Growing Risks for Industrial Control Systems
The United Kingdom's National Cyber Security Center (NCSC) has issued an urgent warning regarding the rising frequency of cyberattacks targeting operational technology systems. Across various sectors, threat actors now exploit internet-connected control devices to disrupt industrial processes. While large-scale outages remain rare, the agency notes that these intrusions are becoming more frequent as geopolitical tensions rise and attackers refine their methods.
Security researchers point to a common failure: the assumption that industrial equipment is air-gapped from the public internet. Chris Grove of Nozomi Networks says that industrial systems are often linked to external networks through forgotten vendor maintenance tunnels or misconfigured firewalls. These connections provide easy entry for attackers using simple, automated scanning tools. Once inside, they target outdated firmware and default passwords to gain control over critical infrastructure.
The Challenge of Visibility and Legacy Assets
Identifying every device within an industrial facility presents a massive obstacle for security teams. Many operational technology assets remain in service for decades, often running software that cannot handle standard IT security scans. These legacy machines do not appear on standard asset inventories, leaving them invisible to traditional monitoring tools. Because these systems are hard to track, they often lack the necessary patches or security updates to withstand modern threats.
Sean Tufts, a field CTO at Claroty, highlights that accurate asset identification is a critical missing piece in many security programs. His research indicates that nearly 90 percent of cyber-physical systems fail to report precise product codes, and many use internal names that do not match official vendor databases. Without this data, security teams cannot effectively assess the risk level of their own hardware, making it impossible to prioritize which devices need urgent protection.
Shifting Defense Strategies
Newer edge devices, such as 5G gateways and automated robotics, add further complexity to the security landscape. These components often sit between cloud environments and older local hardware to export data, yet they frequently arrive with insecure remote access configurations. Team82 research shows that 82 percent of analyzed cyber-physical system attacks involved unauthorized use of remote access clients, while 66 percent exploited compromised human-machine interfaces.
The NCSC advises organizations to conduct a thorough audit of their OT architecture to ensure that control devices are not directly reachable from the internet. Recommended safeguards include restricting external network access, logging all internal traffic, and disabling remote programming during normal operating hours. As government agencies issue repeated warnings, industry observers believe that voluntary guidelines will soon transition into strict regulatory mandates. Organizations must act now to segment their networks and verify that no critical control systems are accessible via public connections.

