Context
The NCSC has seen increased targeting of operational technology systems (OT) across multiple sectors globally, including the UK. This has been carried out by a range of threat actors and resulted in some limited real-world disruption.
Key points to note and next actions
- Any organisation with internet-exposed OT could be affected, and firms should not assume that their OT is inaccessible from the internet without verifying it. Misconfigurations, legacy connections or unmanaged assets can all lead to unintended exposures.
- The NCSC recommends that firms should –
- Build a definitive view of their OT assets and ensure OT devices are not directly accessible from the public internet
- Replace default credentials and strengthen access controls for OT systems
- Control access to OT networks and maintain secure, supported boundary devices
- Adopt secure industrial and management protocols where possible
- Ensure all connectivity to and within OT networks is logged and monitored
- Ensure OT devices are operated in a state that prevents remote programming during normal operations
- Separate OT, management and business networks to limit the impact of incidents
- Maintain tested backups and recovery procedures for critical OT systems
The NCSC recommends all organisations should register for its free Early Warning service to help identify publicly exposed vulnerabilities and other potential security issues affecting internet-facing systems, supporting efforts to detect and address risks before they are exploited.
