Firmware Updates
Firmware updates correct known faults and close security gaps in relays, controllers and HMI panels. They also rewrite the device, so an interrupted update can leave a unit that will not start. Plan the work into a shutdown window rather than attempting it on a live system.
Before the update
- Record the current firmware version of every device you intend to touch.
- Export and store the running configuration. A firmware update can reset parameters to factory defaults.
- Confirm the target version is approved for your hardware revision. Controllers of the same model can carry different revisions.
- Ensure the supply is stable, ideally through a UPS.
Performing the update
- Take the device out of service and confirm the process it controls is safely stopped.
- Connect over the engineering port rather than the plant network, so other traffic cannot interrupt the transfer.
- Load the firmware file and start the transfer. Do not remove power or disconnect the cable until the device reports completion.
- Allow the device to restart on its own. A forced restart during the write is the usual cause of a bricked unit.
- Verify the reported version, then reload the saved configuration.
After the update
Re-run the functional checks for anything the device controls, including trips and interlocks. Treat the update as complete only once those tests pass and the results are recorded against the project.
If the update fails
Leave the device powered and connected, and do not retry repeatedly. Note the exact point of failure and the error shown, then contact ECS support through the contact page. Most controllers have a recovery mode, but using it correctly depends on how far the write progressed.