UK NCSC warns of growing risk from internet-exposed operational technology

The UK National Cyber Security Centre has warned that operational technology systems are increasingly being targeted by cyber attackers, highlighting the risks posed by internet-exposed industrial devices. The warning follows a wave of attacks against US water and wastewater utilities in July that affected internet-facing programmable logic controllers and, in some cases, disrupted operations.

UK NCSC warns of growing risk from internet-exposed operational technology

The UK National Cyber Security Centre (NCSC) has warned organisations to address the risks posed by operational technology (OT) systems that are directly exposed to the internet, following increased targeting of OT environments across multiple sectors.

In an advisory published on 27 August, the NCSC said it had observed increased targeting of OT systems globally, including in the UK, by a range of threat actors. The activity has resulted in limited real-world disruption and prompted the agency to urge organisations that use, deploy, or maintain OT to review their security posture.

The warning comes after a series of attacks targeting internet-facing OT devices in the US water and wastewater sector.

Attacks target internet-facing PLCs

On 30 July, the US Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) warned that malicious cyber actors had been targeting internet-facing programmable logic controllers (PLCs) used by water and wastewater utilities.

Since 27 July, utilities in at least seven US states had reported incidents to the FBI, with some attacks degrading water operations. The affected devices included Rockwell Automation/Allen-Bradley MicroLogix 1100 and 1400 series PLCs.

The attackers gained remote access to internet-facing devices and modified configurations, including IP addresses and passwords. This resulted in some organisations losing monitoring and control functionality. Reported operational effects included loss of pressure and flooding, while at least one organisation identified changes to PLC project files.

The incidents highlighted a particular risk associated with systems that connect industrial equipment directly to external networks. In some cases, remote access can be necessary for maintenance or monitoring, but exposing control devices directly to the internet can provide attackers with a route into systems responsible for physical processes.

US authorities had already warned in April about Iranian-affiliated actors exploiting internet-connected PLCs in US critical infrastructure, including water and wastewater systems.

NCSC calls for better visibility of OT environments

The UK NCSC said organisations should first establish a definitive view of their OT architecture, including assets, communications pathways and external connections. This is intended to identify systems that may have been unintentionally exposed through misconfigurations, legacy connections or unmanaged assets.

The agency specifically advised organisations to ensure that OT devices such as PLCs and human-machine interfaces (HMIs) are not directly accessible from the public internet.

It also recommended replacing default credentials, avoiding shared passwords, using unique administrator accounts and enabling multi-factor authentication where supported. Organisations should also strengthen their OT network boundaries and restrict external access to systems that require it.

The NCSC’s broader guidance recommends limiting the exposure of OT connectivity and avoiding inbound connections to OT environments where possible. Where external access is required, such as for remote vendor support, access should be brokered through a secure gateway rather than allowing direct connections to OT assets.

From cyber compromise to physical disruption

The growing concern around OT security stems partly from the difference between conventional IT systems and technologies that control physical processes.

PLCs are used to regulate machinery, equipment and industrial processes, while HMIs allow operators to monitor and control those processes. A compromise of an IT system may primarily affect information or access to digital services, whereas interference with OT can affect the operation of physical infrastructure.

The recent incidents in the US demonstrated this distinction. According to the FBI and EPA, attackers’ manipulation of PLC configurations contributed to loss of monitoring and control, with some utilities reporting operational effects including pressure loss and flooding.

Geopolitical tensions add to the threat

The NCSC placed the latest OT activity within a broader pattern of disruptive cyber operations affecting both critical national infrastructure and other sectors. It said the threat from state use of offensive cyber capabilities, including outside periods of conflict, has almost certainly increased amid greater geopolitical instability and advances in cyber capabilities.

The agency also stressed that the problem is not limited to a particular sector or type of organisation. Any organisation operating internet-exposed OT may be affected, particularly where legacy equipment, unmanaged assets or insecure connections remain in use.

The NCSC has therefore framed OT security as part of wider cyber resilience rather than as a narrowly technical issue. Organisations are encouraged to maintain visibility of their systems, reduce unnecessary exposure, monitor for unexpected changes and ensure that recovery arrangements are tested.

The warning comes as critical infrastructure operators face a growing need to connect traditionally isolated industrial systems to networks for remote management, monitoring and other services. The challenge is to retain those operational benefits without creating unnecessary pathways for attackers into systems that control essential physical processes.

Go to Top