Skip to main content

folkfox

Skip to main content
Skip to content
MANAGED SECURITY AND DETECTION

The pipe under the waterline

The UK's cyber agency put it in writing: attackers are reaching operational technology through connections defenders assumed did not exist. The advisory is short, the mitigation list is eight lines long, and the market implication runs a good deal deeper.

Quick answerThe NCSC warned on 27 August 2026 of increased targeting of operational technology through internet-exposed systems and edge devices, with some limited real-world disruption. Good ot cybersecurity starts by verifying exposure, never assuming isolation.
Section 01

What the NCSC actually said#

Government advisories about ot cybersecurity usually arrive padded in maybes. This one, published 27 August, is unusually direct. The National Cyber Security Centre reports increased targeting of operational technology systems across multiple sectors globally, including in the UK, carried out by a range of threat actors, and, the phrase that matters, resulting in some limited real-world disruption. Not modelled disruption. Some limited real disruption, already happened.

The mechanism is the humbling part. The agency warns organisations not to assume their OT is inaccessible from the internet without verifying it, because unintended exposure arises through misconfigurations, legacy connections and unmanaged assets. In other words, the assets were not stormed, they were reachable. The burrow had a back entrance nobody on the payroll remembered digging.

ot cybersecurity listening at the waterline: an ink-drawn fox crouched at a sluice gate over a hidden pipe
The gate is heavy and locked. The pipe under the waterline is the finding.

The strategic sentence sits at the end, and it is the one boards will quote: the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased. In assessment language, almost certainly is as loud as it gets. For anyone selling or buying ics security, the demand driver just moved from compliance calendars to a live government assessment, and every ot cybersecurity roadmap in the country got reread this week.

@Cybernews
Hackers are targeting OT and edge devices, exploiting organizations' false belief that their OT is isolated from the internet, warns the UK's National Cyber Security Centre (NCSC).
28 August 2026View on X

False belief is the precise diagnosis. The gap between the network diagram and the network is where this whole story lives, and it is a gap no amount of perimeter spend closes, because the perimeter on the diagram is not the perimeter in the ground.

Section 02

The catalogue that keeps counting#

Zoom out and the advisory sits on a steadily filling ledger. CISA's Known Exploited Vulnerabilities catalogue, the US government's list of flaws confirmed exploited in the wild, reached 1,685 entries at catalogue version 2026.08.27, published the same day as the NCSC advisory. The folkfox count of the public KEV feed puts 201 additions in 2026 so far, a steady 17 to 31 a month, every one of them a door somebody actually walked through.

Known exploited vulnerabilities added to the KEV catalogue each year
Bar chart of known exploited vulnerabilities added to the CISA KEV catalogue per year from 2021 to 2026, context for ot cybersecurity exposure2021: 3112022: 5552023: 1872024: 1862025: 2452026: 2016004002000311202155520221872023186202424520252012026
Additions have run between 186 and 555 a year since the catalogue launched, with 201 already logged in 2026 by late August. folkfox count of CISA's public KEV feed, catalogue version 2026.08.27; the 2021 figure includes the launch backlog.

The week supplied its own worked example. A Citrix NetScaler flaw disclosed in June as a denial-of-service issue was shown to chain into unauthenticated remote code execution, confirmed exploited, added to the KEV list on 26 August with a US federal patch deadline of 29 August, per Help Net Security, with the NVD and CVE Program records tracking the flaw. Gateway appliances are exactly the edge devices the NCSC is pointing at: the boxes that stand between the internet and everything the diagram says is separate.

This is also why the phrase critical infrastructure protection has stopped being an American budget line and become a shared operational tempo. The US formally organises defence around sixteen critical infrastructure sectors; the UK's advisory speaks to the same estates, and the same scent trail runs through both: internet-reachable device, known flaw, patient adversary.

Section 03

What measured ot cybersecurity data says about the stakes#

Independent measurement backs the government's nose. Dragos, whose telemetry comes from industrial incident response, reported in its 2026 OT/ICS Cybersecurity Report that ransomware groups targeting industrial organisations surged 49 percent year over year, 119 groups tracked in 2025 against 80 the year before, with manufacturing accounting for more than two thirds of all victims. The hunters have multiplied, and they have picked their ground.

Ransomware dwell time in OT environments
Ransomware dwell time in OT environmentsBullet chart showing 42 days average ransomware dwell time in OT environments against a 5 day benchmark with full visibility, the scada security monitoring gapAverage dwell time: 42 of 5Average dwell time42 days
The industry-wide average dwell time for ransomware in OT environments was 42 days, against a 5 day average detection and containment where comprehensive OT visibility was in place, per Dragos's 2026 report.

