
Water sector example added to the NCSC’s Secure connectivity principles
The NCSC has published a new fictional worked example demonstrating how organisations can apply the Secure Connectivity Principles for Operational Technology (OT). The example explores how a regional water utility might approach the challenge of standardising digital connectivity across its OT environment while maintaining safety, reliability, and cyber resilience.
The aim of the example is not to prescribe a single architecture or implementation. Instead, it demonstrates how organisations can use the NCSC’s Secure Connectivity Principles as a target state while making risk-informed decisions that reflect their own operational context, regulatory obligations, and threat landscape.
The example highlights how architectural choices, governance processes, and operational practices all play a role in achieving resilient OT connectivity. In practice, organisations must balance security, safety, reliability, and operational requirements, particularly where legacy infrastructure is involved.
Throughout the example, the fictional organisation ‘Admin Corp Water’ works through the eight secure connectivity principles, illustrating how each one can guide design decisions such as reducing exposure, centralising connectivity, managing legacy protocols, strengthening boundaries, and preparing for cyber incidents.
This worked example has been developed in collaboration with the Industrial Control Systems Community of Interest (ICS‑COI) Boundary Expert Group. The group brings together practitioners from across critical national infrastructure sectors who are responsible for designing, securing, and operating the boundaries between operational technology and external networks. Their insights helped shape both the original guidance and this worked example, ensuring the scenarios and design considerations reflect the realities organisations face when operating critical infrastructure.
This publication also marks an important milestone for the community. It is the first time the Boundary Expert Group has directly authored content for the NCSC website, working collaboratively with the NCSC to validate the technical approaches against the secure connectivity principles. This model allowed practitioner experience and NCSC guidance to be combined to produce a practical and technically grounded worked example.
We would like to thank those in this group who took time out of their busy day jobs to contribute to this work.
We hope this approach can be repeated in the future. Critical sectors often face different operational constraints, regulatory environments, and threat contexts. Worked examples developed with sector experts can help illustrate how NCSC principles can be interpreted and applied in those different environments, supporting organisations to better understand how to turn guidance into practical implementation.
By combining NCSC expertise with the experience of practitioners responsible for securing real operational systems, this collaboration aims to make guidance more accessible, more practical, and ultimately more effective for the organisations that rely on it.
David G
Security Architect, NCSC
Source: UK NCSC (Cyber) (11 August 2026)







