NCSC and CISA: Check Your OT and Edge Device Internet Exposure
On 27 August 2026, the UK's NCSC reported a rise in attacks on exposed OT systems, while CISA published its Internet Exposure Reduction Guidance. Together, the two sets of advice provide a practical checklist for an exposure audit.
On Thursday 27 August 2026, the UK's National Cyber Security Centre (NCSC) said it had observed an increase in attacks against OT systems across multiple sectors worldwide, including the UK. Industrial Cyber reported this on 28 August. The same day, the US CISA published its *Internet Exposure Reduction Guidance*, covering IIoT, SCADA, ICS and remote access technologies.
What the NCSC said
According to the NCSC, the activity comes from several different actors and has caused "some limited real-world disruption". The picture is broader: disruptive actions are being seen against internet-exposed systems and edge devices across all sectors, as already noted in a joint advisory from July 2026 on misconfigured routers.
Organisations should not assume their OT is unreachable from the internet without verifying it.
Unintended exposure can result from misconfigurations, legacy connections or unmanaged assets. For this reason, the NCSC first asks for a definitive view of the OT architecture: assets, communication paths and external connections.
The measures recommended by the NCSC
Recommended actions include:
- never expose PLCs or HMIs directly to the public internet;
- change default credentials, avoid shared passwords, and use unique administrative accounts, MFA where supported, and key-based authentication such as SSH keys;
- keep gateways, firewalls, routers and remote access appliances supported and up to date, replacing them before end of support, and manage them only from segregated management networks that are not connected to the internet;
- migrate to secure protocol versions: DNP3 to DNP3-SAv5, CIP to CIP Security, Modbus to Modbus Security, OPC DA to OPC UA;
- eliminate Telnet and SNMP v1 and v2; if an insecure protocol has no alternative, confine it to isolated segments;
- log and monitor all connectivity to and within the OT, defining a baseline for static environments and checking for access from unexpected devices, networks or paths;
- do not leave PLCs in PROGRAM mode or other maintenance modes, and protect controller logic with write protection;
- segment management networks, OT control systems and corporate IT by function and criticality.
The CISA guidance and the water sector case
CISA reports that in July 2026 it observed malicious activity against more than 100 internet-exposed systems in the water and wastewater sector. In most cases these were PLCs connected directly to cellular modems. Attackers accessed them remotely and changed IP addresses and passwords, causing loss of monitoring and control and, in some cases, operational disruption.
The steps CISA recommends:
- look for exposed assets with tools such as CISA's Cyber Hygiene service, Shodan, Censys, Thingful and Shadowserver;
- check whether integrators, vendors or MSSPs have remote access via VPN or cellular modems, obtain the external IP addresses of their systems, and ask to be notified if they change;
- remove internet access that is not operationally necessary;
- for assets that must remain exposed, change default passwords, apply patches, replace unsupported devices, use a jump host with MFA, and monitor inbound and outbound traffic;
- route remote access through a secure gateway, firewall or VPN rather than connecting directly to PLCs, HMIs or RTUs, with unique accounts and phishing-resistant MFA.
Why it matters for plant operators
Two national agencies published aligned guidance one day apart, both centred on unintended exposure of PLCs, HMIs, edge devices and third-party remote access. The result is a checklist that can be used right away for an exposure audit, for planning protocol upgrades and for reviewing segmentation.
Some caveats apply, however. The NCSC describes the impact as "limited" and, as reported, does not name actors or sectors. The CISA case concerns US utilities, and it is unclear whether it applies to manufacturing, although the pattern (PLCs behind cellular modems, poorly tracked third-party access) is plausible in many plants. This article is based on Industrial Cyber's summaries, not on the full original texts.
A practical first step
Start with the inventory: map assets and external connections, then verify from the outside what is actually reachable, including cellular modems and vendor access. Only then does it make sense to prioritise the work: close unnecessary exposure, put remote access behind a controlled point with MFA, and plan the replacement of unsupported protocols and devices.