NCSC publishes water-utility example for secure OT connectivity guidance

The UK National Cyber Security Centre (NCSC) has released a fictional worked example showing how organisations can apply its Secure Connectivity Principles for Operational Technology. The scenario fol...

The UK National Cyber Security Centre (NCSC) has released a fictional worked example showing how organisations can apply its Secure Connectivity Principles for Operational Technology. The scenario follows a regional water utility seeking to standardise digital connectivity across its operational technology (OT) estate without compromising safety, reliability or cyber resilience.

The publication is intended as a practical illustration rather than a prescribed network design. It encourages organisations to use the principles as a target state while adapting implementation decisions to their own operating environment, regulatory responsibilities, legacy systems and threat profile.

Applying the principles in practice

In the scenario, the fictional organisation “Admin Corp Water” considers each of the eight principles and examines the architectural, governance and operational measures needed to support secure connectivity. The example addresses issues including:

  • Reducing unnecessary exposure of OT systems
  • Centralising and controlling connectivity
  • Managing legacy technologies and protocols
  • Strengthening boundaries between OT and external networks
  • Preparing for and responding to cyber incidents

The NCSC said the example demonstrates that effective OT security depends on more than technical architecture. Organisations must also establish suitable governance and operating processes, while balancing security requirements with safety, availability and the practical limitations of older infrastructure.

Industry collaboration

The work was developed with the NCSC’s Industrial Control Systems Community of Interest Boundary Expert Group. The group includes practitioners from critical national infrastructure sectors who design, secure and operate connections between operational systems and outside networks.

This is the first content authored directly by the group for the NCSC website. The collaboration was intended to test the guidance against real-world constraints and make the resulting recommendations more relevant to organisations responsible for critical services.

The NCSC said sector-led examples could be developed for other industries, where operational conditions, regulation and cyber threats differ. Such material can help organisations translate broad principles into practical decisions without implying that a single architecture will suit every environment.