The pipe under the waterline
The UK's cyber agency put it in writing: attackers are reaching operational technology through connections defenders assumed did not exist. The advisory is short, the mitigation list is eight lines long, and the market implication runs a good deal deeper.
By Katie Delaney · 2026-08-30 · 8 min read
What the NCSC actually said#
Government advisories about ot cybersecurity usually arrive padded in maybes. This one, published 27 August, is unusually direct. The National Cyber Security Centre reports increased targeting of operational technology systems across multiple sectors globally, including in the UK, carried out by a range of threat actors, and, the phrase that matters, resulting in some limited real-world disruption. Not modelled disruption. Some limited real disruption, already happened.
The mechanism is the humbling part. The agency warns organisations not to assume their OT is inaccessible from the internet without verifying it, because unintended exposure arises through misconfigurations, legacy connections and unmanaged assets. In other words, the assets were not stormed, they were reachable. The burrow had a back entrance nobody on the payroll remembered digging.

The strategic sentence sits at the end, and it is the one boards will quote: the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased. In assessment language, almost certainly is as loud as it gets. For anyone selling or buying ics security, the demand driver just moved from compliance calendars to a live government assessment, and every ot cybersecurity roadmap in the country got reread this week.
Hackers are targeting OT and edge devices, exploiting organizations' false belief that their OT is isolated from the internet, warns the UK's National Cyber Security Centre (NCSC).
False belief is the precise diagnosis. The gap between the network diagram and the network is where this whole story lives, and it is a gap no amount of perimeter spend closes, because the perimeter on the diagram is not the perimeter in the ground.
The catalogue that keeps counting#
Zoom out and the advisory sits on a steadily filling ledger. CISA's Known Exploited Vulnerabilities catalogue, the US government's list of flaws confirmed exploited in the wild, reached 1,685 entries at catalogue version 2026.08.27, published the same day as the NCSC advisory. The folkfox count of the public KEV feed puts 201 additions in 2026 so far, a steady 17 to 31 a month, every one of them a door somebody actually walked through.
The week supplied its own worked example. A Citrix NetScaler flaw disclosed in June as a denial-of-service issue was shown to chain into unauthenticated remote code execution, confirmed exploited, added to the KEV list on 26 August with a US federal patch deadline of 29 August, per Help Net Security, with the NVD and CVE Program records tracking the flaw. Gateway appliances are exactly the edge devices the NCSC is pointing at: the boxes that stand between the internet and everything the diagram says is separate.
This is also why the phrase critical infrastructure protection has stopped being an American budget line and become a shared operational tempo. The US formally organises defence around sixteen critical infrastructure sectors; the UK's advisory speaks to the same estates, and the same scent trail runs through both: internet-reachable device, known flaw, patient adversary.
What measured ot cybersecurity data says about the stakes#
Independent measurement backs the government's nose. Dragos, whose telemetry comes from industrial incident response, reported in its 2026 OT/ICS Cybersecurity Report that ransomware groups targeting industrial organisations surged 49 percent year over year, 119 groups tracked in 2025 against 80 the year before, with manufacturing accounting for more than two thirds of all victims. The hunters have multiplied, and they have picked their ground.
Forty two days of undetected residence, against five where visibility exists. That single pairing is the entire commercial argument for monitored OT, and it is measured, not modelled. It is also the number that separates a scada security programme that watches from one that assumes: the protocols are old and trusting, so the watching is the protection.
None of this says the sky is falling, and honest ot cybersecurity marketing should resist saying so. The NCSC's disruption is limited and its advice is doable. The Dragos numbers describe criminal economics, not inevitability. The story is not doom, it is drift: estates that changed faster than their diagrams, and defenders pricing risk off the diagram.
