The NCSC has seen increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK.
This has been carried out by a range of threat actors and resulted in some limited real-world disruption.
Any organisation that uses, deploys or maintains OT systems should treat this development seriously and review their security posture accordingly.
Who is affected?
Any organisation with internet-exposed OT could be affected by this activity.
Organisations should not assume that their OT is inaccessible from the internet without verifying it, as unintended exposure can arise through misconfigurations, legacy connections, or unmanaged assets.
Wider context
The NCSC has been engaging with sectors directly in response to this recent targeting and is now sharing this advisory to support national resilience efforts.
For some time, the NCSC has been warning about a broader pattern of disruptive cyber activity carried out by state and non-state actors affecting organisations in both critical national infrastructure (CNI) and non-CNI sectors.
Against the backdrop of technology-enabled uplifts in cyber capability and increased geopolitical instability, the NCSC assesses that the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.
As a result of this wider context, it is essential that all organisations take action now given the developing threat picture.
What should organisations do?
In response to the observed disruptive activity, organisations should take the following actions:
- Build a definitive view of your OT assets and ensure OT devices are not directly accessible from the public internet
- Replace default credentials and strengthen access controls for OT systems
- Control access to OT networks and maintain secure, supported boundary devices
- Adopt secure industrial and management protocols wherever possible
- Ensure all connectivity to and within OT networks is logged and monitored
- Ensure OT devices are operated in a state that prevents remote programming during normal operations
- Separate OT, management and business networks to limit the impact of incidents
- Maintain tested backups and recovery procedures for critical OT systems
Implications for non-operational technology organisations
While the NCSC has observed targeting of OT, there continues to be a broader pattern of disruptive cyber activity targeting internet exposed systems and edge devices affecting all sectors
In addition, they have previously highlighted other activity such as that against poorly configured routers, published in July 2026 with international partners.
For non-OT organisations, such activity highlights the importance of maintaining visibility of internet-exposed assets and edge network devices.
Key actions include maintaining an accurate inventory of internet-facing systems, understanding the function and data flows of edge devices, applying vendor security updates promptly, retiring end-of-life equipment, disabling insecure management protocols such as SNMP v1, SNMP v2 and Telnet, and monitoring for unexpected configuration changes or outbound connections.
Building long-term cyber resilience
Effective cyber resilience requires organisations to be prepared before an incident occurs and capable of responding and recovering when one does.
Organisations should review their readiness for significant cyber incidents, taking account of the NCSC’s guidance on preparing for severe cyber threats, and ensure that arrangements for responding to and recovering from cyber attacks are established, maintained and regularly exercised in line with the NCSC’s guidance on what to do when cyber attacks disrupt your organisation.
All organisations should register for the NCSC’s free Early Warning service to help identify publicly exposed vulnerabilities and other potential security issues affecting internet-facing systems, supporting efforts to detect and address risks before they are exploited.
Cyber Assessment Framework
Organisations that have embedded strong cyber resilience practices are better placed to prevent, detect and respond to cyber incidents before they cause operational disruption.
The Cyber Assessment Framework (CAF) provides a comprehensive framework for assessing how well an organisation is meeting expected security and resilience outcomes. Boards should seek assurance that the outcomes and principles described within the CAF are being achieved across all systems supporting essential functions.
Cyber Essentials
Where the CAF is not appropriate, Cyber Essentials is an excellent first step in gaining assurance that your systems are protected against the most common threats.
It is the minimum standard of cyber security recommended by the Government for organisations of all sizes.
To read more NCSC news, click here.