The National Cyber Security Centre (NCSC) has produced new guidance for teams operating in operational technology (OT) to set out secure connectivity principles in the field.
This builds on the previous guidance published by the NCSC on creating and maintaining complete and accurate records of their OT environment.
Like in any environment, connectivity brings a wealth of benefits – “remote monitoring, predictive maintenance, and integrated analytics” are some of the key examples the NCSC cites. Still, it also brings about increased risks such as an expanded attack surfaces, turning legacy devices into liabilities, increasing supply chain complexity, and bringing in remote access risks.
Similarly, historic OT environments would not have been designed with a consideration of connectivity, resulting in jarring security gaps that can be difficult to close.
The guidance provides eight principles for OT teams to bring to their approach to securing connectivity.
Principle 1. Balance the risk and opportunities: This involves the creation of a full business case to support a decision with a full risk analysis.
Principle 2. Limit the exposure of your connectivity: Adopting an exposure management approach, with proactive risk mitigation.
Principle 3. Centralise and standardise network connections: Reducing complexity, consolidating access points, and having uniform security controls across the entire OT estate.
Principle 4. Use standardised and secure protocols: Optimise prioritisation for security protocols across the state for standardisation and the right balance of security and access.
Principle 5. Harden your OT boundary: Invest in modern, modular, and replaceable boundary assets, ensuring a flexible security control to allow for boundary evolution.
Recommended
- New Smart Devices Secure-By-Design Laws Come Into Effect
- Scot-Secure West 2025 | How To Scale Your Cybersecurity Function
- Can Scotland’s New Framework Set the Standard for Cyber Resilience?
Principle 6. Limit the impact of compromise: Layer security controls to reduce the impact of threats to other systems, focusing on contamination and lateral movement.
Principle 7. Ensure all connectivity is logged and monitored: Comprehensive record keeping can make compromise detection easier, as well as helping to understand capability.
Principle 8. Establish an isolation plan: Create a plan to isolate OT environments in the case of a cyber incident in conjunction with a business continuity plan.
“The stronger your connectivity design, the harder it becomes for adversaries to cause disruption – whether their target is your data, your process, or the critical services your OT supports,” the NCSC wrote in a blog post discussing the guidance.





