Summary
- The NCSC has observed increased targeting of operational technology globally, including in the UK, by multiple threat actors.
- Internet-exposed PLCs, HMIs, boundary devices, legacy connections, and unmanaged assets are central to the warning.
- The agency says boards should seek assurance against Cyber Assessment Framework outcomes across systems supporting essential functions.
The UK’s National Cyber Security Centre has warned that operational technology is facing increased targeting across multiple sectors, including in Britain, after activity by several threat actors caused limited real-world disruption.
The agency has not attributed the activity to a single campaign or adversary. Its warning instead describes a broader pattern in which internet-accessible operational technology, edge devices, misconfiguration, legacy connections, and unmanaged assets create opportunities to interfere with systems linked to physical processes.
Any organisation with internet-exposed OT could be affected, the NCSC said. It warned organisations not to assume industrial systems are isolated without first verifying their architecture and external connections.
That assumption can be particularly difficult to sustain in older industrial environments. Equipment installed for long service lives may later acquire remote-maintenance connections, engineering access, monitoring links, or integration with corporate networks that were absent when it was first deployed.
The NCSC highlighted programmable logic controllers and human-machine interfaces among devices that should not be directly accessible from the public internet. It also drew attention to industrial gateways, firewalls, routers, and remote-access appliances positioned at OT network boundaries.
Those systems can carry disproportionate risk because they mediate access between relatively static industrial equipment and less trusted networks. Unsupported products, default credentials, insecure management protocols, or poorly controlled remote access can weaken an otherwise segmented environment.
The agency recommends maintaining a definitive view of OT assets and communication paths, replacing default credentials, separating operational, management, and business networks, and keeping boundary devices within vendor support.
It also points to stronger authentication, logging, tested recovery procedures, and controls over remote programming. Legacy management technologies including Telnet and older versions of SNMP should be disabled or replaced where possible.
The warning extends beyond factories and traditional critical national infrastructure. The NCSC says the targeting forms part of a broader pattern of disruptive activity against internet-exposed systems and edge devices across sectors.
That makes asset visibility as important as any individual vulnerability. An organisation cannot protect or retire a device it does not know is internet-facing, and changes accumulated through maintenance or supplier access can leave systems reachable long after the business purpose for a connection has disappeared.
Industrial environments make remediation more complicated than conventional IT. Patching can require planned outages, systems may rely on vendor-certified configurations, and changes to equipment controlling physical processes can introduce safety and availability consequences of their own.
Long-term resilience therefore depends on architecture, lifecycle management, and recovery planning as well as urgent patching. Unsupported equipment and legacy protocols become harder to compensate for as connectivity around them increases.
The NCSC also places the issue within organisational governance. It says boards should seek assurance that outcomes and principles in the Cyber Assessment Framework are being achieved across systems supporting essential functions.
That requires more than a general assurance that OT is segmented. Useful oversight depends on knowing what equipment exists, which external paths remain open, how suppliers gain access, where unsupported devices remain in service, and how essential operations would be restored after disruption.
The NCSC’s warning does not describe a single imminent attack against UK infrastructure. It documents increased targeting already observed across multiple sectors and some resulting physical-world disruption, with internet exposure and unmanaged connectivity recurring as avoidable sources of risk.





