NCSC UK advisory: increased targeting of internet-exposed OT and edge devices globally, including the UK, by state and non-state actors, with 'some limited real-world disruption'
NCSC UK published an advisory on 2026-08-27 stating it has observed increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK, carried out by "a range of threat actors" and resulting in "some limited real-world disruption": "the NCSC has seen increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK. This has been carried out by a range of threat actors and resulted in some limited real-world disruption" (NCSC UK, 2026-08-27). The advisory names no specific actor, CVE or victim, and is framed as a national-resilience notice rather than an incident disclosure: it instructs organisations with internet-exposed OT not to assume their systems are inaccessible from the internet without verifying it, citing misconfiguration, legacy connections and unmanaged assets as the typical exposure paths — "organisations should not assume that their OT is inaccessible from the internet without verifying it, as unintended exposure can arise through misconfigurations, legacy connections, or unmanaged assets" (NCSC UK, 2026-08-27).
NCSC UK assesses that "the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased" (NCSC UK, 2026-08-27) against a backdrop of technology-enabled capability uplift and geopolitical instability, and explicitly links this to its July 2026 joint advisory (with partners) on Russian state actors exploiting poorly configured routers — a continuation of an already-flagged threat pattern rather than a new, isolated incident. It also connects topically to this pipeline's prior coverage of the Minnesota/US water-utility PLC campaign and the associated European exposure count (86% of 4,117 internet-facing Siemens SIMATIC S7-1200 units concentrated in four EU countries, reached through mobile-carrier connectivity).
Concrete defensive guidance from the advisory: build a definitive OT asset and connectivity inventory; ensure PLCs and HMIs are not directly internet-exposed; eliminate default and shared credentials and enable MFA or key-based authentication on management interfaces; harden the OT boundary with vendor-supported, patched, EOL-replaced gateway devices managed only from a segregated network; migrate to secured protocol variants (DNP3-SAv5, CIP Security, Modbus Security, OPC UA) and disable telnet/SNMPv1/v2; and maintain ransomware-resistant, tested OT backups.
techniques[] maps only T1190 (Exploit Public-Facing Application, for internet-exposed PLC/HMI management interfaces the advisory names as the exposure class it observed being targeted). A default/shared-credential access technique is deliberately not mapped: that language appears only in the advisory's mitigation guidance, not as a described access technique in the targeting it reports, and mapping a technique from a hardening recommendation rather than from observed or stated adversary behaviour would overstate what this source supports. Triage: none is offered beyond the hardening guidance above — this is a resilience notice naming an exposure class rather than a specific observed intrusion chain, so no benign-lookalike discriminator applies; the actionable step is verification of actual internet reachability against documented network architecture, since the advisory's own framing is that the gap between the two is where exposure lives.
The NCSC has seen increased targeting of operational technology (OT) systems across multiple sectors globally, including in the UK. This has been carried out by a range of threat actors and resulted in some limited real-world disruption.
the NCSC assesses that the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased
Organisations should not assume that their OT is inaccessible from the internet without verifying it, as unintended exposure can arise through misconfigurations, legacy connections, or unmanaged assets.
Defender actions
- Build or refresh a definitive OT asset and connectivity inventory for every internet-facing or potentially internet-reachable PLC, HMI or edge device, and confirm none is directly internet-exposed — NCSC-UK states unintended exposure commonly arises through misconfiguration, legacy connections or unmanaged assets rather than deliberate design, so the audit needs to check actual reachability, not documented network diagrams.
- Migrate every internet-reachable OT/edge management interface to a secured protocol variant (DNP3-SAv5, CIP Security, Modbus Security, OPC UA) and disable telnet and SNMPv1/v2 — NCSC-UK names these as the specific protocol-hardening steps for the exposure class its advisory describes.
ATT&CK mapping
1 technique mapped from the cited reporting · MITRE ATT&CK v19.2
Initial Access TA0001
T1190Exploit Public-Facing Application
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.