Site navigation

NCSC Targets OT Cyber-threats with New Guidance

Tom Quinn

,

OT cybersecurity
“As cyber-attackers increasingly target operational technology around the world, it has never been more vital for critical infrastructure operators to ensure security is baked into the systems they use,” said Jonathon Ellison, NCSC.

Critical infrastructure organisations are being helped to secure their operational technology (OT) systems from growing cyber-threats with new guidance from the UK’s National Cyber Security Centre (NCSC).

The advice sets out key security considerations for firms when purchasing OT products, aiming to help OT owners and operators find those that follow secure-by-design principles, ensuring systems have a cyber-resilient foundation and minimise the risks posed by cyber-attacks. 

On issuing the advice, the NCSC warned that threat actors often target OT products, rather than specific organisations, because they can easily replicate attacks across multiple victims and sectors.

Last year saw reports that cyber-attacks against OT infrastructure are on the rise. Research from Fortinet found that nearly one-third of OT organisations reported more than six intrusions in the last year, up from 11% the year before, with 73% of organisations OT systems being impacted. 

With operational technology systems used widely in critical sectors around the world, but many components not developed with security as a priority, even minor weaknesses can be exploited by cyber-attackers to devastating effect, especially within essential services such as energy, water supplies and transportation networks.

Common weaknesses in OT products highlighted in the guide include poor authentication processes, known software vulnerabilities, limited logging, insecure default settings and passwords, and insecure legacy protocols. 

“As cyber-attackers increasingly target operational technology around the world, it has never been more vital for critical infrastructure operators to ensure security is baked into the systems they use,” said Jonathon Ellison, NCSC director of national resilience and future technology.

Organisations that own and operate OT systems are being encouraged to integrate twelve security considerations outlined in the NCSC’s guide into procurement processes to help defend against these threats, with the hope of sending a clear signal to manufacturers about the level of security they expect from products.

Among the security considerations that organisations should take in mind are whether the product allows for security and safety logging, has strong authentication controls, protects data, is configured in a secure way by default, and is supported by established vulnerability management processes by the manufacturer.

The new advice, published alongside the NCSC’s Five Eyes and international partners, places emphasis on vendors and manufacturers to play a key role in fixing foundational insecurities and taking responsibility for cybersecurity outcomes. 

“This new guide gives organisations practical advice on how to prioritise OT products that are secure by design when making purchasing decisions, helping to mitigate the very real cyber threats they face,” added Ellison.

“I strongly advise UK operators of OT systems to follow this guidance to help set a strong foundation for their cyber resilience and to send a signal to manufacturers that security is more than just an extra feature for products but a requirement in demand.”


Recommended reading


In November, a study from tech solutions firm IDS-INDATA revealed that vulnerabilities in ageing OT-IT networks within the manufacturing industry had contributed to supply chain attacks rising by 50%, with older OT systems, often running on outdated software, being prime targets for ransomware attacks.

Tom Quinn

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data