to expect from a properly conducted industrial assessment.

6 min read

Do you have visibility into your OT network?

MON5 maps assets, vulnerabilities and anomalies in real time — without stopping production.

MON5.EU

OT (Operational Technology) cybersecurity for manufacturing plants. Map, identify, monitor and protect your industrial network.

🇮🇹MON5 S.R.L. · Italy
Bologna · Via Paolo Nanni Costa 20
Faenza · Corso Aurelio Saffi 21
VAT IT02725300392
🇱🇺AARG S.à.r.l. · Luxembourg
49, Boulevard Royal
L-2449 Luxembourg
VAT LU35998569
© 2026 MON5 · All rights reserved
Get certifications
Coesione Italia 21-27 Emilia-Romagna · Co-funded by the European Union · Ministero delle Imprese · Regione Emilia-Romagna