NCSC warns of growing cyber threat to exposed OT and edge devices
The biggest security risk may be inside your network.

Hacker exploiting a smartphone vulnerability for cybercrime. Kmatta/Getty.
- The NCSC warns that hackers increasingly target operational technology and edge devices such as routers, firewalls, and VPN gateways.
- Organizations often wrongly assume their operational technology cannot be reached from the internet.
- Misconfigurations, old connections, and unmanaged assets can expose critical systems to attackers.
- The NCSC urges organizations to find exposed assets, secure access, update devices, monitor networks, and prepare recovery plans.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Any organization that uses, deploys, or maintains operational technology (OT) systems is increasingly targeted by threat actors, potentially disrupting business continuity or society.
Operational technology, or OT, refers to hardware and software that’s used to monitor and control physical processes.
For example, in water treatment plants, OT is being used to control pumps, valves, and chemical processes. Controlling air conditioning, access systems, or production lines is also handled with OT systems.
According to the UK’s National Cyber Security Centre (NCSC), hackers are targeting OT systems and edge devices, including routers, firewalls, VPN gateways, and network switches, more often.
A major mistake many organizations make is that they assume their OT is inaccessible from the internet without verifying it. This unintended exposure can arise through misconfigurations, legacy connections, or unmanaged assets, the cybersecurity agency explains.
Given the increased technical capabilities of (non-state) threat actors and current geopolitical tensions, organizations across critical national infrastructure and other sectors are more likely to be targeted.
The NCSC makes various recommendations for organizations that use OT systems and edge devices to protect their internal network:
- Identify all OT assets and check whether they are not directly exposed to the public internet.
- Change default passwords immediately, avoid sharing accounts with colleagues, and enable multi-factor authentication (MFA) where possible.
- Secure edge devices, keep them updated, and replace legacy hardware.
- Monitor network activity to detect unusual activity or configuration changes.
- Separate OT, management, and business networks to minimize impact in the event of a security incident.
- Create regular backups and develop recovery procedures for critical OT systems.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“Effective cyber resilience requires organizations to be prepared before an incident occurs and capable of responding and recovering when one does,” the NCSC concludes.
Earlier this week, the Cybersecurity & Infrastructure Security Agency (CISA) recommended that critical infrastructure operators identify systems accessible from the internet, remove unnecessary remote access, and secure necessary remote access.
“Many organizations unknowingly leave common vulnerabilities and weaknesses exposed to the internet, making them easy targets for exploitation. Threat actors can use internet-based search and discovery platforms to identify publicly accessible systems with misconfigurations, default credentials, and outdated software that they can exploit to gain unauthorized access,” the agency said.