Critical Infrastructure Security,
Geo Focus: The United Kingdom,
Geo-Specific
Industrial Operators Face Growing Risk From Directly Connected Control Devices

The National Cyber Security Center (NCSC) of the United Kingdom has issued a significant warning regarding the escalating risks posed by cyber-attacks on operational technology (OT) systems across various sectors globally. This urgent advisory underscores the critical necessity for organizations to secure devices connected to the internet. The rising tide of cyber threats has prompted the NCSC to emphasize that safeguarding these systems is not merely a suggestion; it is an imperative requirement.
While the actual incidents of disruption have, thus far, been relatively limited, it is widely recognized that the sophistication and frequency of OT attacks are projected to increase. These developments are fueled in part by advancements in technology, which have bolstered the capabilities of both state and non-state actors in the cyber domain. Furthermore, the ongoing geopolitical instability has contributed to a rise in offensive cyber operations, increasing the urgency for protective measures and strategies.
The advisory clearly states, “Targeting operational technology reinforces the need for organizations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience.” As part of this initiative, the NCSC is advocating for a comprehensive visibility check across all sectors to ensure that organizations are fully aware of their cyber vulnerabilities.
This advisory emerged amidst concerns that a publicly accessible programmable logic controller (PLC) may have been exploited to incapacitate a small power plant in the U.K. for a duration of four days. The industry is now pressing the government for more clarity about this intrusion, particularly regarding whether an OT device utilized in industrial sites for automating mechanical or electrical processes was implicated in the attack path. This scrutiny reflects a growing concern about the security of fundamental infrastructure and its susceptibility to cyber threats.
The NCSC did not specify any individual incidents in its statement. However, it urged organizations to conduct thorough inventories of their OT architecture, advising that devices like PLCs and human-machine interfaces should not have direct internet exposure. Chris Grove, the director of cybersecurity strategy at OT security firm Nozomi Networks, echoed this sentiment, asserting, “NCSC said it plainly: do not assume it’s not internet-accessible, verify.” He added that the most precarious phrase in industrial cybersecurity is the belief that “that system isn’t connected to the internet because I have an air-gap.”
Grove elaborated on this point, citing that many ostensibly isolated systems have hidden connections, often created through forgotten vendor links, misconfigured firewalls, or unmanaged devices that have evaded documentation. This complexity has made industrial systems especially appealing targets for cyber attackers. According to Grove, these attackers are increasingly targeting edge devices and internet-exposed OT due to their cost-effectiveness, rather than relying on advanced malware or innovative techniques. These devices frequently operate outside the realm of endpoint protection, running outdated firmware and default credentials, thereby offering an easily exploitable pathway for cybercriminals.
In addition to the vulnerabilities presented by newer devices, the presence of legacy assets—some of which are up to 30 years old—presents a considerable challenge. These older systems often employ protocols that cannot be safely examined by standard IT scanners and may fall off organizational charts, complicating risk assessment efforts. Sean Tufts, the Field CTO at Claroty, emphasized that this visibility challenge is compounded by the fact that a significant percentage of cyber-physical systems, including PLCs, HMIs, and gateways, fail to provide accurate product codes.
This lack of precise identification means that organizations often cannot assess their risk accurately, underscoring the need for visibility that extends beyond conventional inventory lists. Moreover, issues associated with newer edge devices, such as 5G equipment and data forwarders, introduce additional layers of complexity. These devices, while capable of enhancing operational efficiency, create insecure remote connections and, if not managed properly, can lead to new vulnerabilities.
Tufts presented findings from Team82, revealing that approximately 82% of cyber-physical system attacks involved VNC clients used for unauthorized remote access, while 66% were related to compromised HMIs or SCADA systems. To address these issues, the NCSC has recommended implementing stronger authentication methods, restricting access from external networks, adopting secure protocols, and maintaining thorough logs of all connectivity within OT networks. Moreover, organizations should adopt practices that prevent remote programming during regular operations and ensure a robust recovery plan is in place.
According to Grove, the fundamental challenge lies in the organizational commitment to cybersecurity measures. He noted that the NCSC’s repeated warnings regarding internet-exposed edge devices indicate a growing urgency; when a government repeats its warnings, it signals a transition from advisories to mandates. The U.S. has already begun to reflect this urgency, with the Cybersecurity and Infrastructure Security Agency (CISA) issuing a binding directive aimed at mitigating risks associated with end-of-support edge devices.
As the threat landscape continues to evolve, CISA has also highlighted the pervasive issue of organizations unwittingly exposing vulnerabilities that can be easily discovered by threat actors through internet search queries. The agency’s findings from a wave of attacks affecting over 100 water and wastewater systems in July underscored the risks associated with PLCs connected to mobile networks via SIM cards for wireless internet access. CISA urged organizations to channel all necessary remote access through secure gateways, firewalls, or VPNs, reinforcing the necessity for organizations to tighten their cybersecurity controls as the stakes grow higher.

