NCSC warns organisations to reduce exposure of internet-connected OT systems

The UK National Cyber Security Centre (NCSC) is urging organisations to review the security of operational technology (OT) after observing increased targeting of industrial systems in the UK and inter...

The UK National Cyber Security Centre (NCSC) is urging organisations to review the security of operational technology (OT) after observing increased targeting of industrial systems in the UK and internationally. The activity, involving both state and non-state actors, has caused limited real-world disruption across multiple sectors.

Organisations that operate, deploy or maintain OT should not assume their systems are isolated from the internet. Exposure can result from configuration errors, older connections, unmanaged equipment or remote-access arrangements. The NCSC said the warning forms part of a broader effort to strengthen resilience as geopolitical tensions and cyber capabilities continue to develop.

  • Map the environment: Create an accurate inventory of OT assets, network routes, external connections and legacy systems. Confirm that programmable logic controllers (PLCs), human-machine interfaces (HMIs) and similar devices cannot be reached directly from the public internet.
  • Improve authentication: Replace default credentials, eliminate shared passwords, use separate administrator accounts and enable multi-factor authentication where available. Stronger methods, such as key-based authentication, should be considered when supported.
  • Secure network boundaries: Restrict connections from untrusted networks and keep firewalls, routers, industrial gateways and remote-access appliances supported and patched. Their administration should be limited to a segregated management network.
  • Prefer secure protocols: Adopt protected alternatives such as DNP3-SAv5, CIP Security, Modbus Security and OPC UA where practical. Legacy protocols including Telnet and older versions of SNMP should be removed or confined to isolated segments when replacement is not possible.
  • Monitor activity: Log communications within OT environments and investigate unexpected attempts to reach PLCs, HMIs and other control assets. Because industrial networks are often relatively predictable, baseline monitoring can help identify misuse and misconfiguration.
  • Limit unauthorised changes: Operate controllers in modes that prevent remote programming during normal activity and apply write protection or equivalent safeguards to control logic.
  • Segment networks: Separate OT, management and business IT networks, allowing only the communications necessary for operations. Segmentation can reduce the spread and impact of an intrusion.

The NCSC’s advice applies to critical infrastructure and other organisations using exposed industrial technology, with the agency encouraging businesses to assess their posture and address preventable weaknesses promptly.