Summary
- The NCSC says operational technology has been targeted across multiple sectors globally, including in the UK, with some limited real-world disruption.
- Misconfiguration, legacy connections, weak credentials, unsupported equipment, and unmanaged assets can expose industrial environments to the public internet.
- Organisations are being urged to inventory OT, isolate devices, strengthen access controls, monitor connections, and give boards assurance over resilience.
Britain’s National Cyber Security Centre has warned organisations to find industrial equipment and network devices that have accidentally or unnecessarily been left accessible from the public internet after observing increased targeting of operational technology across several sectors globally, including in the UK. The agency says the activity has already caused limited real-world disruption, although it has not publicly attributed the pattern to a single actor.
The warning covers operational technology used to control or monitor physical processes, including equipment found in manufacturing, utilities, transport, and other infrastructure-heavy environments. Unlike conventional office IT, these systems can contain programmable logic controllers, human-machine interfaces, industrial gateways, and remote-access systems whose operational lives stretch across many years.
That longevity creates a persistent security problem because connectivity often accumulates around equipment that was not designed for direct exposure to modern internet threats. The NCSC says organisations should not assume their operational environments are isolated without checking, since forgotten remote-access routes, misconfiguration, legacy connections, and unmanaged assets can leave equipment reachable from networks its operators believe are separated.
The agency is calling for definitive inventories of operational assets and communication routes, accompanied by stronger authentication, supported boundary equipment, network segregation, secure management protocols, and monitoring. Industrial devices including programmable controllers and human-machine interfaces should not be directly accessible from the public internet, while default and shared credentials should be replaced wherever systems allow.
Old connectivity becomes an operational risk
Although the immediate alert concerns industrial environments, the same pattern extends to edge devices positioned around conventional enterprise networks. Routers, firewalls, remote-access appliances, and other boundary equipment are attractive targets because compromise can give an attacker a route around controls protecting systems further inside an organisation.
Boundary devices can also receive less operational attention than servers and employee endpoints. An appliance may remain in service because it continues performing its networking function even after vendor support has ended or a management interface has been forgotten, leaving infrastructure that appears reliable operationally while becoming progressively harder to defend.
The NCSC recommends keeping edge equipment within vendor support, applying updates, replacing products before end of life, and restricting administration to segregated management networks. It also advises organisations to retire insecure management protocols where possible and adopt safer alternatives when industrial equipment supports them.
Those recommendations are comparatively mundane beside discussion of AI-enabled attacks or highly capable state-backed intrusion groups, but many incidents begin with ordinary weaknesses. A publicly exposed interface, unchanged credential, unsupported router, or forgotten connection can remove the need for an attacker to defeat more sophisticated controls elsewhere.
OT security is reaching the board
The agency has placed the warning within its Cyber Assessment Framework rather than treating it solely as technical advice for industrial engineers. Boards should seek assurance that security and resilience outcomes are being achieved across systems supporting essential functions, pushing responsibility beyond the teams that operate individual plants or network appliances.
That approach aligns with the UK’s broader move towards tighter cyber-resilience requirements. The Cyber Security and Resilience Bill is intended to give government a larger role in technology risk around essential services, extending the policy focus beyond incident response towards weaknesses embedded in systems and supply chains.
Operational technology makes that shift difficult because replacing vulnerable equipment is rarely equivalent to patching an employee laptop. Industrial systems can have narrow maintenance windows, specialist certification requirements, dependencies on machinery expected to remain in use for decades, and safety constraints that prevent operators changing configurations simply because a software update is available.
Compensating controls therefore become necessary where equipment cannot be modernised immediately. Network isolation, tightly controlled remote access, monitoring, asset discovery, and the ability to disconnect affected systems can reduce exposure while replacement programmes catch up with technology that has outlived its original security assumptions.
The NCSC is also directing organisations towards its Early Warning service, which can flag vulnerabilities and other issues associated with internet-facing systems. Such services are particularly useful where an organisation cannot confidently describe everything it exposes externally, since automated attackers scanning public infrastructure may otherwise develop a more accurate inventory than the organisation running it.
The latest warning does not suggest that every connected industrial device is about to be compromised, nor that recent targeting has caused widespread disruption. Instead, it concentrates attention on an avoidable class of exposure while the capability and incentive to interfere with physical services are increasing.
The practical work remains deliberately unglamorous: establish what is connected, determine what can be reached from outside, remove unnecessary exposure, and check whether the devices controlling the boundary remain supported. Organisations unable to answer those questions cannot treat presumed isolation as a security control.












