Summary
- The NCSC has published a fictional water-utility example applying its eight Secure Connectivity Principles to operational technology.
- The design covers legacy systems, remote access, centralised connections, monitoring, segmentation, backup communications, and deliberate isolation during incidents.
- The guidance treats cyber architecture as part of safety and service continuity, showing why connected infrastructure cannot be managed using ordinary corporate IT assumptions alone.
The National Cyber Security Centre has turned its operational-technology connectivity principles into a detailed water-sector blueprint, showing how a utility could modernise remote access and network links without creating an uncontrolled route into pumps, treatment systems, telemetry, and other essential infrastructure.
The worked example is fictional, but its environment is recognisable. “Admin Corp Water” supplies millions of homes and businesses through treatment works, reservoirs, pumping stations, pipelines, programmable logic controllers, human-machine interfaces, remote telemetry units, and supervisory control and data acquisition systems.
The organisation also faces a transition common across utilities and industrial operators. Analogue communication services are disappearing, more sites require digital connectivity for maintenance and monitoring, software updates are becoming centralised, and operators want better visibility across geographically dispersed assets.
Connecting those systems creates exposure because operational equipment can remain in service for decades and may rely on protocols or assumptions developed when the network was largely isolated. The NCSC’s example applies eight Secure Connectivity Principles covering business justification, exposure reduction, centralised connections, secure protocols, hardened boundaries, containment, monitoring, and isolation planning.
Connectivity begins with operational consequence
Before drawing the network architecture, the fictional utility establishes what risks the organisation will accept. The worked example gives it zero tolerance for cyber incidents that could result in unsafe water and very low tolerance for connectivity failures capable of causing prolonged disruption to supply, requiring senior owners to approve the business case.
That approach recognises that connectivity also creates operational value. Remote access can reduce engineer travel, centralised management simplifies software updates, and better monitoring can identify failures more quickly, so simply disconnecting every operational system would remove business and service benefits alongside cyber risk.
The design instead differentiates between services according to consequence. Remote maintenance is useful but can be withdrawn if necessary because engineers can return to sites physically, while communications supporting regional monitoring and control require greater resilience where their loss could affect continuity of supply.
The example uses fixed communications with an independent mobile backup and avoids making operational activity dependent on the enterprise IT network. Separating those paths reduces the chance that a corporate outage or compromise automatically removes the utility’s ability to monitor and operate physical processes.
Legacy equipment dictates the security architecture
When the fictional organisation maps its estate, it finds a mixture of direct internet connections retained for vendor support, mobile links, and some locations connected too closely to the corporate network. The proposed architecture moves those connections towards a central secure-connectivity service rather than maintaining a patchwork of site-specific routes.
Remote users connect through hardened jump hosts rather than directly to operational devices, while unsolicited inbound connections are removed. Patching and antivirus updates are redesigned so that systems inside the OT environment initiate or broker the process rather than allowing corporate services to push traffic freely into sensitive networks.
Protocol age creates another constraint because industrial equipment often outlives ordinary enterprise technology. The utility audits communications across process control, telemetry, servers, and workstations, replaces insecure protocols where feasible, and applies compensating controls where legacy equipment cannot yet be removed.
The architecture also assumes that perimeter security can fail. A demilitarised zone and multiple enforcement points limit how far an attacker can move after compromising one system, while emergency credentials are retained for situations in which central identity infrastructure becomes unavailable.
Isolation has to work before an incident
The eighth principle concerns deliberate isolation, which carries different consequences in operational environments from an ordinary office network. Disconnecting a business application can be disruptive, whereas disconnecting an industrial system without understanding its dependencies can itself create a safety or service failure.
The NCSC therefore treats isolation as an operating state to be designed and rehearsed in advance. Organisations need to know which functions remain available, how local operators regain access, which updates stop flowing, how monitoring changes, and what has to happen before systems are connected again.
That focus aligns with a broader move from preventing every intrusion towards preserving essential functions during compromise and recovery. The NCSC has warned about hostile-state pressure on UK critical infrastructure, while legacy technology and growing dependence on external connectivity continue to expand the attack surface.
The water example was developed with the Industrial Control Systems Community of Interest’s Boundary Expert Group and is intended to be useful beyond one sector. Energy, manufacturing, transport, and other cyber-physical environments face the same combination of long-lived equipment and rising demand for remote access, central management, data collection, and digital maintenance.
None of the individual controls depends on exotic security technology, which is precisely why the example is useful. The difficult work lies in documenting the estate, removing historical exceptions, deciding which connections are necessary, assigning ownership of the resulting risk, and ensuring the network can continue operating when central systems fail.
For a water utility, connectivity eventually reaches processes that determine whether water remains safe and whether customers continue receiving it. The NCSC’s blueprint treats that operational reality as the starting point for cyber architecture rather than something to consider after a network has already been connected.












