Threat to industrial digital systems ramps up
Disruptive cyber attacks are going beyond computers and into manufacturing and processing systems, Small to Medium-Sized Enterprises (SMEs) have been warned.
The National Cyber Security Centre (NCSC) has seen a concerted and increased number of attacks on what’s known as Operational Technology (OT) in numerous sectors both globally and domestically. These attacks have had real-world effects.
Hackers cut off a small gas-fired ‘peaker’ power station earlier this year. These UK plants have small local capacities, are remote with no employees and use OT to balance local baseload and feed into the national grid.
OT is both the hardware and software systems that monitor, control and automate infrastructure and processes across a variety of sectors.
The NCSC is warning that organisations should not assume their equipment is not internet-exposed. It said, “Against the backdrop of technology-enabled uplifts in cyber capability and increased geopolitical instability, the NCSC assesses that the threat from state use of offensive cyber, including outside of conflict, has almost certainly increased.”
Without organisations testing legacy structures, older equipment or misconfiguration, systems can be easy to exploit for state and non-state actors.
Companies should examine all their Programmable Logic Controllers (PLCs), Industrial Control Systems (ICS) and Supervisory Control and Data Acquisition (SCADA) systems to ensure their security.
The NCSC has outlined a series of steps that should be taken.
- Build a definitive view of your OT architecture, including all assets, communications pathways and external connections. This will help identify internet-exposed systems, unmanaged assets and legacy connectivity that may introduce risk.
- Ensure OT devices are not directly exposed to the public internet.
- Change any default credentials and prevent the use of shared passwords on web interfaces, management interfaces, and management protocols.
- Use unique accounts for administrators and enable multi-factor authentication (MFA) wherever supported. Any stronger authentication mechanisms, such as public/private key authentication, are recommended.
- This includes the control of access to OT networks. The NCSC recommends updating systems efficiently. This also includes ensuring that the management of these devices is only possible from a segregated management network that is not connected to the internet.
The NCSC proposes updating certain industrial protocols and security applications, which it lists on its website, including procedures.
If it wasn’t important before, IT departments should ensure they log and monitor all connectivity to and within OT networks. As OT environments are typically static and predictable, baseline monitoring can be highly effective at identifying unauthorised activity, misconfigurations, or potential cyber compromise.
Monitoring is also important during normal operations. PLCs, in particular, should not be left in programming or maintenance modes and should be in write-protected mode where possible.
The NCSC also recommends the separation of networks; for example, the business and management system should be separated from OT and, come to that, security systems.







