The U.K. National Cyber Security Centre (NCSC) said it has seen increased targeting of OT (operational technology) systems across multiple sectors globally, including in the U.K., with activity by a range of threat actors causing limited real-world disruption. The agency said organizations using, deploying or maintaining OT should review their security posture, warning that internet exposure can arise through misconfigurations, legacy connections or unmanaged assets.
“This has been carried out by a range of threat actors and resulted in some limited real-world disruption,” the agency wrote in a Thursday news post. “Any organisation that uses, deploys or maintains OT systems should treat this development seriously and review their security posture accordingly. Organisations should not assume that their OT is inaccessible from the internet without verifying it, as unintended exposure can arise through misconfigurations, legacy connections, or unmanaged assets.”
The NCSC also identified that, while it has observed targeting of OT, there continues to be a broader pattern of disruptive cyber activity targeting internet-exposed systems and edge devices across all sectors.
“We have previously highlighted other activity such as that against poorly configured routers, published in July 2026 with international partners,” the post detailed. “For non-OT organisations, such activity highlights the importance of maintaining visibility of internet-exposed assets and edge network devices. Key actions include maintaining an accurate inventory of internet-facing systems, understanding the function and data flows of edge devices, applying vendor security updates promptly, retiring end-of-life equipment, disabling insecure management protocols such as SNMP v1, SNMP v2 and Telnet, and monitoring for unexpected configuration changes or outbound connections.”
The agency called upon organizations to develop a definitive view of OT architecture, including all assets, communications pathways and external connections. This approach identifies internet-exposed systems, unmanaged assets and legacy connectivity that may introduce risk. OT devices, such as PLCs (programmable logic controllers) and HMIs (human machine interfaces), should not be directly exposed to the public internet.
Moreover, organizations must change default credentials and prevent shared passwords on web interfaces, management interfaces, and management protocols. Implementation requires unique administrator accounts, multi-factor authentication (MFA) wherever supported, and stronger authentication mechanisms such as public/private key authentication instead of passwords where protocols support it (e.g., SSH).
The agency also required hardening of OT boundaries. Access to OT from external or untrusted networks must be strictly controlled. Devices facilitating external connectivity, such as industrial gateways, firewalls, routers and remote access appliances, must remain within vendor support, receive routine updates, be replaced before end-of-life, and be managed only from segregated management networks disconnected from the internet.
Organizations should adopt secure versions of industrial and management protocols where available. For industrial protocols, this includes migrating DNP3 to DNP3-SAv5, CIP to CIP Security, Modbus to Modbus Security, and OPC DA to OPC UA. For management, this means removing telnet, SNMP v1, and SNMP v2. Insecure protocols with no secure alternatives should be limited to isolated network segments.
The NCSC mandated logging and monitoring of all connectivity to and within OT networks, with particular focus on detecting attempts to communicate with OT assets from unexpected devices, networks, or routes. Static and predictable OT environments benefit from baseline monitoring to identify unauthorized activity, misconfigurations, or cyber compromise. PLCs should not be left in PROGRAM or other maintenance modes. Controller logic requires password-based write protection or equivalent mechanisms to prevent unauthorized changes, reducing risks from accidental modification and malicious alteration of operational processes.
Finally, the agency called for segmentation of management networks, OT control systems, and business IT networks based on function and criticality, with communications restricted to those required for operations. This approach limits unauthorized access and prevents compromised systems from affecting the wider environment.
Organizations must maintain tested backups of OT systems, configurations, controller logic, and critical engineering data, with regular restoration and recovery practice. Affected systems should be quickly isolable from the broader network to enable rapid restoration from trusted backups and minimize downtime. Backups should be designed to be ransomware-resistant.
The NCSC also suggested that organizations build effective cyber resilience to be prepared before an incident occurs and capable of responding and recovering when one does. “Organisations should review their readiness for significant cyber incidents, taking account of the NCSC’s guidance on preparing for severe cyber threats, and ensure that arrangements for responding to and recovering from cyber attacks are established, maintained and regularly exercised in line with the NCSC’s guidance on what to do when cyber attacks disrupt your organisation.”
Additionally, organisations should register for the NCSC’s free Early Warning service to help identify publicly exposed vulnerabilities and other potential security issues affecting internet-facing systems, supporting efforts to detect and address risks before they are exploited.
Noting that this marks a significant step up for the industry, Ric Derbyshire, principal security researcher at Orange Cyberdefense, identified this as “we’ve moved beyond warning about the risk of OT disruption to actively seeing real-world impact. The advisory from the NCSC marks a notable change for industrial cybersecurity. We’ve moved past the stage of warning about the risk of OT disruption to actively seeing real-world impact.”
He added that the impact observed so far is limited, “but this is still a clear escalation in the threat to OT. I’d advise every organisation operating in OT to take the advisory seriously and review where assets are exposed to the internet.”
This week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) published guidance to help organizations identify systems accessible from the internet, remove unnecessary remote access and secure internet-facing assets. The guidance focuses on reducing an organization’s exposure to potential cyber threats by identifying externally accessible systems and addressing access that is not required. It also concentrates on reducing internet exposure as a way to strengthen cybersecurity defenses, and calls on organizations to assess which systems are reachable from the internet, eliminate unnecessary remote access and secure systems that must remain externally accessible.

