Britain's National Cyber Security Centre has issued an alert saying it is seeing more attacks on operational technology, the computers and controllers that run physical processes in factories, utilities and buildings, and that some of that activity has already caused real disruption.
The NCSC says the targeting spans multiple sectors globally, including in the UK, and is being carried out by "a range of threat actors". It describes the resulting damage as "some limited real-world disruption". The alert names no group, no sector and no victim, and gives no figures. Its whole argument is that any organization that uses, deploys or maintains OT should treat the development seriously and review its security posture now.
Assume it is reachable until you have checked
The single instruction the NCSC repeats hardest is not about patching. It is about knowing what you have. Organizations, it says, should not assume their OT is unreachable from the internet without verifying it, because unintended exposure arises through misconfigurations, legacy connections and unmanaged assets that nobody has looked at in years.
That is a familiar failure. In July, US authorities went public after attackers reached water utilities through programmable logic controllers that were sitting on the internet with weak or default credentials, in some cases locking operators out of their own equipment. The NCSC's advice reads like an attempt to get ahead of the same pattern in the UK.
The wider picture the NCSC is pointing at
The alert sets the OT activity inside a broader assessment. Against a backdrop of what it calls technology-enabled uplifts in cyber capability and increased geopolitical instability, the NCSC assesses that the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased. It has been warning for some time about disruptive activity by both state and non-state actors hitting critical national infrastructure and ordinary businesses alike.
For organizations with no OT at all, the agency draws the line at the network edge. It points back to a joint international advisory it published in July 2026 on poorly configured routers, and to the broader run of intrusions through internet-facing appliances. Recent research has found that state intelligence services and ransomware crews keep queuing at the same edge vendors, which makes an unpatched firewall a shared entry point rather than a niche risk.
Get the controllers off the public internet
The NCSC's eight actions are unglamorous and mostly free. Build a definitive view of the OT architecture, including every asset, communication path and external connection, and make sure PLCs and human-machine interfaces are not directly exposed to the internet. Replace default credentials, ban shared passwords on web and management interfaces, use unique administrator accounts, and turn on multi-factor authentication wherever it is supported, preferring key-based authentication to passwords where a protocol such as SSH allows it.
Then harden the boundary. Industrial gateways, firewalls, routers and remote-access appliances should be within vendor support, updated by default, replaced before end of life, and manageable only from a segregated network that is not itself on the internet. Where secure versions of protocols exist, the NCSC wants them adopted: DNP3 to DNP3-SAv5, CIP to CIP Security, Modbus to Modbus Security, OPC DA to OPC UA, with Telnet and SNMP v1 and v2 removed. Anything insecure that has no alternative should be confined to isolated segments.
The last three are about surviving a bad day. Log and monitor all connectivity to and within OT networks, watching in particular for attempts to talk to PLCs and HMIs from unexpected devices or routes; OT environments are static enough that baseline monitoring works unusually well. Keep controllers out of PROGRAM and other maintenance modes during normal operation, and use password-based write protection on controller logic. And maintain tested, ransomware-resistant backups of OT configurations, controller logic and engineering data, with recovery actually practised rather than assumed.
The NCSC also points organizations at its free Early Warning service, which flags publicly exposed vulnerabilities on internet-facing systems, and at the Cyber Assessment Framework for boards that want assurance, with Cyber Essentials as the floor where the CAF does not fit. None of this is new guidance. What is new is the agency saying, on the record, that the thing it has been warning about has started to break equipment. More of the UK's exposure picture sits on our United Kingdom country profile.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.