Eight moves, and the order they land in#
The advisory's ot cybersecurity mitigation list, which sits comfortably beside the agency's broader 10 Steps guidance, is a workmanlike eight lines, and the sequence matters more than the length. Verification first: build a definitive view of OT assets and prove nothing faces the public internet. Hygiene second: replace default credentials, strengthen access control, keep boundary devices supported. Architecture third: secure protocols, segmentation, logging on every connection, devices locked against remote programming in normal operation. Resilience last: tested backups and recovery for the systems that keep the lights on.
Build a definitive asset view of OT and confirm no device is directly reachable from the public internet. Assumption is not evidence.
Replace default credentials, tighten access controls, and keep boundary devices secure, supported and patched.
Adopt secure industrial and management protocols, separate OT from management and business networks, and log and monitor every connection.
Run OT devices in a state that prevents remote programming during normal operations, so a reachable device is still not a programmable one.
Maintain tested, ransomware-resistant backups and recovery procedures for critical OT, because the 42-day dwell average says some intrusions will be found late.
For the vendors who sell this work, managed detection, exposure assessment, segmentation engineering, the marketing brief writes itself and still gets fluffed weekly. Lead with the government's sentence, not your own superlative. Quote the 42-and-5 pairing with its source attached. Skip the shadowy-hoodie stock art. A technical buyer reading a vendor page after this advisory wants evidence handled honestly, the discipline the morning's ServiceNow piece showed in action, and the standard every security content programme we run is held to.
The fox survives by checking the wind before trusting the burrow, and the whole advisory boils down to that vulpine habit: verify, then rest. Our earlier pieces on industrial ransomware's second quarter and exploit speed map the same ground, and the folkfox SEO and GEO team helps security vendors turn exactly this kind of evidence into visibility that survives a technical reader.
Frequently asked questions#
What did the NCSC warn about on 27 August 2026?
Increased targeting of operational technology systems across multiple sectors globally, including the UK, by a range of threat actors, resulting in some limited real-world disruption. The advisory stresses that organisations should verify, not assume, that OT is unreachable from the internet.
What is ot cybersecurity and how is it different from IT security?
Good ot cybersecurity is the protection of operational technology: the control systems, sensors and devices that run physical processes in plants, utilities and infrastructure. Unlike IT, availability and safety dominate, downtime is physical, patching windows are rare, and many protocols were designed with no authentication at all.
What are the 16 critical infrastructure sectors?
The sixteen sectors the United States formally designates for critical infrastructure protection, spanning energy, water, healthcare, financial services, communications, transportation, manufacturing, food, chemicals, dams, defence, emergency services, government facilities, information technology, nuclear, and commercial facilities. CISA maintains the list.
How do attackers reach OT systems that are supposed to be isolated?
Through exposure nobody verified: misconfigurations, legacy connections and unmanaged assets, per the NCSC, plus internet-facing edge devices such as gateways and remote-access appliances with known exploited flaws. The diagram says isolated; the scan says reachable.
What is scada security and why does monitoring matter so much?
It is the defence of supervisory control and data acquisition systems, the layer operators use to watch and drive industrial processes. Because industrial protocols are old and trusting, detection is the protection: Dragos measured 42 days of average ransomware dwell in OT, against 5 where full visibility existed.
Is the threat to critical infrastructure actually increasing?
The NCSC assesses that the threat from state use of offensive cyber, including outside conflict, has almost certainly increased, and Dragos measured a 49 percent year-over-year rise in ransomware groups targeting industrial organisations. Increased, yes; inevitable disaster, no.
Read more on this topic#
Nobody touched the turbine. They took the office.
What the Q2 industrial incident data says about where ot cybersecurity attackers actually land.
Read the pieceTwenty seven minutes from hello to remote access
From this morning's edition: a live exploitation timeline with a number on it.
Read the piecePatch Tuesday, Exploited Wednesday: What Vulnerability Management Services Must Prove Now
Why exploit speed is now the metric buyers should interrogate.
Read the pieceSelling security to people who read the advisory?
folkfox writes cybersecurity marketing that survives a technical buyer: the government's sentence quoted straight, the measured numbers sourced, and no hoodie stock art anywhere.