Forty two days of undetected residence, against five where visibility exists. That single pairing is the entire commercial argument for monitored OT, and it is measured, not modelled. It is also the number that separates a scada security programme that watches from one that assumes: the protocols are old and trusting, so the watching is the protection.

None of this says the sky is falling, and honest ot cybersecurity marketing should resist saying so. The NCSC's disruption is limited and its advice is doable. The Dragos numbers describe criminal economics, not inevitability. The story is not doom, it is drift: estates that changed faster than their diagrams, and defenders pricing risk off the diagram.

Section 04

Eight moves, and the order they land in#

The advisory's ot cybersecurity mitigation list, which sits comfortably beside the agency's broader 10 Steps guidance, is a workmanlike eight lines, and the sequence matters more than the length. Verification first: build a definitive view of OT assets and prove nothing faces the public internet. Hygiene second: replace default credentials, strengthen access control, keep boundary devices supported. Architecture third: secure protocols, segmentation, logging on every connection, devices locked against remote programming in normal operation. Resilience last: tested backups and recovery for the systems that keep the lights on.

The NCSC's mitigation ladder, grouped
Verify exposure

Build a definitive asset view of OT and confirm no device is directly reachable from the public internet. Assumption is not evidence.

Fix the basics

Replace default credentials, tighten access controls, and keep boundary devices secure, supported and patched.

Harden the architecture

Adopt secure industrial and management protocols, separate OT from management and business networks, and log and monitor every connection.

Lock operations

Run OT devices in a state that prevents remote programming during normal operations, so a reachable device is still not a programmable one.

Rehearse recovery

Maintain tested, ransomware-resistant backups and recovery procedures for critical OT, because the 42-day dwell average says some intrusions will be found late.

For the vendors who sell this work, managed detection, exposure assessment, segmentation engineering, the marketing brief writes itself and still gets fluffed weekly. Lead with the government's sentence, not your own superlative. Quote the 42-and-5 pairing with its source attached. Skip the shadowy-hoodie stock art. A technical buyer reading a vendor page after this advisory wants evidence handled honestly, the discipline the morning's ServiceNow piece showed in action, and the standard every security content programme we run is held to.

The fox survives by checking the wind before trusting the burrow, and the whole advisory boils down to that vulpine habit: verify, then rest. Our earlier pieces on industrial ransomware's second quarter and exploit speed map the same ground, and the folkfox SEO and GEO team helps security vendors turn exactly this kind of evidence into visibility that survives a technical reader.

Questions

Frequently asked questions#

What did the NCSC warn about on 27 August 2026?

Increased targeting of operational technology systems across multiple sectors globally, including the UK, by a range of threat actors, resulting in some limited real-world disruption. The advisory stresses that organisations should verify, not assume, that OT is unreachable from the internet.

What is ot cybersecurity and how is it different from IT security?

Good ot cybersecurity is the protection of operational technology: the control systems, sensors and devices that run physical processes in plants, utilities and infrastructure. Unlike IT, availability and safety dominate, downtime is physical, patching windows are rare, and many protocols were designed with no authentication at all.

What are the 16 critical infrastructure sectors?

The sixteen sectors the United States formally designates for critical infrastructure protection, spanning energy, water, healthcare, financial services, communications, transportation, manufacturing, food, chemicals, dams, defence, emergency services, government facilities, information technology, nuclear, and commercial facilities. CISA maintains the list.

How do attackers reach OT systems that are supposed to be isolated?

Through exposure nobody verified: misconfigurations, legacy connections and unmanaged assets, per the NCSC, plus internet-facing edge devices such as gateways and remote-access appliances with known exploited flaws. The diagram says isolated; the scan says reachable.

What is scada security and why does monitoring matter so much?

It is the defence of supervisory control and data acquisition systems, the layer operators use to watch and drive industrial processes. Because industrial protocols are old and trusting, detection is the protection: Dragos measured 42 days of average ransomware dwell in OT, against 5 where full visibility existed.

Is the threat to critical infrastructure actually increasing?

The NCSC assesses that the threat from state use of offensive cyber, including outside conflict, has almost certainly increased, and Dragos measured a 49 percent year-over-year rise in ransomware groups targeting industrial organisations. Increased, yes; inevitable disaster, no.

Keep reading

Read more on this topic#

Selling security to people who read the advisory?

folkfox writes cybersecurity marketing that survives a technical buyer: the government's sentence quoted straight, the measured numbers sourced, and no hoodie stock art anywhere.